๐ท๐ด
clauss
2026-09-02 06:10:49
(1 hour ago)
35.227.48.236 - - [02/Sep/2026:09:10:48 +0300] "GET /.git/config HTTP/1.1" 403 146 "-" "crusader-wor ...
show more
35.227.48.236 - - [02/Sep/2026:09:10:48 +0300] "GET /.git/config HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
35.227.48.236 - - [02/Sep/2026:09:10:48 +0300] "GET /public/.git/config HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 05:07:49
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.227.48.236 (236.48.227.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.48.236 (236.48.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 01:07:40.323227 2026] [security2:error] [pid 27364:tid 27364] [client 35.227.48.236:55380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.restaurantfixture.com"] [uri "/www/.git/config"] [unique_id "apevHNWAYo_p90GwQLVWCAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 02:06:37
(5 hours ago)
[ns31.kdns.gr] httpd-config-scan: sites=www.inpv.gr; logs=/var/log/httpd/domains/inpv.gr.log; sample ...
show more
[ns31.kdns.gr] httpd-config-scan: sites=www.inpv.gr; logs=/var/log/httpd/domains/inpv.gr.log; samples=/src/.git/config | /backend/.git/config | /www/.git/config
show less
Hacking
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-02 00:30:05
(7 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฉ๐ช
Trashware
2026-09-01 22:40:07
(9 hours ago)
Vulnerability scan
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 21:08:04
(10 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ณ๐ฑ
e.fierstra
2026-09-01 19:15:38
(12 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 18:30:27
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.227.48.236 (236.48.227.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.48.236 (236.48.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 14:30:21.855875 2026] [security2:error] [pid 18729:tid 18729] [client 35.227.48.236:58188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "myhomeflyer.com"] [uri "/www/.git/config"] [unique_id "apcZvTIyVLa5fR-74t89dQAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-09-01 17:51:27
(13 hours ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
Anonymous
2026-09-01 14:18:15
(17 hours ago)
35.227.48.236 - - [01/Sep/2026:14:18:15 +0000] "GET /src/.git/config HTTP/1.1" 403 4012 "-" "crusade ...
show more
35.227.48.236 - - [01/Sep/2026:14:18:15 +0000] "GET /src/.git/config HTTP/1.1" 403 4012 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
nyt
2026-09-01 09:37:50
(22 hours ago)
Sensitive File Probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:29:59
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.227.48.236 (236.48.227.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.48.236 (236.48.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:29:55.318529 2026] [security2:error] [pid 3520:tid 3520] [client 35.227.48.236:44338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thenotarymobile.com"] [uri "/www/.git/config"] [unique_id "apabE2FLrpU6ECJp_p41IwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cybertailor
2026-09-01 07:22:32
(1 day ago)
35.227.48.236 - - [01/Sep/2026:12:22:28 +0500] "GET /wordpress/.git/config HTTP/1.1" 404 146 "-" "cr ...
show more
35.227.48.236 - - [01/Sep/2026:12:22:28 +0500] "GET /wordpress/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
35.227.48.236 - - [01/Sep/2026:12:22:28 +0500] "GET /htdocs/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
35.227.48.236 - - [01/Sep/2026:12:22:28 +0500] "GET /.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
35.227.48.236 - - [01/Sep/2026:12:22:28 +0500] "GET /html/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
35.227.48.236 - - [01/Sep/2026:12:22:28 +0500] "GET /var/www/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Port Scan
๐ฉ๐ช
Vegascosmetics
2026-09-01 06:37:58
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.git (Match: /.git)
show less
Hacking
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-31 16:29:27
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack