๐ฌ๐ง
openstrike.co.uk
2026-09-02 05:13:25
(18 hours ago)
17 attacks on deployment descriptor URLs, env grabbing URLs, password grabbing URLs, overlong URLs, ...
show more
17 attacks on deployment descriptor URLs, env grabbing URLs, password grabbing URLs, overlong URLs, PHP arg injection (type 2):
GET /portal/file?cmd=getFileLocal&fileid=..%2F..%2F..%2F..%2Fwebapps/nc_web/WEB-INF/web.xml HTTP/1.1
GET /.env%00 HTTP/1.1
GET /root/.aws/credentials HTTP/1.1
GET /?unix:AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
show less
Hacking
๐น๐ท
oalver
2026-09-01 10:37:32
(1 day ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature, nginx_auth_flood. Sources: nginx. Details: path_signature: request to /media../.git/config (HTTP 403); auth_flood: 8 requests to /content../.git/config (HTTP 403) within 60s. First seen: 2026-09-01. Risk score: 55/100.
show less
Web App Attack
๐ณ๐ฟ
Antinson
2026-09-01 06:13:31
(1 day ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
๐ฌ๐ท
setupgr
2026-09-01 05:41:49
(1 day ago)
(wplogin_block) Blocked WP-Login Access Attempt 213.182.213.57 (NL/The Netherlands/North Holland/Hal ...
show more
(wplogin_block) Blocked WP-Login Access Attempt 213.182.213.57 (NL/The Netherlands/North Holland/Halfweg/-/[AS214504 HOSTMAN]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 213.182.213.57 - - [01/Sep/2026:08:41:41 +0300] "GET /wp-login.php HTTP/2.0" 503 7137 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-01 05:40:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.182.213.57 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.182.213.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:40:06.780288 2026] [security2:error] [pid 7272:tid 7272] [client 213.182.213.57:49886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adona.info"] [uri "/events../.git/config"] [unique_id "apZlNiu_mFlcUzyHrxa43AAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 05:35:31
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
wordpresshosting.solutions
2026-09-01 05:33:35
(1 day ago)
Web app vulnerability scanning detected. Evidence: 213.182.213.57 - - [01/Sep/2026:05:33:35 +0000] " ...
show more
Web app vulnerability scanning detected. Evidence: 213.182.213.57 - - [01/Sep/2026:05:33:35 +0000] "GET /%2f.env.production HTTP/1.1" 404 5595 "https://[DOMAIN]/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36"
213.182.213.57 - - [01/Sep/2026:05:33:35 +0000] "GET /%2f.env HTTP/1.1" 404 5595 "https://[DOMAIN]/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36"
show less
Web App Attack
๐ง๐ช
taivas.nl
2026-09-01 05:32:12
(1 day ago)
Site scraper
Web App Attack
๐ณ๐ฑ
maxxsense
2026-09-01 05:24:11
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 213.182.213.57 (ES/Spain/-)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-01 04:59:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.182.213.57 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.182.213.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:59:03.730483 2026] [security2:error] [pid 16604:tid 16604] [client 213.182.213.57:3238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "achildsspace.com"] [uri "/lib../.git/config"] [unique_id "apZbl1fA4KOG2ovOnYhYDgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
AWW-Admin
2026-09-01 04:57:38
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 213.182.213.57 (ES/Spain/-)
SQL Injection
๐ซ๐ท
dwmp
2026-09-01 04:55:20
(1 day ago)
[01/Sep/2026:06:55:19.296437 +0200] apZat8-2chacAtoJHPjiLQAAAJY 213.182.213.57 55462 38.242.227.117 ...
show more
[01/Sep/2026:06:55:19.296437 +0200] apZat8-2chacAtoJHPjiLQAAAJY 213.182.213.57 55462 38.242.227.117 7081
[01/Sep/2026:06:55:19.325150 +0200] apZat8-2chacAtoJHPjiLwAAAJQ 213.182.213.57 55442 38.242.227.117 7081
[01/Sep/2026:06:55:19.329197 +0200] apZat67alaEScLdgWxvBjgAAAEM 213.182.213.57 55438 38.242.227.117 7081
...
show less
Brute-Force
SSH
๐จ๐ฆ
Mediashaker
2026-09-01 04:39:18
(1 day ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 213.182.213.57 (ES/Spain ...
show more
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 213.182.213.57 (ES/Spain/-)
show less
Port Scan
๐ฉ๐ช
maxpower
2026-09-01 04:35:02
(1 day ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 213.182.213.57 (ES/Spain/-): 1 in the la ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 213.182.213.57 (ES/Spain/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 213.182.213.57 - - [01/Sep/2026:06:34:59 +0200] "GET /.aws/credentials HTTP/1.1" 404 30700 "http://abruzzotour.it/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36" "213.182.213.57" host=abruzzotour.it
show less
Port Scan
๐บ๐ธ
agenciahypelab.com.br
2026-09-01 04:33:49
(1 day ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH