🇫🇷
ELYAZ
2026-08-24 15:40:53
(2 weeks ago)
(y3) Failed access -byebye- from 35.194.221.249 (TW/Taiwan/249.221.194.35.bc.googleusercontent.com): ...
show more
(y3) Failed access -byebye- from 35.194.221.249 (TW/Taiwan/249.221.194.35.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
🇺🇸
CBJ
2026-08-24 15:35:29
(2 weeks ago)
fail2ban: apache-filepath-recon
...
Web App Attack
🇺🇸
RamSet
2026-08-24 15:30:43
(2 weeks ago)
[swy] HTTP-Probe on port 443 (via domain). 1 distinct paths probed in 2min. Sustained 1 req/min. Pat ...
show more
[swy] HTTP-Probe on port 443 (via domain). 1 distinct paths probed in 2min. Sustained 1 req/min. Paths: /.git/config
show less
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-08-24 15:26:12
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack
🇵🇱
Budyn
2026-08-24 15:25:38
(2 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: budyn.wtf | URI: /.git/config | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇩🇪
Blexyel
2026-08-24 15:25:38
(2 weeks ago)
35.194.221.249 - - [24/Aug/2026:17:25:37 +0200] "GET /.git/config HTTP/1.1" 404 435 "-" "Mozilla/5.0 ...
show more
35.194.221.249 - - [24/Aug/2026:17:25:37 +0200] "GET /.git/config HTTP/1.1" 404 435 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" "share.fomx.gay"
...
show less
Brute-Force
Web App Attack
🇺🇸
0tsystems
2026-08-24 15:24:06
(2 weeks ago)
Automated scan detected on 0t.systems: /.git
Web App Attack
🇸🇪
SkyDancer
2026-08-24 15:22:20
(2 weeks ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
🇺🇸
Actors.Bible
2026-08-24 15:21:42
(2 weeks ago)
Webapp Vulnerability Probing:
GET /.git/config
Web App Attack
🇹🇼
tye
2026-08-24 15:21:09
(2 weeks ago)
Wazuh Alert Evidence: 35.194.221.249 (35.194.221.249) - - [24/Aug/2026:23:21:06 +0800] "GET /.git/co ...
show more
Wazuh Alert Evidence: 35.194.221.249 (35.194.221.249) - - [24/Aug/2026:23:21:06 +0800] "GET /.git/config HTTP/1.1" 404 5188 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-24 15:17:20
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.194.221.249 (249.221.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.221.249 (249.221.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 11:17:12.363510 2026] [security2:error] [pid 6102:tid 6102] [client 35.194.221.249:65354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ladbc.club"] [uri "/.git/config"] [unique_id "aoxgeGuYewPbK20P40NQugAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-24 14:53:27
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.194.221.249 (249.221.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.221.249 (249.221.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 10:53:21.941991 2026] [security2:error] [pid 7346:tid 7346] [client 35.194.221.249:44482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelholdawayvideos.info"] [uri "/.git/config"] [unique_id "aoxa4dZM7-0N-WthI6InBgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-24 13:55:56
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.194.221.249 (249.221.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.221.249 (249.221.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 09:55:50.661129 2026] [security2:error] [pid 12591:tid 12591] [client 35.194.221.249:7244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "numbulary.org"] [uri "/.git/config"] [unique_id "aoxNZiwhoKcrwg9CijcTfwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-24 13:25:53
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.194.221.249 (249.221.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.221.249 (249.221.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 09:25:47.105067 2026] [security2:error] [pid 30094:tid 30094] [client 35.194.221.249:37358] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gbcwoodbine.org"] [uri "/.git/config"] [unique_id "aoxGW-l0SSl_iGq0lQqrnQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-24 13:05:52
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.194.221.249 (249.221.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.221.249 (249.221.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 09:05:44.388611 2026] [security2:error] [pid 26799:tid 26799] [client 35.194.221.249:1442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "decroos.org"] [uri "/.git/config"] [unique_id "aoxBqFR58xBHA9xFUaO09wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack