๐ฌ๐ง
openstrike.co.uk
2026-06-12 05:14:43
(3 hours ago)
4 attacks on deployment descriptor URLs, password grabbing URLs:
GET /WEB-INF/web.xml HTTP/1.1
GET / ...
show more
4 attacks on deployment descriptor URLs, password grabbing URLs:
GET /WEB-INF/web.xml HTTP/1.1
GET /.vscode/sftp.json HTTP/1.1
show less
Hacking
Anonymous
2026-06-12 02:14:58
(6 hours ago)
Aggressive web scan
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-06-11 21:56:18
(10 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
e.fierstra
2026-06-11 20:29:12
(11 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-06-11 18:31:53
(13 hours ago)
212 requests with url.path *credentials.json
206 requests with url.path *config.json
150 requests ...
show more
212 requests with url.path *credentials.json
206 requests with url.path *config.json
150 requests with url.path *compose.yml
147 requests with url.path *config.yml
134 requests with url.path *secrets.json
show less
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-06-11 14:34:38
(17 hours ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
masterguru
2026-06-11 10:37:54
(21 hours ago)
Restricted File Access Attempt. Matched phrase ".sql.gz" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ฉ๐ช
paissangroup
2026-06-11 09:42:58
(22 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
DEV-DNS
2026-06-11 09:23:30
(22 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ฌ๐ง
consul.to
2026-06-11 05:41:33
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ฆ๐น
penguin-solutions.at
2026-06-11 05:22:08
(1 day ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 03:57:20
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.17.146.97 (97.146.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.17.146.97 (97.146.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 23:57:14.119873 2026] [security2:error] [pid 22770:tid 22770] [client 34.17.146.97:60626] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||avanyupublishing.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "avanyupublishing.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aioyGs5H-kxXiCbtLgMlQwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 03:18:42
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.17.146.97 (97.146.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.17.146.97 (97.146.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 23:18:38.089063 2026] [security2:error] [pid 10150:tid 10150] [client 34.17.146.97:41090] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.inmaine.aromatherapyricebags.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.inmaine.aromatherapyricebags.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aiopDiK8W7cdGAPfCl_5TwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 01:44:05
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.17.146.97 (97.146.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.17.146.97 (97.146.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 21:44:00.292898 2026] [security2:error] [pid 30423:tid 30423] [client 34.17.146.97:55048] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tablerockfriends.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tablerockfriends.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aioS4Ec0SnTaTk1j7XS3twAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-06-10 22:24:22
(1 day ago)
[11/Jun/2026:00:24:22 +0200] 17811302623.416501 34.17.146.97 0 217.154.7.177 443
[11/Jun/2026:00:24: ...
show more
[11/Jun/2026:00:24:22 +0200] 17811302623.416501 34.17.146.97 0 217.154.7.177 443
[11/Jun/2026:00:24:22 +0200] 178113026240.708485 34.17.146.97 0 217.154.7.177 443
[11/Jun/2026:00:24:22 +0200] 178113026236.980547 34.17.146.97 0 217.154.7.177 443
[11/Jun/2026:00:24:22 +0200] 178113026251.558222 34.17.146.97 0 217.154.7.177 443
[11/Jun/2026:00:24:22 +0200] 178113026299.172473 34.17.146.97 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack