Anonymous
2026-08-27 23:30:07
(1 hour ago)
136.117.204.187 - - [28/Aug/2026:08:30:04 +0900] "GET /var/www/.git/config HTTP/1.1" 403 441 "-" "cr ...
show more
136.117.204.187 - - [28/Aug/2026:08:30:04 +0900] "GET /var/www/.git/config HTTP/1.1" 403 441 "-" "crusader-worker/1.0"
136.117.204.187 - - [28/Aug/2026:08:30:04 +0900] "GET /api/.git/config HTTP/1.1" 403 441 "-" "crusader-worker/1.0"
136.117.204.187 - - [28/Aug/2026:08:30:04 +0900] "GET /app/.git/config HTTP/1.1" 403 441 "-" "crusader-worker/1.0"
...
show less
Brute-Force
๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 22:01:55
(2 hours ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
๐ฉ๐ช
NewGastroline
2026-08-27 19:32:58
(5 hours ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 16:07:03
(8 hours ago)
Automated web scanner. Requested suspicious paths: /htdocs/.git/config | /app/.git/config | /backend ...
show more
Automated web scanner. Requested suspicious paths: /htdocs/.git/config | /app/.git/config | /backend/.git/config | /www/.git/config | /public/.git/config | /wordpress/.git/config | /site/.git/config | /var/www/.git/config | /html/.git/config | /.git/config | /src/.git/config | /api/.git/config. UTC: 2026-08-27 15:55:35.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 15:26:27
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.117.204.187 (187.204.117.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.117.204.187 (187.204.117.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:26:21.219913 2026] [security2:error] [pid 15941:tid 15941] [client 136.117.204.187:38770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "monteriggioni.montepulciano.org"] [uri "/api/.git/config"] [unique_id "apBXHdiz23nmH69sUqrPcAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-27 14:55:24
(9 hours ago)
Multiple WAF Violations
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-08-27 12:50:40
(11 hours ago)
[Thu Aug 27 22:50:39.735834 2026] [security2:error] [pid 508724] [client 136.117.204.187:58140] [cli ...
show more
[Thu Aug 27 22:50:39.735834 2026] [security2:error] [pid 508724] [client 136.117.204.187:58140] [client 136.117.204.187] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "ccideas.com.au"] [uri "/backend/.git/config"] [unique_id "apAyn2psFmaQkSv031QMzAAAAAk"]
...
show less
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2026-08-27 11:42:06
(12 hours ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐ซ๐ท
masterguru
2026-08-27 11:17:58
(13 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ฌ๐ง
foxxelabs
2026-08-27 10:06:26
(14 hours ago)
Automated report from FoxxeLabs Sentinel. Path probed: /.git/config | Project: anseo | Reason(s): Kn ...
show more
Automated report from FoxxeLabs Sentinel. Path probed: /.git/config | Project: anseo | Reason(s): Known exploit path: /.git/config | User-Agent: crusader-worker/1.0
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 09:36:40
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.117.204.187 (187.204.117.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.117.204.187 (187.204.117.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 05:36:34.965295 2026] [security2:error] [pid 4506:tid 4506] [client 136.117.204.187:49178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "neilvboyer.com"] [uri "/backend/.git/config"] [unique_id "apAFIi0ER2U-f7l-WUVDmgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 08:10:02
(16 hours ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
XICTRON
2026-08-27 07:40:05
(16 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐จ๐ญ
Origon
2026-08-27 06:48:53
(17 hours ago)
http-sensitive-files - IP: 136.117.204.187 - time="2026-08-27T08:48:52+02:00" level=info msg="(555f ...
show more
http-sensitive-files - IP: 136.117.204.187 - time="2026-08-27T08:48:52+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 136.117.204.187 (US/396982) : 4h ban on Ip 136.117.204.187" module=db
show less
Web App Attack
๐จ๐ญ
4server
2026-08-27 06:42:50
(17 hours ago)
[ThuAug2708:42:44.8621922026][security2:error][pid3935970:tid3936137][client136.117.204.187:0]ModSec ...
show more
[ThuAug2708:42:44.8621922026][security2:error][pid3935970:tid3936137][client136.117.204.187:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.benvenutialfood.ch.81-17-25-250.cpanel.site\"][uri\"/public/.git/config\"][unique_id\"ao_cZEE70dJANlRQYHv4xQAAAQI\"]
show less
Hacking
Web App Attack