๐ฌ๐ง
openstrike.co.uk
2026-10-02 05:13:38
(23 minutes ago)
468 attacks on env grabbing URLs (type 2), PHP URLs, config grabbing URLs (type 2), shell probes, pa ...
show more
468 attacks on env grabbing URLs (type 2), PHP URLs, config grabbing URLs (type 2), shell probes, password/key grabbing URLs, env grabbing URLs, VC URLs, directory traversals:
GET /@fs/proc/self/environ?import&raw?? HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /config.yaml HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /.ssh/id_dsa HTTP/1.1
GET /etc/.env HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
show less
Hacking
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-10-01 05:41:55
(23 hours ago)
34.123.167.125 - - [01/Oct/2026:06:41:54 +0100] "GET /firebase-adminsdk.json HTTP/2.0" 401 410 "-" " ...
show more
34.123.167.125 - - [01/Oct/2026:06:41:54 +0100] "GET /firebase-adminsdk.json HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ฌ๐ง
Apache
2026-10-01 05:35:32
(1 day ago)
(mod_security) mod_security (id:930100) triggered by 34.123.167.125 (US/United States/125.167.123.34 ...
show more
(mod_security) mod_security (id:930100) triggered by 34.123.167.125 (US/United States/125.167.123.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-10-01 05:13:45
(1 day ago)
717 attacks on config grabbing URLs (type 2), env grabbing URLs (type 2), shell probes, directory tr ...
show more
717 attacks on config grabbing URLs (type 2), env grabbing URLs (type 2), shell probes, directory traversals, VC URLs, password/key grabbing URLs, env grabbing URLs, PHP URLs:
GET /src/amplifyconfiguration.json HTTP/1.1
GET /@fs/proc/self/environ?import&raw?? HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /..%2f.env HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /id_ecdsa HTTP/1.1
GET /ai/.env HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
show less
Hacking
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-10-01 04:52:00
(1 day ago)
34.123.167.125 - - [01/Oct/2026:05:52:00 +0100] "GET /i.php HTTP/2.0" 401 410 "-" "Mozilla/5.0 (comp ...
show more
34.123.167.125 - - [01/Oct/2026:05:52:00 +0100] "GET /i.php HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ฉ๐ช
dave
2026-10-01 03:41:53
(1 day ago)
threat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity ...
show more
threat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity/appsec-vpatch,crowdsecurity/vpatch-env-access observed_by=1_hosts hit_count=83 first_seen=2026-10-01T03:41:36Z last_seen=2026-10-01T03:41:53Z
show less
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-10-01 03:35:24
(1 day ago)
34.123.167.125 - - [01/Oct/2026:04:35:24 +0100] "GET /62mqrxsph7vk3oapezzj HTTP/2.0" 401 433 "-" "Mo ...
show more
34.123.167.125 - - [01/Oct/2026:04:35:24 +0100] "GET /62mqrxsph7vk3oapezzj HTTP/2.0" 401 433 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-10-01 03:13:15
(1 day ago)
34.123.167.125 - - [01/Oct/2026:04:13:15 +0100] "GET /config/storage.yml HTTP/2.0" 401 410 "-" "Mozi ...
show more
34.123.167.125 - - [01/Oct/2026:04:13:15 +0100] "GET /config/storage.yml HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ธ๐ฌ
simpeg-adm.bandung.go.id
2026-10-01 02:43:27
(1 day ago)
01/Oct/2026:02:43:26 +0000;34.123.167.125;"/z9x8c7v6b5-debug-trigger-vendors.wildlyinlove.co.uk"
01/ ...
show more
01/Oct/2026:02:43:26 +0000;34.123.167.125;"/z9x8c7v6b5-debug-trigger-vendors.wildlyinlove.co.uk"
01/Oct/2026:02:43:26 +0000;34.123.167.125;"/lib/terminal-xhr.php"
01/Oct/2026:02:43:26 +0000;34.123.167.125;"/f2jxl1uzkzxkfjtr2jub"
01/Oct/2026:02:43:26 +0000;34.123.167.125;"/h5f3woi76m39qgj6rmfy"
01/Oct/2026:02:43:26 +0000;34.123.167.125;"/.vite/manifest.json"
01/Oct/2026:02:43:26 +0000;34.123.167.125;"/dist/manifest.json"
01/Oct/2026:02:43:26 +0000;34.123.167.125;"/model/info"
...
show less
Web Spam
Brute-Force
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-10-01 02:28:30
(1 day ago)
34.123.167.125 - - [01/Oct/2026:03:28:30 +0100] "GET /config.json HTTP/2.0" 401 410 "-" "Mozilla/5.0 ...
show more
34.123.167.125 - - [01/Oct/2026:03:28:30 +0100] "GET /config.json HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ซ๐ท
โจ
2026-10-01 01:24:21
(1 day ago)
Domain : torbaywebdesign.co.uk
Rule : hack
2026-10-01 01:21:47 ***hidden-privacy*** GET /api/proc/se ...
show more
Domain : torbaywebdesign.co.uk
Rule : hack
2026-10-01 01:21:47 ***hidden-privacy*** GET /api/proc/self/environ - 443 - 34.123.167.125 HTTP/2 Mozilla/5.0 (compatible; MoonshotBot/1.0; https://kimi.ai/) - www.torbaywebdesign.co.uk 404 0 2 12892 500 96 - -
show less
Hacking
SQL Injection
Brute-Force
๐ซ๐ท
โจ
2026-10-01 00:54:08
(1 day ago)
Domain : redirect.netenergy.uk
Rule : env
2026-10-01 00:53:21 217.194.210.152 GET /@fs/app/.env raw? ...
show more
Domain : redirect.netenergy.uk
Rule : env
2026-10-01 00:53:21 217.194.210.152 GET /@fs/app/.env raw?? 443 - 34.123.167.125 HTTP/2 Mozilla/5.0 (compatible; cohere-ai; https://cohere.com/crawler) - www.visitcombemartin.co.uk 404 0 2 1530 602 96 - -
show less
Hacking
SQL Injection
๐ซ๐ท
โจ
2026-10-01 00:38:16
(1 day ago)
Domain : theway.org.uk
Rule : env
2026-10-01 00:37:25 ***hidden-privacy*** GET /assets../.env - 443 ...
show more
Domain : theway.org.uk
Rule : env
2026-10-01 00:37:25 ***hidden-privacy*** GET /assets../.env - 443 - 34.123.167.125 HTTP/2 Mozilla/5.0 (compatible; DeepSeekBot/1.0; https://www.deepseek.com/) - www.theway.org.uk 404 0 2 4878 407 105 - -
show less
Hacking
SQL Injection
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-30 23:08:00
(1 day ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01]
Hacking
SQL Injection
Web App Attack
Anonymous
2026-09-30 22:48:07
(1 day ago)
CrowdSec detection: crowdsecurity/http-probing
Web App Attack
Hacking