🇬🇧
openstrike.co.uk
2026-09-13 05:13:53
(42 minutes ago)
2 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
🇩🇪
Dentax
2026-09-12 22:17:36
(7 hours ago)
35.253.91.221 - - [13/Sep/2026:00:17:36 +0200] "GET /.git/config HTTP/1.1" 404 381 "-" "-"
...
Web App Attack
Anonymous
2026-09-12 22:07:02
(7 hours ago)
Automated web scanner. Requested suspicious paths: /.git/config. UTC: 2026-09-12 21:36:52.
Web App Attack
🇺🇸
mnsf
2026-09-12 22:05:08
(7 hours ago)
Abuse Detected (10)
Brute-Force
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-12 21:59:23
(7 hours ago)
Auto-ban: >3000 req/min op 2026-09-12
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-12 21:50:46
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.253.91.221 (221.91.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.91.221 (221.91.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 17:50:40.592177 2026] [security2:error] [pid 22350:tid 22350] [client 35.253.91.221:44162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rfinderradios.suffolksystems.com"] [uri "/.git/config"] [unique_id "aqXJMBYcHcuk7eijb9oZYgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
iulianh
2026-09-12 21:44:41
(8 hours ago)
80,443
Brute-Force
SSH
🇺🇸
ambor
2026-09-12 21:37:55
(8 hours ago)
Attack type: wordpress_attack_attempt | Target: /.git/config | Country: US
Web App Attack
Brute-Force
🇺🇸
TPI-Abuse
2026-09-12 21:35:13
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.253.91.221 (221.91.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.91.221 (221.91.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 17:35:08.430879 2026] [security2:error] [pid 72220:tid 72220] [client 35.253.91.221:38336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rewirenetworks.com"] [uri "/.git/config"] [unique_id "aqXFjBxr2JV_Rr9RUBUUnwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ksol-hostmaster
2026-09-12 21:26:38
(8 hours ago)
2026/09/12 23:26:36 [error] 73904#159237: *5744654 access forbidden by rule, client: 35.253.91.221, ...
show more
2026/09/12 23:26:36 [error] 73904#159237: *5744654 access forbidden by rule, client: 35.253.91.221, server: revolutionbim.com, request: "GET /.git/config HTTP/1.1", host: "revolutionbim.com"
...
show less
Web Spam
🇦🇺
2000cn.com.au
2026-09-12 21:12:39
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-12 20:32:38
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.253.91.221 (221.91.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.91.221 (221.91.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 16:32:30.881862 2026] [security2:error] [pid 21335:tid 21335] [client 35.253.91.221:49404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "retiredengineers.net"] [uri "/.git/config"] [unique_id "aqW23pTYXnNRLF6wNBH0eQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 20:07:07
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.253.91.221 (221.91.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.91.221 (221.91.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 16:07:00.442077 2026] [security2:error] [pid 25403:tid 25403] [client 35.253.91.221:59836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "restest.rayeliotschwartz.com"] [uri "/.git/config"] [unique_id "aqWw5BMQj0GdfbBpdAY5UgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-12 19:44:58
(10 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇧🇬
Stoyko Stoykov
2026-09-12 19:40:11
(10 hours ago)
35.253.91.221 - - [12/Sep/2026:22:40:11 +0300] "GET /.git/config HTTP/1.1" 404 0 "-" "-"
...
Hacking
Web App Attack