🇨🇭
4server
2026-09-21 10:31:49
(12 minutes ago)
[MonSep2112:31:43.9260192026][security2:error][pid1769978:tid1770088][client136.85.99.221:0]ModSecur ...
show more
[MonSep2112:31:43.9260192026][security2:error][pid1769978:tid1770088][client136.85.99.221:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"xn--sanierung-alter-huser-schweiz-hqc.ch\"][uri\"/.git/config\"][unique_id\"arEHj26UXxwe4jKluw0kfwAAAMg\"]
show less
Hacking
Web App Attack
🇵🇱
Budyn
2026-09-21 10:12:26
(32 minutes ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: sweetpuddingtrap.xyz | URI: /.git/config | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇩🇪
LRob
2026-09-21 09:57:01
(47 minutes ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-09-21 09:57 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-21 09:39:11
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.85.99.221 (221.99.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.99.221 (221.99.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 05:39:06.327277 2026] [security2:error] [pid 32013:tid 32013] [client 136.85.99.221:60524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yukitex.net"] [uri "/.git/config"] [unique_id "arD7Os9e9clZSHck8eBqjwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-21 09:30:21
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-21 09:17:01
(1 hour ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-21 09:09:53
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.85.99.221 (221.99.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.99.221 (221.99.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 05:09:45.671920 2026] [security2:error] [pid 13789:tid 13881] [client 136.85.99.221:44370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "taxelon.com"] [uri "/.git/config"] [unique_id "arD0WT0mYg8yi6NQ1t-w5wAAAVA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hary74656
2026-09-21 08:47:55
(1 hour ago)
Fail2Ban on schani.hostmi.at: jail=apache-instablock, failures=1.
136.85.99.221 [21/Sep/2026:10:47:5 ...
show more
Fail2Ban on schani.hostmi.at: jail=apache-instablock, failures=1.
136.85.99.221 [21/Sep/2026:10:47:54 +0200] [vhost schani.hostmi.at] 403 "GET /.git/config HTTP/1.1"
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-21 07:22:28
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.99.221 (221.99.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.99.221 (221.99.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 03:22:20.734903 2026] [security2:error] [pid 22323:tid 22323] [client 136.85.99.221:52966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "soundtrax.net"] [uri "/.git/config"] [unique_id "arDbLITJg2U-kemeSD_I8AAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-21 07:05:38
(3 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-21 06:44:13
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.99.221 (221.99.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.99.221 (221.99.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:44:06.661364 2026] [security2:error] [pid 3903144:tid 3903144] [client 136.85.99.221:35380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xpengineering.com"] [uri "/.git/config"] [unique_id "arDSNr2WJX3J7GBo4OvjLQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
paissangroup
2026-09-21 06:27:18
(4 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-21 06:05:28
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.99.221 (221.99.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.99.221 (221.99.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:05:24.179797 2026] [security2:error] [pid 18374:tid 18374] [client 136.85.99.221:46948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "studio716.info"] [uri "/.git/config"] [unique_id "arDJJKyl7klgV3nbxnvC0gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-21 05:34:48
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.99.221 (221.99.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.99.221 (221.99.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:34:43.482107 2026] [security2:error] [pid 31018:tid 31018] [client 136.85.99.221:47226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zeet.es"] [uri "/.git/config"] [unique_id "arDB8yp6EfJdUuHBZV1YOAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-21 04:58:37
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.99.221 (221.99.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.99.221 (221.99.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:58:30.269330 2026] [security2:error] [pid 31515:tid 31515] [client 136.85.99.221:56344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "valuechains4poor.net"] [uri "/.git/config"] [unique_id "arC5dhbaQEBjS2nT2RGxigAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack