๐ฌ๐ง
openstrike.co.uk
2026-09-23 05:14:53
(5 hours ago)
2287 attacks on config grabbing URLs (type 2), env grabbing URLs, VC URLs, password/key grabbing URL ...
show more
2287 attacks on config grabbing URLs (type 2), env grabbing URLs, VC URLs, password/key grabbing URLs, directory traversals, PHP arg injection (type 2), env grabbing URLs (type 2), PHP URLs:
GET /app-config.json HTTP/1.1
GET /.env.js HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/1.1
GET /..%2f.env HTTP/1.1
GET /index.php?s=index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=env HTTP/1.1
GET /_image?href=/proc/self/environ HTTP/1.1
POST /icecoder/lib/terminal-xhr.php HTTP/1.1
show less
Hacking
Web App Attack
๐ซ๐ท
โจ
2026-09-23 02:41:11
(7 hours ago)
Domain : pinewood-finance.co.uk
Rule : env
2026-09-23 02:40:20 W3SVC94 PLESK72 ***hidden-privacy*** ...
show more
Domain : pinewood-finance.co.uk
Rule : env
2026-09-23 02:40:20 W3SVC94 PLESK72 ***hidden-privacy*** GET /.env.prod - 443 - 207.175.173.60 HTTP/2.0 Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; https://zhipuai.cn/) _fbp=fb.1.1.7901312194E+12.1528797745.AQECAQMB; ASP.NET_SessionId=qrvm0i0tvhsdsjjkosnw1tsl - www.pinewood-finance.co.uk 404 0 2 1558 502 5 - -
show less
Hacking
SQL Injection
๐ฌ๐ง
gws-hostmaster
2026-09-23 01:28:50
(8 hours ago)
ModSecurity OWASP CRS (Anomaly Score: 45): HTTP header is restricted by policy (/x-middleware-subreq ...
show more
ModSecurity OWASP CRS (Anomaly Score: 45): HTTP header is restricted by policy (/x-middleware-subrequest/);JavaScript Prototype Pollution;JSON-Based SQL Injection;Node.js Injection Attack 1/2;OS File Access Attempt;Remote Command Execution: Unix Shell Code Found;Restricted File Access Attempt;URL file extension is restricted by policy;
show less
Web App Attack
๐ฌ๐ง
Greg Poulson
2026-09-23 01:04:02
(9 hours ago)
Our website was hit by this DDOS at a rate of 325 in 5 minutes.
DDoS Attack
Web Spam
Brute-Force
๐ฌ๐ง
blik2108
2026-09-22 23:26:16
(10 hours ago)
www.blacknell.co.uk:443 207.175.173.60 - - [23/Sep/2026:00:26:09 +0100] "GET /asset-manifest.json HT ...
show more
www.blacknell.co.uk:443 207.175.173.60 - - [23/Sep/2026:00:26:09 +0100] "GET /asset-manifest.json HTTP/1.1" 404 13641 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
www.blacknell.co.uk:443 207.175.173.60 - - [23/Sep/2026:00:26:09 +0100] "GET /webpack-stats.json HTTP/1.1" 404 13641 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
www.blacknell.co.uk:443 207.175.173.60 - - [23/Sep/2026:00:26:09 +0100] "GET /dist/manifest.json HTTP/1.1" 404 13641 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
www.blacknell.co.uk:443 207.175.173.60 - - [23/Sep/2026:00:26:09 +0100] "GET /2y8fj69bvs6ajs8qmyfb HTTP/1.1" 404 13641 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
www.blacknell.co.uk:443 207.175.173.60 - - [23/Sep/2026:00:26:09 +0100] "GET /static/manifest.
...
show less
Brute-Force
๐ณ๐ฑ
ConsulHosting
2026-09-22 21:37:51
(12 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ฌ๐ง
gurnip
2026-09-22 18:59:14
(15 hours ago)
Vulnerability probe of page /api, not found on server.
Brute-Force
Web App Attack
๐ฌ๐ง
noise.agency
2026-09-22 17:29:34
(16 hours ago)
207.175.173.60 (BE/Belgium/60.173.175.207.bc.googleusercontent.com), more than 10 Apache 403 hits
Hacking
๐ณ๐ฑ
Roderic
2026-09-22 17:13:54
(17 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐ซ๐ฎ
as211431.net
2026-09-22 16:06:30
(18 hours ago)
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/2 ...
show more
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/2 (GET method)
Endpoint: /app_dev.php/_profiler
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
AvonleaConsulting
2026-09-22 14:55:55
(19 hours ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
๐ฌ๐ง
SilverZippo
2026-09-22 13:30:52
(20 hours ago)
Web App Attack
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-22 13:20:16
(20 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-22 13:12:37
(21 hours ago)
207.175.173.60 - - [22/Sep/2026:15:12:35 +0200] "GET /dist/.env HTTP/2.0" 404 294 "-" "DuckAssistBot ...
show more
207.175.173.60 - - [22/Sep/2026:15:12:35 +0200] "GET /dist/.env HTTP/2.0" 404 294 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
207.175.173.60 - - [22/Sep/2026:15:12:35 +0200] "GET /core/.env HTTP/2.0" 403 297 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email])"
207.175.173.60 - - [22/Sep/2026:15:12:35 +0200] "GET /.aws/credentials HTTP/2.0" 404 294 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
207.175.173.60 - - [22/Sep/2026:15:12:35 +0200] "GET /.aws/config HTTP/2.0" 404 294 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
207.175.173.60 - - [22/Sep/2026:15:12:35 +0200] "GET /.git/HEAD HTTP/2.0" 403 297 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
207.175.173.60 - - [22/Sep/2026:15:12:35 +0200] "GET /.git-credentials HTTP/2.0" 403 297 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
207.175.173.60 - - [22/Sep/2026:15:12:35 +0200] "GET /.git/config HTT
show less
Bad Web Bot
๐ฌ๐ง
gws-hostmaster
2026-09-22 12:53:59
(21 hours ago)
ModSecurity OWASP CRS (Anomaly Score: 45): HTTP header is restricted by policy (/x-middleware-subreq ...
show more
ModSecurity OWASP CRS (Anomaly Score: 45): HTTP header is restricted by policy (/x-middleware-subrequest/);JavaScript Prototype Pollution;JSON-Based SQL Injection;Node.js Injection Attack 1/2;OS File Access Attempt;Remote Command Execution: Unix Shell Code Found;
show less
Web App Attack