Anonymous
2026-08-26 17:26:34
(8 minutes ago)
git/env leak probe
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-08-26 17:24:31
(10 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-26 17:20:37
(14 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.85.74.35 (35.74.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.74.35 (35.74.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 13:20:33.856219 2026] [security2:error] [pid 30687:tid 30687] [client 136.85.74.35:59566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arrowhead30.com"] [uri "/.git/config"] [unique_id "ao8gYRFMGq8yciAFNorg3QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
araptus
2026-08-26 17:05:03
(29 minutes ago)
Gateway auto-report: /.git/config (UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36)
Web App Attack
Hacking
Anonymous
2026-08-26 17:00:46
(33 minutes ago)
136.85.74.35 - - [27/Aug/2026:01:00:45 +0800] "GET /.git/config HTTP/1.1" 200 30687 "-" "Mozilla/5.0 ...
show more
136.85.74.35 - - [27/Aug/2026:01:00:45 +0800] "GET /.git/config HTTP/1.1" 200 30687 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 17:00:20
(34 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.85.74.35 (35.74.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.74.35 (35.74.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 13:00:15.300519 2026] [security2:error] [pid 23517:tid 23517] [client 136.85.74.35:41650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bodyworkbydallas.com"] [uri "/.git/config"] [unique_id "ao8bn8DGCfyMzh6H88UFXQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 16:49:17
(45 minutes ago)
Web application attack detected.
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-26 16:43:56
(50 minutes ago)
cloudlinux2 fail2ban: 2026-08-26 18:38:49,242 fail2ban.filter [1775]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-26 18:38:49,242 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.81.94.31 - 2026-08-26 18:38:49cloudlinux2 fail2ban: 2026-08-26 18:38:55,312 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 5.38.46.209 - 2026-08-26 18:38:55cloudlinux2 fail2ban: 2026-08-26 18:39:59,418 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 5.38.46.209 - 2026-08-26 18:39:59cloudlinux2 fail2ban: 2026-08-26 18:39:58,598 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.81.59.14 - 2026-08-26 18:39:58cloudlinux2 fail2ban: 2026-08-26 18:40:09,021 fail2ban.actions [1775]: NOTICE [plesk-modsecurity] Unban 102.208.164.224cloudlinux2 fail2ban: 2026-08-26 18:40:18,748 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 85.152.58.12 - 2026-08-26 18:40:18cloudlinux2 fail2ban: 2026-08-26 18:40:29,058 fail2ban.actions [1775]: NOTICE [plesk-modsecurity] Unban 34.16.147.221cloudlinux2 fail2ban: 2026-08-26 18:40:41,085 fa
show less
Web App Attack
๐ฉ๐ช
Selckie
2026-08-26 16:37:38
(57 minutes ago)
fail2ban: NGINX unusual impact
Web App Attack
๐บ๐ธ
jfz-abuse
2026-08-26 16:36:01
(58 minutes ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 16:04:52
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.85.74.35 (35.74.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.74.35 (35.74.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:04:46.677136 2026] [security2:error] [pid 25450:tid 25450] [client 136.85.74.35:23812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sbxyz.net"] [uri "/.git/config"] [unique_id "ao8OnraTzOl96pq0dRG3FgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 15:14:23
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.74.35 (35.74.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.74.35 (35.74.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 11:14:17.650673 2026] [security2:error] [pid 4018:tid 4018] [client 136.85.74.35:56684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adm-sal.com"] [uri "/.git/config"] [unique_id "ao8CyVJjsq0XiT17Dw_jxQAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 10:45:39
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.74.35 (35.74.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.74.35 (35.74.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 06:45:36.185714 2026] [security2:error] [pid 15244:tid 15244] [client 136.85.74.35:32520] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zavijava.net"] [uri "/.git/config"] [unique_id "ao7D0HKhx2fjX8vFXTVg4AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-26 10:44:29
(6 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 136.85.74.35 (SG/Singapore/35.74.85 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 136.85.74.35 (SG/Singapore/35.74.85.136.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 10:07:16
(7 hours ago)
(mod_security) mod_security (id:949110) triggered by 136.85.74.35 (35.74.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 136.85.74.35 (35.74.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 06:07:13.906483 2026] [security2:error] [pid 7416:tid 7416] [client 136.85.74.35:33100] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "omnustechnologies.com"] [uri "/.git/config"] [unique_id "ao660Q5aJh0ld7xYgR9qQwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack