🇳🇱
homeshowdomain.nl
2026-09-06 22:00:40
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-05.
show less
Web App Attack
SSH
Hacking
🇳🇱
homeshowdomain.nl
2026-09-05 21:59:41
(4 days ago)
Auto-ban: >3000 req/min op 2026-09-05
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-05 21:15:47
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.64.135.98 (98.135.64.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.64.135.98 (98.135.64.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:15:41.356908 2026] [security2:error] [pid 31695:tid 31695] [client 136.64.135.98:43826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adampayments.com"] [uri "/.git/config"] [unique_id "apyGfaR-d8VibPDFV_JihgAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 20:45:52
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.64.135.98 (98.135.64.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.64.135.98 (98.135.64.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:45:48.780329 2026] [security2:error] [pid 546:tid 546] [client 136.64.135.98:39936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acworthga.us"] [uri "/.git/config"] [unique_id "apx_fDENaO0nVWnPbfT0SgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 20:09:31
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.64.135.98 (98.135.64.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.64.135.98 (98.135.64.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:09:25.331810 2026] [security2:error] [pid 11946:tid 11946] [client 136.64.135.98:45160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "activethinkers.net"] [uri "/.git/config"] [unique_id "apx29XoQjCDSOeZEAvH8RwAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
tsZero
2026-09-05 20:05:51
(4 days ago)
Scan example: path=/.git/config status=200
Hacking
🇳🇴
jad-abuse
2026-09-05 20:00:10
(4 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 2 hits.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 19:47:31
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.64.135.98 (98.135.64.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.64.135.98 (98.135.64.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 15:47:23.351385 2026] [security2:error] [pid 16549:tid 16549] [client 136.64.135.98:42042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "actionrev.mainstreetofficesuites.com"] [uri "/.git/config"] [unique_id "apxxy-5yde_xrBG4oZCETQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-05 19:45:15
(4 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 19:29:23
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.64.135.98 (98.135.64.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.64.135.98 (98.135.64.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 15:29:16.361408 2026] [security2:error] [pid 31872:tid 31872] [client 136.64.135.98:49134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acsellsre.com"] [uri "/.git/config"] [unique_id "apxtjJHmnOv-0sxsPjo8xwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 19:21:04
(4 days ago)
Web application attack detected.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 19:08:50
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.64.135.98 (98.135.64.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.64.135.98 (98.135.64.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 15:08:45.683796 2026] [security2:error] [pid 7118:tid 7118] [client 136.64.135.98:52378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acpalms.com"] [uri "/.git/config"] [unique_id "apxovebjopH3GcD--2h0GQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-05 18:59:02
(4 days ago)
168 requests with url.path */.git/config
Brute-Force
Bad Web Bot
🇳🇱
ipoac.nl
2026-09-05 18:57:44
(4 days ago)
-:443 136.64.135.98 - - [05/Sep/2026:20:57:43 +0200] - "GET /.git/config HTTP/1.1" 403 6335 "-" "-"
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-05 18:45:46
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.64.135.98 (98.135.64.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.64.135.98 (98.135.64.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 14:45:39.218738 2026] [security2:error] [pid 3656:tid 3656] [client 136.64.135.98:54582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acmax.com"] [uri "/.git/config"] [unique_id "apxjU9oDqgcn1l6uICdBDgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack