๐ฌ๐ง
openstrike.co.uk
2026-07-21 05:13:48
(2 hours ago)
2 attacks on VC URLs:
GET /.git/HEAD HTTP/1.1
Hacking
Anonymous
2026-07-21 00:35:03
(7 hours ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
Dominik Lysiak
2026-07-20 23:42:33
(8 hours ago)
157.52.92.26 - - [21/Jul/2026:01:42:30 +0200] "GET /.git/HEAD HTTP/1.1" 200 19238 "-" "Mozilla/5.0 ( ...
show more
157.52.92.26 - - [21/Jul/2026:01:42:30 +0200] "GET /.git/HEAD HTTP/1.1" 200 19238 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
157.52.92.26 - - [21/Jul/2026:01:42:31 +0200] "GET /.git/HEAD HTTP/1.1" 200 19238 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
157.52.92.26 - - [21/Jul/2026:01:42:32 +0200] "GET /.git/HEAD HTTP/1.1" 200 19238 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 22:21:34
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.26 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 18:21:30.778264 2026] [security2:error] [pid 16210:tid 16210] [client 157.52.92.26:47886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.glassicannex.org"] [uri "/.git/HEAD"] [unique_id "al6fakFiv9rdCg2CbZjH8QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 21:21:20
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.26 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 17:21:13.773509 2026] [security2:error] [pid 3289467:tid 3289467] [client 157.52.92.26:56428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.razeemco.com"] [uri "/.git/HEAD"] [unique_id "al6RSR66x3IIclBG14usLAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-07-20 18:52:45
(13 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 157.52.92.26 (SG/Singapore/-): 2 in t ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 157.52.92.26 (SG/Singapore/-): 2 in the last 3600 secs (0-196)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-20 17:24:27
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.26 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 13:24:19.544771 2026] [security2:error] [pid 14056:tid 14056] [client 157.52.92.26:13054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "littlehorneng.com"] [uri "/.git/HEAD"] [unique_id "al5Zw6Z0jxbxZrJQa_IZ7QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 11:23:58
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.26 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 07:23:53.109815 2026] [security2:error] [pid 10513:tid 10513] [client 157.52.92.26:41514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.celltechs.net"] [uri "/.git/HEAD"] [unique_id "al4FSZSF0YwmQ_TYZrPfQAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-07-20 08:06:42
(23 hours ago)
[redacted] 157.52.92.26 - - [20/Jul/2026:09:06:40 +0100] "GET /.git/HEAD HTTP/1.1" 302 6793 0/114182 ...
show more
[redacted] 157.52.92.26 - - [20/Jul/2026:09:06:40 +0100] "GET /.git/HEAD HTTP/1.1" 302 6793 0/114182 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0" [redacted] 157.52.92.26 - - [20/Jul/2026:09:06:40 +0100] "GET /.git/config HTTP/1.1" 302 6793 0/105766 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 23:15:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.26 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 19:15:48.636749 2026] [security2:error] [pid 21134:tid 21134] [client 157.52.92.26:47768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.smokeyspb.photos"] [uri "/.git/HEAD"] [unique_id "al1apA6b5X2yWH47SaEJ8gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2026-07-19 21:19:48
(1 day ago)
Probing for .git:
157.52.92.26 - - [19/Jul/2026:23:19:45 +0200] "GET /.git/config HTTP/1.1" 403 146 ...
show more
Probing for .git:
157.52.92.26 - - [19/Jul/2026:23:19:45 +0200] "GET /.git/config HTTP/1.1" 403 146 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0"
show less
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-07-19 18:13:01
(1 day ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 157.52.92.26 - - [19/Jul/202 ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 157.52.92.26 - - [19/Jul/2026:21:13:00 +0300] "GET /.git/HEAD HTTP/1.1" 403 2426 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
show less
Web App Attack
๐ซ๐ท
masterguru
2026-07-19 09:47:09
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 157.52.92.26 (SG/Singapore/-): 1 in t ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 157.52.92.26 (SG/Singapore/-): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ณ๐ด
jad-abuse
2026-07-19 09:11:14
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 2 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 07:00:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.26 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 03:00:23.679788 2026] [security2:error] [pid 15355:tid 15355] [client 157.52.92.26:36310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artsy-style.com"] [uri "/.git/HEAD"] [unique_id "alx2B11B0LQp7mtLqkAiZAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack