๐ฉ๐ช
bazter.pro
2026-09-29 08:25:57
(3 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ซ๐ท
Catalin Negru
2026-09-28 21:06:07
(15 hours ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-28 20:58:10
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.79.191 (191.79.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.79.191 (191.79.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 16:58:06.219569 2026] [security2:error] [pid 1410:tid 1434] [client 136.85.79.191:40498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "internationalboardofstandards.com"] [uri "/.git/config"] [unique_id "arrU3obosWUWupbHhUqSBgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 20:06:46
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.79.191 (191.79.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.79.191 (191.79.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 16:06:40.559072 2026] [security2:error] [pid 3009:tid 3009] [client 136.85.79.191:57830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "internationalavionics.com"] [uri "/.git/config"] [unique_id "arrI0Lhi4dFVL2SigBb2dwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 06:59:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.85.79.191 (191.79.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.79.191 (191.79.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 02:59:36.431530 2026] [security2:error] [pid 32225:tid 32225] [client 136.85.79.191:34788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "americashealthtalk.com"] [uri "/.git/config"] [unique_id "aroQWIDEjRnH5LgXgi-krQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 19:28:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.85.79.191 (191.79.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.79.191 (191.79.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 15:28:37.751324 2026] [security2:error] [pid 13606:tid 13606] [client 136.85.79.191:51422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tarakanov.com"] [uri "/.git/config"] [unique_id "arluZWotjZgmgO54eaSGSgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 16:10:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.85.79.191 (191.79.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.79.191 (191.79.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 12:10:38.206541 2026] [security2:error] [pid 6867:tid 6867] [client 136.85.79.191:60386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aticom.net"] [uri "/.git/config"] [unique_id "ark__qa_nIFzCDcqc-aemAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-27 07:29:40
(2 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
Anonymous
2026-09-27 06:09:43
(2 days ago)
2026/09/27 06:09:41 [error] 2270634#2270634: *361156 [client 136.85.79.191] ModSecurity: Access deni ...
show more
2026/09/27 06:09:41 [error] 2270634#2270634: *361156 [client 136.85.79.191] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `55' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 55)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "aobandassociates.com"] [uri "/"] [unique_id "179048938166.953899"] [ref ""], client: 136.85.79.191, server: aobandassociates.com, request: "POST / HTTP/1.1", host: "aobandassociates.com"
2026/09/27 06:09:42 [error] 2270634#2270634: *361156 [client 136.85.79.191] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `55' ) [file "/usr/local/owas
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-26 16:03:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.85.79.191 (191.79.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.79.191 (191.79.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 12:03:42.798315 2026] [security2:error] [pid 28035:tid 28035] [client 136.85.79.191:55280] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ohiobabe.com"] [uri "/.git/config"] [unique_id "arfs3jgRhNajmSTxvf9tPgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 15:06:30
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.85.79.191 (191.79.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.79.191 (191.79.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 11:06:23.967473 2026] [security2:error] [pid 7213:tid 7213] [client 136.85.79.191:42340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.oglesbyproductions.com"] [uri "/.git/config"] [unique_id "arffb0YRMo83amQbFvoBgwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-26 08:54:47
(3 days ago)
backdoor: Prototype pollution / command injection attempt
Web App Attack
๐ฉ๐ช
LRob
2026-09-26 05:53:45
(3 days ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.git/config | 2026-09-26 05:53 UTC
show less
Hacking
Web App Attack
๐ฉ๐ช
pscriptos
2026-09-25 19:43:08
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ซ๐ท
Catalin Negru
2026-09-25 19:17:41
(3 days ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force