🇬🇧
openstrike.co.uk
2026-09-08 05:13:59
(13 seconds ago)
2 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
Anonymous
2026-09-08 04:14:03
(1 hour ago)
35.240.20.72 - - [08/Sep/2026:06:13:57 +0200] "GET /_netrc HTTP/1.1" 404 30147
35.240.20.72 - - [08/ ...
show more
35.240.20.72 - - [08/Sep/2026:06:13:57 +0200] "GET /_netrc HTTP/1.1" 404 30147
35.240.20.72 - - [08/Sep/2026:06:13:58 +0200] "GET /docker-compose.yml HTTP/1.1" 404 28788
35.240.20.72 - - [08/Sep/2026:06:13:58 +0200] "GET /docker-compose.yaml HTTP/1.1" 404 28670
35.240.20.72 - - [08/Sep/2026:06:13:59 +0200] "GET /~/.aws/credentials HTTP/1.1" 404 28688
35.240.20.72 - - [08/Sep/2026:06:13:59 +0200] "GET /aws-credentials.json HTTP/1.1" 404 28791
35.240.20.72 - - [08/Sep/2026:06:13:59 +0200] "GET /credentials HTTP/1.1" 404 28830
35.240.20.72 - - [08/Sep/2026:06:14:00 +0200] "GET /credentials.json HTTP/1.1" 404 30443
35.240.20.72 - - [08/Sep/2026:06:14:00 +0200] "GET /gcp-credentials.json HTTP/1.1" 404 28890
35.240.20.72 - - [08/Sep/2026:06:14:01 +0200] "GET /application_default_credentials.json HTTP/1.1" 404 28670
35.240.20.72 - - [08/Sep/2026:06:14:01 +0200] "GET /config/aws.yml HTTP/1.1" 404 28812
...
show less
Web Spam
Web App Attack
🇫🇷
COMAITE
2026-09-08 01:12:19
(4 hours ago)
Suspicious URL access.
Web App Attack
🇧🇪
cmbplf
2026-09-08 00:53:32
(4 hours ago)
849 requests with url.path */.git/config
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 23:19:55
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.20.72 (72.20.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.20.72 (72.20.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 19:19:51.750943 2026] [security2:error] [pid 1054692:tid 1054704] [client 35.240.20.72:47530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sparkhypnotherapy.com"] [uri "/.git/config"] [unique_id "ap9Gl5ccLocYKtbGLd_rLwAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 22:27:03
(6 hours ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
🇫🇷
Baking333
2026-09-07 22:17:52
(6 hours ago)
[redacted] 35.240.20.72 - - [07/Sep/2026:23:17:51 +0100] "GET /.git/config HTTP/1.1" 302 6793 0/4771 ...
show more
[redacted] 35.240.20.72 - - [07/Sep/2026:23:17:51 +0100] "GET /.git/config HTTP/1.1" 302 6793 0/47713 "-" "Mozilla/5.0 (Linux; Android 15; SM-S936B) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/27.0 Chrome/135.0.0.0 Mobile Safari/537.36" [redacted] 35.240.20.72 - - [07/Sep/2026:23:17:51 +0100] "GET / HTTP/1.1" 200 8283 0/91523 "https://[redacted]/.git/config" "Mozilla/5.0 (Linux; Android 15; SM-S936B) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/27.0 Chrome/135.0.0.0 Mobile Safari/537.36"
show less
Bad Web Bot
Web App Attack
🇦🇺
2000cn.com.au
2026-09-07 22:15:22
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-07 22:13:04
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.20.72 (72.20.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.20.72 (72.20.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 18:13:00.363943 2026] [security2:error] [pid 31946:tid 31946] [client 35.240.20.72:38940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "natashahenry.co.uk"] [uri "/.git/config"] [unique_id "ap827KmWaHD3Xa07wJRnyQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-09-07 22:04:33
(7 hours ago)
Attempted access to sensitive endpoint (/.git/config) detected. Automated scan or unauthorized probi ...
show more
Attempted access to sensitive endpoint (/.git/config) detected. Automated scan or unauthorized probing.
show less
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-07 21:59:50
(7 hours ago)
Auto-ban: >3000 req/min op 2026-09-07
Web App Attack
SSH
Hacking
🇩🇪
Vegascosmetics
2026-09-07 21:42:46
(7 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.git (Match: /.git)
show less
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 21:26:23
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.20.72 (72.20.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.20.72 (72.20.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 17:26:16.952276 2026] [security2:error] [pid 19605:tid 19605] [client 35.240.20.72:42448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paulshorrock.com"] [uri "/.git/config"] [unique_id "ap8r-NxpCs3vOrIqYxIl2QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-07 21:18:21
(7 hours ago)
[08/Sep/2026:00:18:21 +0300] -- 35.240.20.72 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/ ...
show more
[08/Sep/2026:00:18:21 +0300] -- 35.240.20.72 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 21:07:28
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.20.72 (72.20.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.20.72 (72.20.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 17:07:23.284550 2026] [security2:error] [pid 2416898:tid 2416898] [client 35.240.20.72:33190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.adelaidapacific.com"] [uri "/.git/config"] [unique_id "ap8nix8dtG_XgOBeOP0AxQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack