🇷🇴
iulianh
2026-09-04 18:34:50
(25 minutes ago)
80,443
Brute-Force
SSH
🇩🇪
barbarella
2026-09-04 14:02:17
(4 hours ago)
Multiple (12) times attack on http port 80: Attempted to access git files. (GET /htdocs/.git/config) ...
show more
Multiple (12) times attack on http port 80: Attempted to access git files. (GET /htdocs/.git/config)
14:02:17 Attempted to access git files. (GET /backend/.git/config)
14:02:17 Attempted to access git files. (GET /wordpress/.git/config)
14:02:17 Attempted to access git files. (GET /app/.git/config)
14:02:17 Attempted to access git files. (GET /var/www/.git/config)
14:02:17 Attempted to access git files. (GET /public/.git/config)
14:02:17 Attempted to access git files. (GET /.git/config)
14:02:17 Attempted to access git files. (GET /html/.git/config)
14:02:17 Attempted to access git files. (GET /src/.git/config)
show less
Web App Attack
🇿🇦
conure.sh
2026-09-04 09:45:21
(9 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
🇫🇷
✨
2026-09-04 09:32:04
(9 hours ago)
Domain : MailEnable WebMail
Rule : config
2026-09-04 09:30:26 ***hidden-privacy*** GET /app/.git/con ...
show more
Domain : MailEnable WebMail
Rule : config
2026-09-04 09:30:26 ***hidden-privacy*** GET /app/.git/config - 443 - 35.203.137.11 crusader-worker/1.0 - 404 8 0 1425 112 260 - -
show less
Hacking
SQL Injection
🇫🇷
Feelautom
2026-09-04 09:12:19
(9 hours ago)
[FeelAutom Auto-Ban] PathScan: /backend/.git/config (Score: 200)
Port Scan
🇺🇸
mnsf
2026-09-04 09:05:21
(9 hours ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:11:53
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.137.11 (11.137.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.137.11 (11.137.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:11:46.666349 2026] [security2:error] [pid 16204:tid 16204] [client 35.203.137.11:38362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ezekielproductions.com.monmouthbottleshop.com"] [uri "/api/.git/config"] [unique_id "appvMqSh9DXxb3yitFldbwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:24:49
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.137.11 (11.137.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.137.11 (11.137.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:24:44.089131 2026] [security2:error] [pid 21348:tid 21348] [client 35.203.137.11:39970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jahneting.com"] [uri "/htdocs/.git/config"] [unique_id "appWHL0mN4t59716wChdsQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
OptimusGO
2026-09-04 04:32:02
(14 hours ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-09-04 05:32:02 UTC
Log evidence:
35.203.137.11 - - [04/Sep/2026:05:32:02 +0100] "GET /var/www/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
35.203.137.11 - - [04/Sep/2026:05:32:02 +0100] "GET /api/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
35.203.137.11 - - [04/Sep/2026:05:32:02 +0100] "GET /html/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
show less
Port Scan
Brute-Force
🇮🇪
AutosOnShow
2026-09-04 03:01:07
(15 hours ago)
blocked for webapp attack | path requested: /.git/config | seen at 2026-09-04 03:00:39.194 |
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 02:33:13
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.137.11 (11.137.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.137.11 (11.137.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 22:33:09.209704 2026] [security2:error] [pid 30918:tid 30918] [client 35.203.137.11:33176] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ajdejano.janbloom-art.com"] [uri "/htdocs/.git/config"] [unique_id "apot5alndDQm1-5bQU8tHAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Gabriel Camargo
2026-09-04 01:33:56
(17 hours ago)
35.203.137.11 - - [03/Sep/2026:20:33:55 -0500] "GET /.git/config HTTP/1.1" 301 178 "-" "crusader-wor ...
show more
35.203.137.11 - - [03/Sep/2026:20:33:55 -0500] "GET /.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
35.203.137.11 - - [03/Sep/2026:20:33:55 -0500] "GET /src/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
35.203.137.11 - - [03/Sep/2026:20:33:55 -0500] "GET /api/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH
🇫🇷
masterguru
2026-09-04 01:10:50
(17 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 23:49:31
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.137.11 (11.137.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.137.11 (11.137.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:49:26.837075 2026] [security2:error] [pid 17811:tid 17811] [client 35.203.137.11:52314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spottedeaglearts.com"] [uri "/src/.git/config"] [unique_id "apoHhkOBf8YMYECSWEJVOAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 23:04:57
(19 hours ago)
35.203.137.11 - - [04/Sep/2026:01:04:57 +0200] "GET /htdocs/.git/config HTTP/1.1" 403 164 "-" "crusa ...
show more
35.203.137.11 - - [04/Sep/2026:01:04:57 +0200] "GET /htdocs/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.203.137.11 - - [04/Sep/2026:01:04:57 +0200] "GET /backend/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.203.137.11 - - [04/Sep/2026:01:04:57 +0200] "GET /html/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.203.137.11 - - [04/Sep/2026:01:04:57 +0200] "GET /var/www/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.203.137.11 - - [04/Sep/2026:01:04:57 +0200] "GET /wordpress/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.203.137.11 - - [04/Sep/2026:01:04:57 +0200] "GET /site/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.203.137.11 - - [04/Sep/2026:01:04:57 +0200] "GET /www/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.203.137.11 - - [04/Sep/2026:01:04:57 +0200] "GET /api/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.203.137.11 - - [04/Sep/2026:01:04:57 +0200] "GET /.git/config HTTP/1.1" 40
...
show less
Bad Web Bot
Web App Attack