๐ฌ๐ง
openstrike.co.uk
2026-09-25 05:14:50
(9 hours ago)
1671 attacks on VC URLs, directory traversals, PHP arg injection (type 2), password/key grabbing URL ...
show more
1671 attacks on VC URLs, directory traversals, PHP arg injection (type 2), password/key grabbing URLs, PHP URLs, config grabbing URLs (type 2), env grabbing URLs (type 2), env grabbing URLs:
GET /.git/HEAD HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /index.php?s=index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=file_get_contents&vars[1][]=/proc/self/environ HTTP/1.1
GET /.ssh/id_ed25519 HTTP/1.1
POST /icecoder/lib/terminal-xhr.php HTTP/1.1
GET /config/database.yml HTTP/1.1
GET /appearance/../../proc/self/environ HTTP/1.1
GET //.env HTTP/1.1
show less
Hacking
Web App Attack
๐ฌ๐ง
bensmithurst
2026-09-24 20:11:24
(18 hours ago)
34.12.139.100 - - [24/Sep/2026:20:11:24 +0000] "GET /public/plugins/alertlist/../../../../../../../. ...
show more
34.12.139.100 - - [24/Sep/2026:20:11:24 +0000] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 400 150 "-" "-"
34.12.139.100 - - [24/Sep/2026:20:11:24 +0000] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/proc/self/environ HTTP/1.1" 400 150 "-" "-"
34.12.139.100 - - [24/Sep/2026:20:11:24 +0000] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/proc/self/environ HTTP/1.1" 400 150 "-" "-"
34.12.139.100 - - [24/Sep/2026:20:11:24 +0000] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env HTTP/1.1" 400 150 "-" "-"
... [host=LAN***]
show less
Web App Attack
๐ฌ๐ง
pinguin
2026-09-24 19:51:44
(18 hours ago)
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /sw.js
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-09-24 19:09:30
(19 hours ago)
Aggressive web scan
Web App Attack
Anonymous
2026-09-24 17:57:36
(20 hours ago)
CrowdSec detection: crowdsecurity/http-probing
Web App Attack
Hacking
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-24 13:06:00
(1 day ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01]
Hacking
SQL Injection
Web App Attack
๐ฉ๐ช
rh24
2026-09-24 08:33:53
(1 day ago)
(badbots) Bad bot user-agent [redacted] from 34.12.139.100 (100.139.12.34.bc.googleusercontent.com)
Hacking
๐ซ๐ท
spot
2026-09-24 06:36:06
(1 day ago)
34.12.139.100 - - [24/Sep/2026:07:36:01 +0100] "GET /secrets.env HTTP/1.1" 403 4646 "-" "Mozilla/5.0 ...
show more
34.12.139.100 - - [24/Sep/2026:07:36:01 +0100] "GET /secrets.env HTTP/1.1" 403 4646 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
...
show less
Web App Attack
VPN IP
๐ซ๐ฎ
Christopher Hughes
2026-09-24 06:09:00
(1 day ago)
34.12.139.100 - - [24/Sep/2026:07:08:59 +0100] "GET /config/firebase-admin.json HTTP/2.0" 404 224 "- ...
show more
34.12.139.100 - - [24/Sep/2026:07:08:59 +0100] "GET /config/firebase-admin.json HTTP/2.0" 404 224 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-24 06:00:03
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
Mendip_Defender
2026-09-24 05:55:25
(1 day ago)
34.12.139.100 - - [24/Sep/2026:06:55:41 +0100] "GET /users/login HTTP/1.1" 404 6476 "-" "Mozilla/5.0 ...
show more
34.12.139.100 - - [24/Sep/2026:06:55:41 +0100] "GET /users/login HTTP/1.1" 404 6476 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.12.139.100 - - [24/Sep/2026:06:55:41 +0100] "GET /user/login HTTP/1.1" 404 6476 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.12.139.100 - - [24/Sep/2026:06:55:41 +0100] "GET /admin HTTP/1.1" 404 6476 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
๐ฉ๐ช
33three
2026-09-24 05:49:46
(1 day ago)
Fail2Ban jail WebAttack triggered
Brute-Force
๐ณ๐ฑ
Savvii
2026-09-24 05:23:05
(1 day ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-09-24 05:14:34
(1 day ago)
3905 attacks on PHP arg injection (type 2), config grabbing URLs (type 2), VC URLs, PHP URLs, passwo ...
show more
3905 attacks on PHP arg injection (type 2), config grabbing URLs (type 2), VC URLs, PHP URLs, password/key grabbing URLs, env grabbing URLs (type 2), env grabbing URLs, directory traversals:
GET /index.php?s=index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=file_get_contents&vars[1][]=/proc/self/environ HTTP/1.1
GET /settings.json HTTP/1.1
GET /.git/HEAD HTTP/1.1
POST /icecoder/lib/terminal-xhr.php HTTP/1.1
GET /.aws/credentials HTTP/1.1
GET /static/../../../a/../../../../proc/self/environ HTTP/1.1
GET /static/../../../a/../../../../.env HTTP/1.1
GET /..%2f.env HTTP/1.1
show less
Hacking
Web App Attack
๐ฌ๐ง
Apache
2026-09-24 03:46:14
(1 day ago)
(mod_security) mod_security (id:933150) triggered by 34.12.139.100 (100.139.12.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:933150) triggered by 34.12.139.100 (100.139.12.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
SSH
Web App Attack