🇦🇺
electronico
2026-09-05 11:21:33
(6 hours ago)
35.247.160.253 - - [05/Sep/2026:22:21:32 +1100] "GET /api/config.json HTTP/1.1" 404 7408 "-" "Mozill ...
show more
35.247.160.253 - - [05/Sep/2026:22:21:32 +1100] "GET /api/config.json HTTP/1.1" 404 7408 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
35.247.160.253 - - [05/Sep/2026:22:21:32 +1100] "GET /api/actuator/configprops HTTP/1.1" 404 7408 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
35.247.160.253 - - [05/Sep/2026:22:21:32 +1100] "GET /admin/phpinfo.php HTTP/1.1" 404 7408 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
35.247.160.253 - - [05/Sep/2026:22:21:32 +1100] "GET /api/credentials.json HTTP/1.1" 404 7408 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
35.247.160.253 - - [05/Sep/2026:22:21:32 +1100] "GET /api/docker-compose.yml HTTP/1.1" 404 7408 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
35.247.160.2
...
show less
Brute-Force
Web App Attack
🇬🇧
openstrike.co.uk
2026-09-05 05:13:59
(12 hours ago)
12 attacks on VC URLs:
GET /public/.git/config HTTP/1.1
Hacking
🇺🇸
mnsf
2026-09-05 02:05:05
(15 hours ago)
Too many Status 40X (12)
Scanning/Probing (24)
Brute-Force
Web App Attack
🇬🇧
ISPLtd
2026-09-04 22:36:40
(18 hours ago)
Sep 4 19:36:39 35.247.160.253 TCP SPT=40938 DPT=80 SYN
Sep 4 19:36:39 35.247.160.253 TCP SPT=40918 ...
show more
Sep 4 19:36:39 35.247.160.253 TCP SPT=40938 DPT=80 SYN
Sep 4 19:36:39 35.247.160.253 TCP SPT=40918 DPT=80 SYN
Sep 4 19:36:39 35.247.160.253 TCP SPT=40962 DPT=80 SYN
...
show less
DDoS Attack
🇩🇪
4server
2026-09-04 22:34:12
(18 hours ago)
[SatSep0500:34:09.9164272026][security2:error][pid738336:tid738339][client35.247.160.253:0]ModSecuri ...
show more
[SatSep0500:34:09.9164272026][security2:error][pid738336:tid738339][client35.247.160.253:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"risanamento-pareti-umide.ch.risanamento-funghi-muffa.ch\"][uri\"/app/.git/config\"][unique_id\"aptHYWfpV3duVOzbWrrlhQAAAUA\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 22:20:05
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.160.253 (253.160.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.160.253 (253.160.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 18:19:55.440695 2026] [security2:error] [pid 17936:tid 17936] [client 35.247.160.253:60582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "register-yacht-marshall-islands.com.yacht-register-holland.com"] [uri "/html/.git/config"] [unique_id "aptECwBA0bzvJ2aqrqabnwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-04 21:14:32
(20 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:09:28
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.160.253 (253.160.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.160.253 (253.160.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:09:21.837927 2026] [security2:error] [pid 13116:tid 13116] [client 35.247.160.253:45252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.eworld-media.com"] [uri "/var/www/.git/config"] [unique_id "apszgWTi_rjsEwyBdCsTkQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 20:13:26
(21 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
RH5
2026-09-04 12:32:12
(1 day ago)
Restricted URL probing (/.git) (UTC 2026-09-04 12:32)
Web App Attack
🇩🇪
FD-IX
2026-09-04 11:58:56
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:54:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.160.253 (253.160.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.160.253 (253.160.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:54:42.258295 2026] [security2:error] [pid 11178:tid 11194] [client 35.247.160.253:50462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jonathanarlook.com"] [uri "/api/.git/config"] [unique_id "apqxglxg6BX-wTqQPI-_ZwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 09:31:34
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-09-04 08:25:02
(1 day ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 04:34:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.160.253 (253.160.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.160.253 (253.160.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:34:10.499295 2026] [security2:error] [pid 20313:tid 20313] [client 35.247.160.253:46736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ontrek.com"] [uri "/var/www/.git/config"] [unique_id "appKQuQhf7kCo62byPCXDwAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack