🇩🇪
gadix
2026-09-05 11:03:01
(6 hours ago)
[05/Sep/2026:13:03:00.272854 +0200] apv25LasmujV6oDy4VG1MAAAAAY 136.70.143.177 60544 127.0.0.1 7081
...
show more
[05/Sep/2026:13:03:00.272854 +0200] apv25LasmujV6oDy4VG1MAAAAAY 136.70.143.177 60544 127.0.0.1 7081
[05/Sep/2026:13:03:00.274952 +0200] apv25MMqYfrD0ui2U9dCvQAAAAs 136.70.143.177 60560 127.0.0.1 7081
[05/Sep/2026:13:03:00.279457 +0200] apv25Lshe0lI_DCdS1yLywAAAAE 136.70.143.177 60572 127.0.0.1 7081
...
show less
Web App Attack
🇺🇸
factor1
2026-09-05 09:04:12
(8 hours ago)
CrowdSec at apollo Reports Abuse
Web App Attack
Anonymous
2026-09-05 02:33:28
(14 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 22:36:57
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.143.177 (177.143.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.143.177 (177.143.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 18:36:51.230485 2026] [security2:error] [pid 8298:tid 8384] [client 136.70.143.177:45044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "relay2.absurdotron.com"] [uri "/www/.git/config"] [unique_id "aptIAydJYu0S8RePPKmkSgAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 22:03:07
(19 hours ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 19:16:19
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.143.177 (177.143.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.143.177 (177.143.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 15:16:10.714188 2026] [security2:error] [pid 20499:tid 20499] [client 136.70.143.177:33298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "td3friendshelpingfriends.wilburmanagementgroup.com"] [uri "/src/.git/config"] [unique_id "apsY-kbclOocLXksYrv1DQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 18:58:14
(22 hours ago)
[ns65.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/src/.git/config | /api/.g ...
show more
[ns65.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/src/.git/config | /api/.git/config | /app/.git/config
show less
Hacking
Web App Attack
🇩🇪
FD-IX
2026-09-04 16:06:10
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 15:58:54
(1 day ago)
Web scanner: GET /site/.git/config
Web App Attack
Hacking
🇸🇪
vaia.cloud
2026-09-04 14:10:02
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇩🇪
LRob
2026-09-04 13:48:38
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /html/.git/config (+11 more) | 2026-09-04 13:48 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:17:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.70.143.177 (177.143.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.143.177 (177.143.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:17:32.835721 2026] [security2:error] [pid 23502:tid 23502] [client 136.70.143.177:55482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radtraininginc.net"] [uri "/.git/config"] [unique_id "apq23PuWlY0KJbo1BdIuQQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:38:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.70.143.177 (177.143.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.143.177 (177.143.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:38:22.045247 2026] [security2:error] [pid 22278:tid 22300] [client 136.70.143.177:52260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thecraftsycat.com"] [uri "/var/www/.git/config"] [unique_id "apqtrlcuOzOA9SnwC4S1EAAAAQ0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:39:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.70.143.177 (177.143.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.143.177 (177.143.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:39:21.178434 2026] [security2:error] [pid 25498:tid 25498] [client 136.70.143.177:39432] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "providencetheband.com.imagesbyaubrey.com"] [uri "/backend/.git/config"] [unique_id "app1qdlGBXSCAH3713YxDAAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 06:22:07
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking