๐บ๐ธ
TPI-Abuse
2026-09-02 06:43:23
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.117.7.92 (92.7.117.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.117.7.92 (92.7.117.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 02:43:18.687090 2026] [security2:error] [pid 32470:tid 32470] [client 136.117.7.92:43028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "runnercomics.samanthasomers.com"] [uri "/backend/.git/config"] [unique_id "apfFhixta7jS7Bci7k5whgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-02 05:55:10
(11 hours ago)
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-09-02 05:13:08
(12 hours ago)
12 attacks on VC URLs:
GET /htdocs/.git/config HTTP/1.1
Hacking
Anonymous
2026-09-02 04:02:17
(13 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-02 02:24:33
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.117.7.92 (92.7.117.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.117.7.92 (92.7.117.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 22:24:26.693873 2026] [security2:error] [pid 12582:tid 12582] [client 136.117.7.92:34602] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vollmer.ws"] [uri "/wordpress/.git/config"] [unique_id "apeI2rYNmLrv7_KRv_qEuAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-09-01 18:00:53
(23 hours ago)
Active Response: IP 136.117.7.92 Blocked via Firewall Drop. Threat Score: 3.8/10 (LOW). Confidence: ...
show more
Active Response: IP 136.117.7.92 Blocked via Firewall Drop. Threat Score: 3.8/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 17:54:39
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.117.7.92 (92.7.117.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.117.7.92 (92.7.117.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 13:54:34.624860 2026] [security2:error] [pid 22765:tid 22765] [client 136.117.7.92:58446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "californiaappraisers.net"] [uri "/public/.git/config"] [unique_id "apcRWv8dmCo55-Sgu8_0vgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Uwe Sarpe
2026-09-01 17:52:11
(23 hours ago)
[Tue Sep 01 19:52:11.556849 2026] [access_compat:error] [pid 127466:tid 127466] [client 136.117.7.92 ...
show more
[Tue Sep 01 19:52:11.556849 2026] [access_compat:error] [pid 127466:tid 127466] [client 136.117.7.92:47642] AH01797: client denied by server configuration: /var/www/backend
[Tue Sep 01 19:52:11.570477 2026] [access_compat:error] [pid 127464:tid 127464] [client 136.117.7.92:47714] AH01797: client denied by server configuration: /var/www/wordpress
[Tue Sep 01 19:52:11.570499 2026] [access_compat:error] [pid 123564:tid 123564] [client 136.117.7.92:47686] AH01797: client denied by server configuration: /var/www/public
[Tue Sep 01 19:52:11.572056 2026] [access_compat:error] [pid 127463:tid 127463] [client 136.117.7.92:47728] AH01797: client denied by server configuration: /var/www/htdocs
[Tue Sep 01 19:52:11.572702 2026] [access_compat:error] [pid 123569:tid 123569] [client 136.117.7.92:47618] AH01797: client denied by server configuration: /var/www/app
...
show less
Brute-Force
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-09-01 17:01:25
(1 day ago)
Active Response: IP 136.117.7.92 Blocked via Firewall Drop. Threat Score: 3.9/10 (LOW). Confidence: ...
show more
Active Response: IP 136.117.7.92 Blocked via Firewall Drop. Threat Score: 3.9/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 13:35:01
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 12:02:31
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
netclix.gr
2026-09-01 10:00:49
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 136.117.7.92 (US/United States/92.7.117 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.117.7.92 (US/United States/92.7.117.136.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-01 08:48:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.117.7.92 (92.7.117.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.117.7.92 (92.7.117.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:48:10.946688 2026] [security2:error] [pid 891:tid 891] [client 136.117.7.92:36380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "itre.org"] [uri "/var/www/.git/config"] [unique_id "apaRSljzWBrcQPgoYyygVQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-01 08:44:21
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 05:23:22
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack