๐ฌ๐ง
openstrike.co.uk
2026-10-03 05:14:06
(10 minutes ago)
5 attacks on PHP URLs, site downloads (type 2), env grabbing URLs, Laravel URLs, VC URLs:
POST /vend ...
show more
5 attacks on PHP URLs, site downloads (type 2), env grabbing URLs, Laravel URLs, VC URLs:
POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
GET /demo HTTP/1.1
GET /.env HTTP/1.1
GET /_ignition/execute-solution HTTP/1.1
GET /.git/config HTTP/1.1
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-03 05:10:31
(13 minutes ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b8:e000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b8:e000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 01:10:22.543125 2026] [security2:error] [pid 7399:tid 7430] [client 2400:6180:10:200::e6b8:e000:59614] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "btoelsalvador.com"] [uri "/.env"] [unique_id "asCOPuoR-ven96SzNZ-GtAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
zUnlegit
2026-10-03 04:52:14
(32 minutes ago)
Automated web scanner requested sensitive path: /.git/config
Web App Attack
Anonymous
2026-10-03 04:31:32
(52 minutes ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-10-03 03:28:21
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b8:e000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b8:e000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 23:28:18.119417 2026] [security2:error] [pid 27607:tid 27607] [client 2400:6180:10:200::e6b8:e000:40812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bruskiewitz.com"] [uri "/.env"] [unique_id "asB2Uu_D2q--5ddu2-2nAwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-10-03 03:21:00
(2 hours ago)
[SatOct0305:20:58.3954702026][security2:error][pid3195166:tid3195185][client2400:6180:10:200::e6b8:e ...
show more
[SatOct0305:20:58.3954702026][security2:error][pid3195166:tid3195185][client2400:6180:10:200::e6b8:e000:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Matchof\"rx\^0\$\"against\"REQUEST_HEADERS:Content-Length\"required.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"88\"][id\"392301\"][rev\"8\"][msg\"Atomicorp.comWAFRules:RequestContainingContent\,butMissingContent-Typeheader\"][severity\"NOTICE\"][tag\"no_ar\"][hostname\"brunocampagna.com\"][uri\"/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php\"][unique_id\"asB0mtwBw5VbHc8peLje5gAAAAI\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
Hary74656
2026-10-03 02:39:58
(2 hours ago)
Fail2Ban on schani.hostmi.at: jail=apache-instablock, failures=1.
[client 2400:6180:10:200::e6b8:e00 ...
show more
Fail2Ban on schani.hostmi.at: jail=apache-instablock, failures=1.
[client 2400:6180:10:200::e6b8:e000] [realclient 2400:6180:10:200::e6b8:e000] [03/Oct/2026:04:39:57 +0200] [vhost schani.hostmi.at] 403 "GET /.env HTTP/2.0"
show less
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-03 02:38:48
(2 hours ago)
excessive HTTP 404 errors
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-03 02:26:04
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b8:e000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b8:e000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 22:25:56.495987 2026] [security2:error] [pid 15975:tid 15975] [client 2400:6180:10:200::e6b8:e000:34316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brookspowell.com"] [uri "/.env"] [unique_id "asBntBKAv4ErRwYe8OsAbQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 01:48:48
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b8:e000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b8:e000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 21:48:42.746575 2026] [security2:error] [pid 11198:tid 11198] [client 2400:6180:10:200::e6b8:e000:51820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brodyworks.com"] [uri "/.env"] [unique_id "asBe-tldOGuLHd-6ZCQ0jwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 00:52:25
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b8:e000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b8:e000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 20:52:19.129440 2026] [security2:error] [pid 14801:tid 14801] [client 2400:6180:10:200::e6b8:e000:65510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "britanniapilates.com"] [uri "/.env"] [unique_id "asBRw8hvj39m9i5NTevW_gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-03 00:48:21
(4 hours ago)
XSS Attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-03 00:08:55
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b8:e000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b8:e000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 20:08:51.964404 2026] [security2:error] [pid 25318:tid 25318] [client 2400:6180:10:200::e6b8:e000:55880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bright-ideas.keystroke.info"] [uri "/.env"] [unique_id "asBHk8NXFEJBvaEFbGm_IQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-02 22:55:45
(6 hours ago)
2400:6180:10:200::e6b8:e000 - - [03/Oct/2026:00:55:42 +0200] "POST /vendor/phpunit/phpunit/src/Util/ ...
show more
2400:6180:10:200::e6b8:e000 - - [03/Oct/2026:00:55:42 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/2.0" 404 303 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
2400:6180:10:200::e6b8:e000 - - [03/Oct/2026:00:55:42 +0200] "GET / HTTP/2.0" 200 847 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
2400:6180:10:200::e6b8:e000 - - [03/Oct/2026:00:55:42 +0200] "GET /wordpress HTTP/2.0" 404 325 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
2400:6180:10:200::e6b8:e000 - - [03/Oct/2026:00:55:42 +0200] "GET /.env HTTP/2.0" 404 303 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
2400:6180:10:200::e6b8:e000 - - [03/Oct/2026:00:55:42 +0200] "GET /wp HTTP/2.0" 404 303 "-" "Mozilla/5.0 (Windows NT 10.
show less
Web App Attack
Brute-Force
Anonymous
2026-10-02 20:59:09
(8 hours ago)
2400:6180:10:200::e6b8:e000 - - [03/Oct/2026:04:59:09 +0800] "GET /.git/config HTTP/1.1" 404 196 "-" ...
show more
2400:6180:10:200::e6b8:e000 - - [03/Oct/2026:04:59:09 +0800] "GET /.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack