🇬🇧
openstrike.co.uk
2026-09-08 05:13:46
(14 minutes ago)
2 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
Anonymous
2026-09-08 04:19:03
(1 hour ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 01:29:12
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.193.46.219 (219.46.193.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.193.46.219 (219.46.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:29:07.720747 2026] [security2:error] [pid 7078:tid 7078] [client 35.193.46.219:33694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sprek.net.sprektech.com"] [uri "/.git/config"] [unique_id "ap9k4ww4SJbW31fNSlJIJQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇴
jad-abuse
2026-09-07 23:41:54
(5 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 23:22:39
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.193.46.219 (219.46.193.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.193.46.219 (219.46.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 19:22:34.820835 2026] [security2:error] [pid 8835:tid 8835] [client 35.193.46.219:55596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.spittingimagegallery.kathrynmcbride.com"] [uri "/.git/config"] [unique_id "ap9HOv2E0XAF7whB-cQZHwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇿
Antinson
2026-09-07 23:16:44
(6 hours ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
🇺🇸
SodaAudit.app
2026-09-07 23:07:02
(6 hours ago)
[sodaaudit.app] Web app attack. Timestamp: 2026-09-07T21:53:26.000Z. 1 probe events, 1 distinct path ...
show more
[sodaaudit.app] Web app attack. Timestamp: 2026-09-07T21:53:26.000Z. 1 probe events, 1 distinct path(s). Paths (payload): /.git/config
show less
Web App Attack
Anonymous
2026-09-07 23:06:06
(6 hours ago)
Trying to access config files
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 23:00:14
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.193.46.219 (219.46.193.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.193.46.219 (219.46.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 19:00:06.076192 2026] [security2:error] [pid 25998:tid 25998] [client 35.193.46.219:60154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.spathia.projectthinkspot.com"] [uri "/.git/config"] [unique_id "ap9B9jNbsIxExJVXiCBcKwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 22:39:12
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.193.46.219 (219.46.193.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.193.46.219 (219.46.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 18:39:05.875346 2026] [security2:error] [pid 3741:tid 3741] [client 35.193.46.219:38790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.soulwolf.com.ieas.org"] [uri "/.git/config"] [unique_id "ap89CTxn1I6UKwpQ_KkTRAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 22:32:47
(6 hours ago)
35.193.46.219 - - [07/Sep/2026:19:32:46 -0300] "GET /.git/config HTTP/1.1" 403 874 "-" "-"
...
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
🇺🇸
TPI-Abuse
2026-09-07 22:23:54
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.193.46.219 (219.46.193.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.193.46.219 (219.46.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 18:23:48.084675 2026] [security2:error] [pid 7214:tid 7214] [client 35.193.46.219:47746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.songforana.michaelsabbey.org"] [uri "/.git/config"] [unique_id "ap85dBhP_lSlgI3FU62ByAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
kumiko
2026-09-07 22:22:51
(7 hours ago)
[2026-09-08 01:22:50] Probing for dotfiles
"GET /.git/config HTTP/1.1" 301
Bad Web Bot
Web App Attack
🇺🇸
SX Communications
2026-09-07 22:09:03
(7 hours ago)
Web vulnerability scanning / probing from 35.193.46.219: automated requests for CMS admin paths, log ...
show more
Web vulnerability scanning / probing from 35.193.46.219: automated requests for CMS admin paths, login endpoints, xmlrpc, and common scanner fingerprints over HTTPS. 1 hits; paths: /.git/config.
show less
Port Scan
Hacking
Web App Attack
🇮🇹
CoreTech srl
2026-09-07 22:03:57
(7 hours ago)
cloudlinux2 fail2ban: 2026-09-07 23:59:00,833 fail2ban.filter [1794]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-07 23:59:00,833 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 35.193.46.219 - 2026-09-07 23:59:00cloudlinux2 fail2ban: 2026-09-07 23:59:29,363 fail2ban.actions [1794]: NOTICE [plesk-modsecurity] Unban 35.229.121.77cloudlinux2 fail2ban: 2026-09-07 23:59:34,961 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 188.213.202.145 - 2026-09-07 23:59:34cloudlinux2 fail2ban: 2026-09-08 00:00:48,657 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 8.231.214.24 - 2026-09-08 00:00:48cloudlinux2 fail2ban: 2026-09-08 00:00:56,796 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 8.231.214.24 - 2026-09-08 00:00:56cloudlinux2 fail2ban: 2026-09-08 00:01:03,297 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 109.61.112.93 - 2026-09-08 00:01:03cloudlinux2 fail2ban: 2026-09-08 00:02:22,442 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 188.213.202.106 - 2026-09-08 00:02:21cloudlinux2 fail2ban:
show less
Web App Attack