🇬🇧
consul.to
2026-09-06 05:47:17
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
IndigoRidge
2026-09-06 04:57:50
(2 hours ago)
136.67.185.85 - - [06/Sep/2026:00:57:49 -0400] "GET /src/.git/config HTTP/1.1" 403 5477 "-" "crusade ...
show more
136.67.185.85 - - [06/Sep/2026:00:57:49 -0400] "GET /src/.git/config HTTP/1.1" 403 5477 "-" "crusader-worker/1.0"
136.67.185.85 - - [06/Sep/2026:00:57:49 -0400] "GET /www/.git/config HTTP/1.1" 403 5477 "-" "crusader-worker/1.0"
136.67.185.85 - - [06/Sep/2026:00:57:49 -0400] "GET /api/.git/config HTTP/1.1" 403 5477 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 04:37:49
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.185.85 (85.185.67.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.185.85 (85.185.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 00:37:41.848930 2026] [security2:error] [pid 25589:tid 25589] [client 136.67.185.85:34298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mx3.semisysteme.com"] [uri "/.git/config"] [unique_id "apzuFb9VkORBZulfrcuCLAAAAGg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 03:15:56
(4 hours ago)
136.67.185.85 - - [06/Sep/2026:05:15:55 +0200] "GET /var/www/.git/config HTTP/1.1" 301 169 "-" "crus ...
show more
136.67.185.85 - - [06/Sep/2026:05:15:55 +0200] "GET /var/www/.git/config HTTP/1.1" 301 169 "-" "crusader-worker/1.0"
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:08:53
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.185.85 (85.185.67.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.185.85 (85.185.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:08:46.313856 2026] [security2:error] [pid 5124:tid 5124] [client 136.67.185.85:47490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bosch.pamplonaserviciotecnico.com"] [uri "/public/.git/config"] [unique_id "apzZPlViqP6SygQqO5sqnwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
alferez
2026-09-06 02:48:12
(4 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:00:47
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.185.85 (85.185.67.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.185.85 (85.185.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:00:40.305646 2026] [security2:error] [pid 16348:tid 16363] [client 136.67.185.85:49718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.accreditedlawschool.org"] [uri "/var/www/.git/config"] [unique_id "apzJSDIu3NXoDoPvqIkAUwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-06 01:20:03
(6 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:01:33
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.185.85 (85.185.67.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.185.85 (85.185.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:01:27.327274 2026] [security2:error] [pid 26846:tid 26846] [client 136.67.185.85:48444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aspotoftea.littlehorndesign.com"] [uri "/api/.git/config"] [unique_id "apy7Z-ea6Eo_88VyvpHvmwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 22:45:04
(8 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 22:23:16
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.185.85 (85.185.67.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.185.85 (85.185.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:23:12.657606 2026] [security2:error] [pid 2278:tid 2278] [client 136.67.185.85:43292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.henning.org"] [uri "/.htaccess"] [unique_id "apyWUNTeM4v4r8-xzU6pIAAAAF0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇴
noteng.no
2026-09-05 13:20:48
(18 hours ago)
136.67.185.85 - - [05/Sep/2026:15:20:43 +0200] "\x16\x03\x01\x00\xEC\x01\x00\x00\xE8\x03\x03\x84/\x9 ...
show more
136.67.185.85 - - [05/Sep/2026:15:20:43 +0200] "\x16\x03\x01\x00\xEC\x01\x00\x00\xE8\x03\x03\x84/\x91Pu'\xBC\xD0\x14\xC511}Y\xF5\x83J<lp\xD2N\xAE_\x9F\x1C\xF8ZYa\x16\x1E \xEA0\xDC\xE4#t\x04\x89\x1C\xC1\xD7\xDC#\x0E\xF9oA\xE2\xE2rQ\xEBx~\x8D\x96\x12\xC2\xD2\x84[\x0C\x00\x14\x13\x02\x13\x01\x13\x03\xC0,\xC0+\xCC\xA9\xC00\xC0/\xCC\xA8\x00\xFF\x01\x00\x00\x8B\x00\x10\x00\x0B\x00\x09\x08http/1.1\x00\x0B\x00\x02\x01\x00\x00" 400 150 "-" "-"
136.67.185.85 - - [05/Sep/2026:15:20:43 +0200] "\x16\x03\x01\x00\xEC\x01\x00\x00\xE8\x03\x03\x14o\x86:C\xCE\xC6Z\xAEf\x8D\xD0\x83\xE6h\xC9\xB9\xB5" 400 150 "-" "-"
136.67.185.85 - - [05/Sep/2026:15:20:43 +0200] "\x16\x03\x01\x00\xEC\x01\x00\x00\xE8\x03\x03;\x1B\xBE\xDB\xE9\xE9\xB9\x8Ed\x9B\xB7\xF1\xC8\x94nq\xC5\x5C\xBF\x1FP\xB0\xAC\xF4\xD16X\x8FlX\x07o \xF8n\x81\x00&oA\xC1{\xEB,\x1C\xBE1o\x0B75\x1C\x84\x94\xE29\x18+u\xCFB\xC0\x1C\xC3\xB2\x00\x14\x13\x02\x13\x01\x13\x03\xC0,\xC0+\xCC\xA9\xC00\xC0/\xCC\xA8\x00\xFF\x01\x00\x00\x8B\x00\x05\x00\x05\x01\x00\x00
...
show less
Hacking
Web App Attack
🇳🇱
Savvii
2026-09-05 09:32:42
(22 hours ago)
20 attempts against mh-misbehave-ban on comet
Brute-Force
Bad Web Bot
Web App Attack