๐ณ๐ฑ
thedreamer.nl
2026-08-28 19:23:20
(50 minutes ago)
136.66.199.69 - - [28/Aug/2026:21:21:53 +0200] "GET /.git/config HTTP/1.1" 499 0 "-" "crusader-worke ...
show more
136.66.199.69 - - [28/Aug/2026:21:21:53 +0200] "GET /.git/config HTTP/1.1" 499 0 "-" "crusader-worker/1.0" "US" "The Dalles" "45.59990" "-121.18710"
136.66.199.69 - - [28/Aug/2026:21:21:53 +0200] "GET /app/.git/config HTTP/1.1" 499 0 "-" "crusader-worker/1.0" "US" "The Dalles" "45.59990" "-121.18710"
136.66.199.69 - - [28/Aug/2026:21:21:53 +0200] "GET /src/.git/config HTTP/1.1" 499 0 "-" "crusader-worker/1.0" "US" "The Dalles" "45.59990" "-121.18710"
136.66.199.69 - - [28/Aug/2026:21:21:53 +0200] "GET /backend/.git/config HTTP/1.1" 499 0 "-" "crusader-worker/1.0" "US" "The Dalles" "45.59990" "-121.18710"
...
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-08-28 14:50:57
(5 hours ago)
AutoBlock: โ๏ธ Configuration File Access (Non Decay-Based)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 13:27:39
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.199.69 (69.199.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.199.69 (69.199.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 09:27:34.911833 2026] [security2:error] [pid 27496:tid 27496] [client 136.66.199.69:39340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "glidetrubooks.com"] [uri "/var/www/.git/config"] [unique_id "apGMxtCHWeG0orpR_Rb9oQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 11:57:38
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.199.69 (69.199.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.199.69 (69.199.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:57:35.182061 2026] [security2:error] [pid 15487:tid 15487] [client 136.66.199.69:52120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adventiststoday.org"] [uri "/.git/config"] [unique_id "apF3rxdaHJ2P42m_ZDsvSQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-28 10:57:00
(9 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
mnsf
2026-08-28 01:05:21
(19 hours ago)
Too many Status 40X (12)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐บ๐ธ
kosada.com
2026-08-28 00:14:52
(19 hours ago)
Web vulnerability probing (bogus request)
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 22:01:00
(22 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-26.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
factor1
2026-08-27 21:09:03
(23 hours ago)
CrowdSec at churndash Reports Abuse
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-27 18:15:16
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฉ๐ช
Marc
2026-08-27 17:07:18
(1 day ago)
136.66.199.69 - - [27/Aug/2026:19:07:18 +0200] "GET /var/www/.git/config HTTP/1.1" 404 4617 "-" "cru ...
show more
136.66.199.69 - - [27/Aug/2026:19:07:18 +0200] "GET /var/www/.git/config HTTP/1.1" 404 4617 "-" "crusader-worker/1.0" 136.66.199.69 - - [27/Aug/2026:19:07:18 +0200] "GET /htdocs/.git/config HTTP/1.1" 404 4617 "-" "crusader-worker/1.0" 136.66.199.69 - - [27/Aug/2026:19:07:18 +0200] "GET /backend/.git/config HTTP/1.1" 404 4617 "-" "crusader-worker/1.0"
show less
Brute-Force
๐ฆ๐บ
2000cn.com.au
2026-08-27 16:07:09
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-27 15:09:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.66.199.69 (69.199.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.199.69 (69.199.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:09:17.037104 2026] [security2:error] [pid 31233:tid 31233] [client 136.66.199.69:38248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.perryoclock.healingtrek.com"] [uri "/www/.git/config"] [unique_id "apBTHScBBvd8i7n66htNlwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 14:44:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.66.199.69 (69.199.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.199.69 (69.199.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:44:00.323446 2026] [security2:error] [pid 29982:tid 29993] [client 136.66.199.69:39090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "latinofederation.org"] [uri "/var/www/.git/config"] [unique_id "apBNMPYk176w0BDxAgWxjwAAAYg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
LoneRider
2026-08-27 12:48:16
(1 day ago)
[27/Aug/2026:14:48:15.764400 +0200] apAyD7K9GddJg3SruUKlrQAAAAU 136.66.199.69 51326 127.0.0.1 7081
[ ...
show more
[27/Aug/2026:14:48:15.764400 +0200] apAyD7K9GddJg3SruUKlrQAAAAU 136.66.199.69 51326 127.0.0.1 7081
[27/Aug/2026:14:48:15.773255 +0200] apAyDyCJ1Mt0p-6eugSoTAAAAAE 136.66.199.69 51332 127.0.0.1 7081
[27/Aug/2026:14:48:15.776243 +0200] apAyD8Gs00PbYWVloT03rQAAAAk 136.66.199.69 51316 127.0.0.1 7081
...
show less
Hacking