🇺🇸
xmission.com
2026-09-05 11:55:23
(5 hours ago)
35.228.254.54 - - [05/Sep/2026:05:55:23 -0600] "\x16\x03\x01\x00\xEC\x01\x00\x00\xE8\x03\x03\xCC\x15 ...
show more
35.228.254.54 - - [05/Sep/2026:05:55:23 -0600] "\x16\x03\x01\x00\xEC\x01\x00\x00\xE8\x03\x03\xCC\x15\xF0L\xE14\xEEl\xEBti\xE4Y\x9F\xCB8\xF5\xB9\x22r%\x11\xBE\x10kD\xB5\x88\x02\xEEL/ \xB2z\xE0*\xEFLM\xB2x\xC5\xE5v\x809O\xD6%\xE8s\x09\xFB\xC7?\xF3y\xFDn\x8F\x13W\xE2\xEE\x00\x14\x13\x02\x13\x01\x13\x03\xC0,\xC0+\xCC\xA9\xC00\xC0/\xCC\xA8\x00\xFF\x01\x00\x00\x8B\x00#\x00\x00\x00-\x00\x02\x01\x01\x00\x05\x00\x05\x01\x00\x00\x00\x00\x00\x0B\x00\x02\x01\x00\x00\x10\x00\x0B\x00\x09\x08http/1.1\x00+\x00\x05\x04\x03\x04\x03\x03\x00\x17\x00\x00\x003\x00&\x00$\x00\x1D\x00 GD\xD9\xF1\x83F\xCC\xA3Ov\xA0\xCC\x8C-B5\x88\x17[\x93\xF4\x5C\xDA\x9D\x84\xC0\xA1q\x89A\xD39\x00" 400 150 "-" "-"
35.228.254.54 - - [05/Sep/2026:05:55:23 -0600] "\x16\x03\x01\x00\xEC\x01\x00\x00\xE8\x03\x03t\xBEN\xC6i+1\xDA\x01\xE5\x22jy\xC9\xE2\xF0\xA9\x05\xC2T)k\x11g\xD24\x7F\xDED\x95B^ \x7F\xB6m\x17@z\x18>\xCD\xCAfA\x01c\xFF\xFC\xFD\xE7\xF3\x1D\xAB\x1B\xEE\xC1--v\x16\xF1#_\xD8\x00\x14\x13\x02\x13\x01\x13\x03\xC0,\xC0+\xCC\xA9\
...
show less
Web App Attack
🇫🇷
ar2000
2026-09-05 07:43:52
(9 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇬🇧
openstrike.co.uk
2026-09-05 05:13:32
(11 hours ago)
12 attacks on VC URLs:
GET /src/.git/config HTTP/1.1
Hacking
🇺🇸
TPI-Abuse
2026-09-05 02:12:41
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.254.54 (54.254.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.254.54 (54.254.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 22:12:36.726989 2026] [security2:error] [pid 31791:tid 31791] [client 35.228.254.54:47832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.andrewrmarshall.com"] [uri "/public/.git/config"] [unique_id "apt6lEDdZAfSgxof0rEHdQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-05 01:39:34
(15 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 01:27:46
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.254.54 (54.254.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.254.54 (54.254.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 21:27:38.406089 2026] [security2:error] [pid 18040:tid 18040] [client 35.228.254.54:37888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lenorasflowers.lahamradio.com"] [uri "/wordpress/.git/config"] [unique_id "aptwCruz9ULDNkKR3KXAygAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-04 23:14:13
(17 hours ago)
[04/Sep/2026:19:14:12.662082 --0400] aptQxO9cKNm3mRVxXhwTZwAAAkM 35.228.254.54 54026 205.233.18.17 7 ...
show more
[04/Sep/2026:19:14:12.662082 --0400] aptQxO9cKNm3mRVxXhwTZwAAAkM 35.228.254.54 54026 205.233.18.17 7081
[04/Sep/2026:19:14:12.662515 --0400] aptQxO9cKNm3mRVxXhwTaAAAAlc 35.228.254.54 53978 205.233.18.17 7081
[04/Sep/2026:19:14:12.663312 --0400] aptQxO9cKNm3mRVxXhwTaQAAAlA 35.228.254.54 53970 205.233.18.17 7081
[04/Sep/2026:19:14:12.664097 --0400] aptQxO9cKNm3mRVxXhwTagAAAkE 35.228.254.54 53984 205.233.18.17 7081
[04/Sep/2026:19:14:12.664907 --0400] aptQxO9cKNm3mRVxXhwTawAAAko 35.228.254.54 53958 205.233.18.17 7081
...
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-04 22:36:08
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.254.54 (54.254.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.254.54 (54.254.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 18:36:04.191855 2026] [security2:error] [pid 6033:tid 6033] [client 35.228.254.54:59016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rphenry.com"] [uri "/www/.git/config"] [unique_id "aptH1O_b31U2Z3LGAaKy5AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:50:09
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.254.54 (54.254.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.254.54 (54.254.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:50:02.950246 2026] [security2:error] [pid 28058:tid 28058] [client 35.228.254.54:40670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.photojeniq.com"] [uri "/site/.git/config"] [unique_id "aps9CkW53csEl7-3bEumpAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:33:49
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.254.54 (54.254.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.254.54 (54.254.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:33:44.496799 2026] [security2:error] [pid 9130:tid 9130] [client 35.228.254.54:59850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.friends-ytc.com"] [uri "/app/.git/config"] [unique_id "aps5OKBzK-7RuLdVq5JlWgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:10:23
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.254.54 (54.254.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.254.54 (54.254.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:10:20.497074 2026] [security2:error] [pid 22962:tid 22962] [client 35.228.254.54:48474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.vigants.com"] [uri "/api/.git/config"] [unique_id "apszvIp-nACRN_Zp01b3RQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 20:38:23
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.254.54 (54.254.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.254.54 (54.254.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 16:38:19.927256 2026] [security2:error] [pid 22850:tid 22850] [client 35.228.254.54:60786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "directnic.games"] [uri "/src/.git/config"] [unique_id "apssO6BtGtQkYpkD2-5QiwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 18:37:43
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.254.54 (54.254.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.254.54 (54.254.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 14:37:40.240204 2026] [security2:error] [pid 28246:tid 28246] [client 35.228.254.54:51952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.studioarts.net"] [uri "/html/.git/config"] [unique_id "apsP9DTQoW9nE4fKbCMLogAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 17:09:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.228.254.54 (54.254.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.254.54 (54.254.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 13:09:47.596536 2026] [security2:error] [pid 8311:tid 8311] [client 35.228.254.54:58234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "old.renju.net"] [uri "/.git/config"] [unique_id "apr7W0NEYt2k-bI1ORWe8wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇪
AutosOnShow
2026-09-04 15:44:05
(1 day ago)
blocked for webapp attack | path requested: /.git/config | seen at 2026-09-04 15:43:07.064 |
Web App Attack