๐ฌ๐ง
openstrike.co.uk
2026-05-28 05:13:43
(3 months ago)
145 attacks on deployment descriptor URLs, site downloads, password grabbing URLs, PHP URLs, too man ...
show more
145 attacks on deployment descriptor URLs, site downloads, password grabbing URLs, PHP URLs, too many concurrent requests, config grabbing URLs (type 2), config grabbing URLs:
GET /WEB-INF/web.xml HTTP/1.1
GET /db.zip HTTP/1.1
GET /.vscode/sftp.json HTTP/1.1
GET /wp-config.php HTTP/1.1
GET /config/database.php HTTP/1.1
GET /src/application.yml HTTP/1.1
GET /.htaccess HTTP/1.1
show less
Hacking
Web App Attack
Bad Web Bot
๐ณ๐ฑ
ConsulHosting
2026-05-27 14:27:16
(3 months ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ณ๐ฑ
Site.eu
2026-05-27 11:22:09
(3 months ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
XICTRON
2026-05-27 10:15:05
(3 months ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐ณ๐ฑ
Savvii
2026-05-27 09:16:58
(3 months ago)
20 attempts against mh-misbehave-ban on pf102962
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
s@ch@
2026-05-27 09:00:06
(3 months ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack
๐บ๐ธ
markawes
2026-05-27 08:15:15
(3 months ago)
[markis] Auto banned by Fail2Ban. Reason: Malicious web scan / attempted access to sensitive paths. ...
show more
[markis] Auto banned by Fail2Ban. Reason: Malicious web scan / attempted access to sensitive paths. Evidence:
34.182.200.42 - - [27/May/2026:09:15:14 +0100] "GET /actuator/trace HTTP/1.1" 404 3061 "-" "Mozilla/5.0 (X11; CrOS x86_64 12105.100.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.144 Safari/537.36"
34.182.200.42 - - [27/May/2026:09:15:14 +0100] "GET /actuator/auditevents HTTP/1.1" 404 3060 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.35 Safari/537.36"
34.182.200.42 - - [27/May/2026:09:15:14 +0100] "GET /actuator/env HTTP/1.1" 404 3060 "-" "Mozilla/5.0 (X11; Linux i686) AppleWebKit/534.34 (KHTML, like Gecko) QupZilla/1.2.0 Safari/534.34"
show less
Port Scan
Hacking
Web App Attack
๐ฉ๐ช
DEV-DNS
2026-05-27 03:17:15
(3 months ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ฉ๐ช
vmd56152.contaboserver.net
2026-05-27 03:07:36
(3 months ago)
[Wed May 27 05:07:33.838260 2026] [proxy_fcgi:error] [pid 2480050:tid 140373473089280] [client 34.18 ...
show more
[Wed May 27 05:07:33.838260 2026] [proxy_fcgi:error] [pid 2480050:tid 140373473089280] [client 34.182.200.42:45164] AH01071: Got error 'Primary script unknown'
[Wed May 27 05:07:33.839541 2026] [proxy_fcgi:error] [pid 2291122:tid 140373850564352] [client 34.182.200.42:45136] AH01071: Got error 'Primary script unknown'
[Wed May 27 05:07:33.856351 2026] [proxy_fcgi:error] [pid 2291122:tid 140373741524736] [client 34.182.200.42:45166] AH01071: Got error 'Primary script unknown'
[Wed May 27 05:07:33.857449 2026] [proxy_fcgi:error] [pid 2291122:tid 140374244824832] [client 34.182.200.42:45152] AH01071: Got error 'Primary script unknown'
[Wed May 27 05:07:33.860080 2026] [proxy_fcgi:error] [pid 2290889:tid 140373422765824] [client 34.182.200.42:45168] AH01071: Got error 'Primary script unknown'
[Wed May 27 05:07:33.867940 2026] [proxy_fcgi:error] [pid 2290890:tid 140374374557440] [client 34.182.200.42:45182] AH01071: Got error 'Primary script unknown'
[Wed May 27 05:07:34.382451 2026] [proxy
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-27 00:35:26
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 34.182.200.42 (42.200.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.200.42 (42.200.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 20:35:19.058363 2026] [security2:error] [pid 9044:tid 9044] [client 34.182.200.42:33574] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.kraftre.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.kraftre.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ahY8R98u5IgHgkQccVqwNQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
NewGastroline
2026-05-26 23:40:50
(3 months ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-05-26 23:02:34
(3 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-05-26 22:31:13
(3 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 21:16:05
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 34.182.200.42 (42.200.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.200.42 (42.200.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 17:15:57.286565 2026] [security2:error] [pid 845:tid 845] [client 34.182.200.42:50730] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.carterslawncare.net|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.carterslawncare.net"] [uri "/.config/gcloud/credentials.db"] [unique_id "ahYNjUC_kvFAYjfwoFeDRAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-05-26 20:52:38
(3 months ago)
Multiple WAF Violations
Web App Attack