๐ฎ๐ณ
evicky2002
2026-09-24 06:00:03
(4 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-24 02:34:22
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.231.5 (5.231.67.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.231.5 (5.231.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 22:34:17.601230 2026] [security2:error] [pid 20929:tid 20929] [client 136.67.231.5:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.rodrigoaldecoa.com"] [uri "/public/.git/config"] [unique_id "arSMKYB7H6Z9ShqKcziHlAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 00:27:45
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.231.5 (5.231.67.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.231.5 (5.231.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:27:40.043729 2026] [security2:error] [pid 6125:tid 6125] [client 136.67.231.5:43794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.gapanda.com"] [uri "/wordpress/.git/config"] [unique_id "arRufFQq9bvRIgleccv82AAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐พ
shopmax
2026-09-23 23:13:52
(10 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ง๐ช
Saec
2026-09-23 21:28:50
(12 hours ago)
Jarvis auto-ban: Honeypot /.git/config via cloud.saec.me [US] ASN:Google LLC
Port Scan
Web App Attack
๐ณ๐ฑ
thedreamer.nl
2026-09-23 19:26:28
(14 hours ago)
136.67.231.5 - - [23/Sep/2026:21:24:26 +0200] "GET /html/.git/config HTTP/1.1" 404 153 "-" "crusader ...
show more
136.67.231.5 - - [23/Sep/2026:21:24:26 +0200] "GET /html/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0" "US" "The Dalles" "45.59990" "-121.18710"
136.67.231.5 - - [23/Sep/2026:21:24:26 +0200] "GET /backend/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0" "US" "The Dalles" "45.59990" "-121.18710"
136.67.231.5 - - [23/Sep/2026:21:24:26 +0200] "GET /public/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0" "US" "The Dalles" "45.59990" "-121.18710"
136.67.231.5 - - [23/Sep/2026:21:24:26 +0200] "GET /htdocs/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0" "US" "The Dalles" "45.59990" "-121.18710"
...
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:06:42
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.231.5 (5.231.67.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.231.5 (5.231.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:06:38.561748 2026] [security2:error] [pid 22376:tid 22376] [client 136.67.231.5:40724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chaire-construction-4-0.com"] [uri "/var/www/.git/config"] [unique_id "arQjPuGDZiitcr6HXMdxmAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:25:00
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.231.5 (5.231.67.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.231.5 (5.231.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:24:54.049926 2026] [security2:error] [pid 28018:tid 28018] [client 136.67.231.5:45756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cdn.heavyglare.com"] [uri "/www/.git/config"] [unique_id "arQZdsW8Rc_naEea74ZIHQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-23 17:43:02
(16 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
updown.io
2026-09-23 15:36:23
(18 hours ago)
{"level":"info","ts":1790177664.9752538,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790177664.9752538,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"136.67.231.5","remote_port":"60122","client_ip":"136.67.231.5","proto":"HTTP/1.1","method":"GET","host":"bupdate.zyxupdate.tsrqponmlkjilkjihgc7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io","uri":"/public/.git/config","headers":{"Accept":["*/*"],"User-Agent":["crusader-worker/1.0"]}},"bytes_read":0,"user_id":"","duration":0.0000994,"size":0,"status":308,"resp_headers":{"Content-Type":[],"Server":["Caddy"],"Connection":["close"],"Location":["https://bupdate.zyxupdate.tsrqponmlkjilkjihgc7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io/public/.git/config"]}}
{"level":"info","ts":1790177664.9783607,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"136.67.231.5","remote_port":"60138","client_ip":"136.67.231.5","proto":"HTTP/1.1","method":"GET","host":"bupdate.zyxupdate.tsrqponmlkjilkjihgc7402a95-6fc9-4756-b4e6-fa6
...
show less
DDoS Attack
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-23 14:27:29
(19 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
Alt255
2026-09-23 14:02:50
(19 hours ago)
[ti-22al] Web exploit scanning: 3 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-22al] Web exploit scanning: 3 suspicious requests detected by fail2ban jail apache-scanner. Example: 136.67.231.5 - - [23/Sep/2026:16:02:29 +0200] "GET /public/.git/config HTTP/1.1" 404 7822 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
dwmp
2026-09-23 14:02:32
(19 hours ago)
[23/Sep/2026:16:02:32.534722 +0200] arPb-FlHPDtv7M3LoFZIpAAAAFE 136.67.231.5 60782 38.242.227.117 70 ...
show more
[23/Sep/2026:16:02:32.534722 +0200] arPb-FlHPDtv7M3LoFZIpAAAAFE 136.67.231.5 60782 38.242.227.117 7081
[23/Sep/2026:16:02:32.535216 +0200] arPb-OJahLT-R__BYNrJQQAAAA0 136.67.231.5 60718 38.242.227.117 7081
[23/Sep/2026:16:02:32.535491 +0200] arPb-OJahLT-R__BYNrJQgAAABc 136.67.231.5 60756 38.242.227.117 7081
...
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-23 13:53:59
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.231.5 (5.231.67.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.231.5 (5.231.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 09:53:52.685537 2026] [security2:error] [pid 28152:tid 28152] [client 136.67.231.5:50188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bocafloorsusa.digitalmarketing-group.com"] [uri "/html/.git/config"] [unique_id "arPZ8ADnv3s558yzZk2pTAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-23 13:23:54
(20 hours ago)
Multiple WAF Violations
Web App Attack