🇬🇧
openstrike.co.uk
2026-09-12 05:14:23
(13 hours ago)
14 attacks on password/key grabbing URLs:
GET /@fs/root/.aws/credentials?raw?? HTTP/1.1
Hacking
🇺🇸
TPI-Abuse
2026-09-12 04:47:36
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 207.175.154.84 (84.154.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.154.84 (84.154.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 00:47:31.608229 2026] [security2:error] [pid 17128:tid 17128] [client 207.175.154.84:41216] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.aspotoftea.com"] [uri "/.env"] [unique_id "aqTZY4fARgAWRLDSsph_twAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-11 23:47:57
(18 hours ago)
Excessive 404/403 errors
Brute-Force
🇩🇪
findlab
2026-09-11 18:35:01
(23 hours ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:22:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 207.175.154.84 (84.154.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.154.84 (84.154.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:22:34.721197 2026] [security2:error] [pid 4399:tid 4399] [client 207.175.154.84:43518] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asttechgroup.com"] [uri "/js../.env"] [unique_id "aqRG6nL0ct-WNH1yLgF8FgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇷
setupgr
2026-09-11 18:01:14
(1 day ago)
(mod_security) mod_security (id:11000011) triggered by 207.175.154.84 (BE/Belgium/Brussels Capital/B ...
show more
(mod_security) mod_security (id:11000011) triggered by 207.175.154.84 (BE/Belgium/Brussels Capital/Brussels/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Fri Sep 11 21:01:09.453657 2026] [security2:error] [pid 78446:tid 78549] [remote 207.175.154.84:39494] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 84.154.175.207.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "asteriassantorini.com"] [uri "/"] [unique_id "aqRB5eslN0BKVOiJdSmunwABDxQ"]
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-11 17:58:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 207.175.154.84 (84.154.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.154.84 (84.154.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:58:24.686989 2026] [security2:error] [pid 29290:tid 29290] [client 207.175.154.84:48740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "astariamedia.com"] [uri "/images../.env"] [unique_id "aqRBQMrirU4aIGjL9Ni_CwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-11 17:45:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇫🇷
masterguru
2026-09-11 17:35:34
(1 day ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-201)
show less
Bad Web Bot
🇫🇷
dynamix
2026-09-11 17:33:01
(1 day ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-11 17:29:26
(1 day ago)
Web application attack detected.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:16:19
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 207.175.154.84 (84.154.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 207.175.154.84 (84.154.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:16:14.052624 2026] [security2:error] [pid 29423:tid 29423] [client 207.175.154.84:33986] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aspechorizon.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aspechorizon.com"] [uri "/z9x8c7v6b5-debug-trigger-aspechorizon.com"] [unique_id "aqQ3Xmpczccd8t28ul6pMwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-11 17:05:27
(1 day ago)
Abuse Detected (12)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:00:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 207.175.154.84 (84.154.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.154.84 (84.154.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:00:13.959650 2026] [security2:error] [pid 31474:tid 31474] [client 207.175.154.84:48348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "askthetarotcards.com"] [uri "/.git/config"] [unique_id "aqQznedIrGIn76JsvMx5iQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 16:40:01
(1 day ago)
[web.zebs.ch] httpd-config-scan: sites=www.asiqual.com; logs=/var/log/httpd/domains/asiqual.com.log; ...
show more
[web.zebs.ch] httpd-config-scan: sites=www.asiqual.com; logs=/var/log/httpd/domains/asiqual.com.log; samples=/.aws/credentials | /.aws/config | /.git/config
show less
Hacking
Web App Attack