๐ฌ๐ง
openstrike.co.uk
2026-10-09 05:15:32
(3 hours ago)
9 attacks on password/key grabbing URLs:
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws ...
show more
9 attacks on password/key grabbing URLs:
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc HTTP/1.1
show less
Hacking
Anonymous
2026-10-09 04:56:19
(4 hours ago)
/cache/original/../.env
Web App Attack
๐ฆ๐น
services.org.pl
2026-10-09 03:38:29
(5 hours ago)
open() "/var/www/html/fjh65t98ezr5uisjd5qg" failed (2: No such file or directory), client: 136.110.3 ...
show more
open() "/var/www/html/fjh65t98ezr5uisjd5qg" failed (2: No such file or directory), client: 136.110.34.33, server: api.services.org.pl, request: "GET /fjh65t98ezr5uisjd5qg HTTP/1.1", host: "api.services.org.pl"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 01:17:13
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.110.34.33 (33.34.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.110.34.33 (33.34.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:17:06.326916 2026] [security2:error] [pid 2975:tid 2975] [client 136.110.34.33:53588] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thephysicsroom.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thephysicsroom.com"] [uri "/z9x8c7v6b5-debug-trigger-thephysicsroom.com"] [unique_id "ashAkn2tLPbxHZ_4HXSjCQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Serpentex
2026-10-09 01:07:33
(7 hours ago)
136.110.34.33 - - [09/Oct/2026:03:07:30 +0200] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/proc/self/environ H ...
show more
136.110.34.33 - - [09/Oct/2026:03:07:30 +0200] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/proc/self/environ HTTP/1.1" 400 150 "-" "-"
136.110.34.33 - - [09/Oct/2026:03:07:30 +0200] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env HTTP/1.1" 400 150 "-" "-"
136.110.34.33 - - [09/Oct/2026:03:07:32 +0200] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1" 400 150 "-" "-"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-10-09 01:07:21
(7 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-10-09 01:06:24
(8 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 136.110.34.33 (SG/Si ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 136.110.34.33 (SG/Singapore/33.34.110.136.bc.googleusercontent.com)
show less
Bad Web Bot
Anonymous
2026-10-09 01:04:14
(8 hours ago)
136.110.34.33 rolistore.com - [08/Oct/2026:19:04:11 -0600] "GET / HTTP/1.1" 403 158 "-" "Mozilla/5.0 ...
show more
136.110.34.33 rolistore.com - [08/Oct/2026:19:04:11 -0600] "GET / HTTP/1.1" 403 158 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"\n136.110.34.33 rolistore.com - [08/Oct/2026:19:04:11 -0600] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 403 158 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"\n136.110.34.33 rolistore.com - [08/Oct/2026:19:04:12 -0600] "GET /z9x8c7v6b5-debug-trigger-rolistore.com HTTP/1.1" 403 158 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"\n136.110.34.33 rolistore.com - [08/Oct/2026:19:04:12 -0600] "GET /huhdjomjgwj46es8tepz HTTP/1.1" 403 158 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"\n136.110.34.33 rolistore.com - [08/Oct/2026:19:04:12 -0600] "GET /qyheslobdyzymzlcg0nf HTTP/1.1" 403 158 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.c
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 00:47:08
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.110.34.33 (33.34.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.110.34.33 (33.34.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:47:03.551569 2026] [security2:error] [pid 17636:tid 17704] [client 136.110.34.33:57738] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||missmadlove.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "missmadlove.com"] [uri "/z9x8c7v6b5-debug-trigger-missmadlove.com"] [unique_id "asg5h2c580EggU0v6HGfOwAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
lindi
2026-10-09 00:39:43
(8 hours ago)
Probing for resource vulnerabilities
...
Web Spam
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
๐ฏ๐ต
Kinsei Engineering Inc.
2026-10-09 00:26:59
(8 hours ago)
nginx:Illicit login attempts to the CMS, or investigation into CMS plugins with vulnerabilities.
Brute-Force
Web Spam
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-09 00:19:53
(8 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 00:09:06
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.34.33 (33.34.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.34.33 (33.34.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:08:59.827803 2026] [security2:error] [pid 21904:tid 21904] [client 136.110.34.33:59656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kinhung.com"] [uri "/.htpasswd"] [unique_id "asgwmxzzpXc660P1lqjf0AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 23:08:42
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.110.34.33 (33.34.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.110.34.33 (33.34.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:08:34.667750 2026] [security2:error] [pid 17627:tid 17627] [client 136.110.34.33:49106] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kinesiologiaenmovimiento.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kinesiologiaenmovimiento.com"] [uri "/z9x8c7v6b5-debug-trigger-kinesiologiaenmovimiento.com"] [unique_id "asgicpMNCeYW6Q-9ct7bOgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-10-08 23:07:43
(9 hours ago)
Repeated requests for suspicious nonexistent URLs, for example: /z9x8c7v6b5-debug-trigger-kineme.net ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /z9x8c7v6b5-debug-trigger-kineme.net (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot")
show less
Web App Attack