🇺🇸
ambor
2026-09-02 13:24:21
(1 week ago)
L0ss Honeypot: Git configuration file access attempt. Path: /.git/config
Web App Attack
🇸🇪
vaia.cloud
2026-09-02 04:45:01
(1 week ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 04:36:45
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.243.47.147 (147.47.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.47.147 (147.47.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 00:36:40.123696 2026] [security2:error] [pid 10443:tid 10443] [client 35.243.47.147:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.coiledtubingdrilling.com"] [uri "/.git/config"] [unique_id "apen2IxWFzcnX8M9-bsORQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-02 00:47:05
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
masterguru
2026-09-02 00:45:16
(1 week ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.243.47.147 (US/United States/147.4 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.243.47.147 (US/United States/147.47.243.35.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-01 23:19:36
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 35.243.47.147 (147.47.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 35.243.47.147 (147.47.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 19:19:29.151794 2026] [security2:error] [pid 18170:tid 18170] [client 35.243.47.147:57880] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "tn.cescfoundation.org"] [uri "/api/.git/config"] [unique_id "apddgbaRsfJKcZlpAovPqQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
paulo.apoloni
2026-09-01 21:09:15
(1 week ago)
35.243.47.147 - - [01/Sep/2026:18:09:14 -0300] "GET /html/.git/config HTTP/1.1" 444 0 "-" "crusader- ...
show more
35.243.47.147 - - [01/Sep/2026:18:09:14 -0300] "GET /html/.git/config HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
35.243.47.147 - - [01/Sep/2026:18:09:14 -0300] "GET /wordpress/.git/config HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
35.243.47.147 - - [01/Sep/2026:18:09:14 -0300] "GET /.git/config HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
35.243.47.147 - - [01/Sep/2026:18:09:14 -0300] "GET /src/.git/config HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
35.243.47.147 - - [01/Sep/2026:18:09:14 -0300] "GET /public/.git/config HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-01 19:11:34
(1 week ago)
cloudlinux2 fail2ban: 2026-09-01 21:03:58,067 fail2ban.filter [1605]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-01 21:03:58,067 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 169.40.142.133 - 2026-09-01 21:03:58cloudlinux2 fail2ban: 2026-09-01 21:07:09,841 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 35.243.47.147 - 2026-09-01 21:07:09cloudlinux2 fail2ban: 2026-09-01 21:07:09,793 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 35.243.47.147 - 2026-09-01 21:07:09cloudlinux2 fail2ban: 2026-09-01 21:07:10,464 fail2ban.actions [1605]: NOTICE [plesk-modsecurity] Ban 35.243.47.147cloudlinux2 fail2ban: 2026-09-01 21:07:09,856 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 35.243.47.147 - 2026-09-01 21:07:09cloudlinux2 fail2ban: 2026-09-01 21:07:09,834 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 35.243.47.147 - 2026-09-01 21:07:09cloudlinux2 fail2ban: 2026-09-01 21:07:09,871 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 35.243.47.147 - 2026-09-01 21:07:09cloudlinux2 fail2b
show less
Brute-Force
🇳🇱
e.fierstra
2026-09-01 19:10:54
(1 week ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
FreeMyIP
2026-09-01 15:04:06
(1 week ago)
Automated fail2ban report: web application attack / scanning for exploitable paths.
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-01 08:28:23
(1 week ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 04:59:02
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.243.47.147 (147.47.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.47.147 (147.47.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:58:55.950424 2026] [security2:error] [pid 26506:tid 26506] [client 35.243.47.147:55618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trapper.biz"] [uri "/public/.git/config"] [unique_id "apZbj39s7-glRpUFyIKfHgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
gamabe
2026-09-01 03:24:00
(1 week ago)
Detected crowdsecurity/http-sensitive-files attack pattern. Reported by CrowdSec IDS.
Hacking
🇫🇷
dynamix
2026-09-01 02:16:43
(1 week ago)
Multiple WAF Violations
Web App Attack
🇮🇪
AutosOnShow
2026-08-31 20:13:04
(1 week ago)
blocked for webapp attack | path requested: /.git/config | seen at 2026-08-31 20:12:43.618 |
Web App Attack