🇬🇧
openstrike.co.uk
2026-09-05 05:14:10
(6 hours ago)
12 attacks on VC URLs:
GET /var/www/.git/config HTTP/1.1
Hacking
🇺🇸
TPI-Abuse
2026-09-05 02:33:43
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.178.2 (2.178.67.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.178.2 (2.178.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 22:33:36.913262 2026] [security2:error] [pid 13828:tid 13828] [client 136.67.178.2:40866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.phoenix-uk.net"] [uri "/api/.git/config"] [unique_id "apt_gFxZ1iVVvhlM65nmOAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 01:18:24
(10 hours ago)
Web application attack detected.
Web App Attack
🇳🇱
e.fierstra
2026-09-04 22:53:51
(13 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇫🇷
bazter.pro
2026-09-04 22:06:36
(14 hours ago)
Auto-Ban [2026-09-05 01:06:36]: CRITICAL: Exploit trap paths (24); DC: Google LLC [Paths: 12] | Deta ...
show more
Auto-Ban [2026-09-05 01:06:36]: CRITICAL: Exploit trap paths (24); DC: Google LLC [Paths: 12] | Details: Exploit trap paths: /var/www/.git/config, /backend/.git/config, /app/.git/config, /site/.git/config, /src/.git/config | Sensitive files/paths: /var/www/.git/config, /backend/.git/config, /app/.git/config, /site/.git/config, /src/.git/config | 404 errors (24): /var/www/.git/config, /html/.git/config, /site/.git/config, /wordpress/.git/config, /public/.git/config, /.git/config, /backend/.git/config, /api/.git/config, /src/.git/config, /app/.git/config (and 2 more)
show less
Web App Attack
Hacking
🇳🇱
homeshowdomain.nl
2026-09-04 22:02:06
(14 hours ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇩🇪
LRob
2026-09-04 21:58:45
(14 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /html/.git/config (+11 more) | 2026-09-04 21:58 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:37:49
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.178.2 (2.178.67.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.178.2 (2.178.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:37:43.752793 2026] [security2:error] [pid 20636:tid 20636] [client 136.67.178.2:39028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.trainingbysteve.com"] [uri "/app/.git/config"] [unique_id "aps6J6o9uGwFObmsgqZQqAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:14:18
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.178.2 (2.178.67.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.178.2 (2.178.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:14:13.688082 2026] [security2:error] [pid 7208:tid 7208] [client 136.67.178.2:33010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.deannesamuelskids.com"] [uri "/src/.git/config"] [unique_id "aps0pVw1LYHq3v_1idNvswAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
Origon
2026-09-04 21:13:12
(15 hours ago)
http-sensitive-files - IP: 136.67.178.2 - time="2026-09-04T23:13:11+02:00" level=info msg="(555f66b ...
show more
http-sensitive-files - IP: 136.67.178.2 - time="2026-09-04T23:13:11+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 136.67.178.2 (US/396982) : 4h ban on Ip 136.67.178.2" module=db
show less
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 20:47:10
(15 hours ago)
(mod_security) mod_security (id:949110) triggered by 136.67.178.2 (US/United States/2.178.67.136.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 136.67.178.2 (US/United States/2.178.67.136.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
mnsf
2026-09-04 19:05:37
(17 hours ago)
Too many Status 40X (12)
Scanning/Probing (12)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 18:48:48
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.178.2 (2.178.67.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.178.2 (2.178.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 14:48:45.023554 2026] [security2:error] [pid 19363:tid 19363] [client 136.67.178.2:53208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "golflavahotsprings.com"] [uri "/.git/config"] [unique_id "apsSjYpp3cjVNEgmM2u8hAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-04 15:50:03
(20 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:45:50
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.178.2 (2.178.67.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.178.2 (2.178.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:45:42.117471 2026] [security2:error] [pid 11296:tid 11296] [client 136.67.178.2:51406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.luckypupdesigns.com"] [uri "/app/.git/config"] [unique_id "aprnph1QNEpD363JzkydHwAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack