๐ฌ๐ง
openstrike.co.uk
2026-10-09 05:15:36
(17 hours ago)
147 attacks on env grabbing URLs, shell probes, VC URLs, config grabbing URLs (type 2), PHP URLs, di ...
show more
147 attacks on env grabbing URLs, shell probes, VC URLs, config grabbing URLs (type 2), PHP URLs, directory traversals, password/key grabbing URLs, env grabbing URLs (type 2):
GET /api/.env/public/.env HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /secrets.yml HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /.aws/credentials HTTP/1.1
GET /userfiles/x?path=../../../../proc/self/environ HTTP/1.1
show less
Hacking
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-10-09 02:54:26
(19 hours ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-10-09 01:59:54
(20 hours ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-201)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-09 01:48:16
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.182.219.213 (213.219.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.219.213 (213.219.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:48:10.588995 2026] [security2:error] [pid 32616:tid 32616] [client 34.182.219.213:34398] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||superlamb.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "superlamb.com"] [uri "/z9x8c7v6b5-debug-trigger-superlamb.com"] [unique_id "ashH2jVrcIP3hLX3BWkblQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
andypiper
2026-10-09 01:01:50
(21 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-09 00:45:59
(21 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 00:32:58
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.182.219.213 (213.219.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.219.213 (213.219.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:32:54.277760 2026] [security2:error] [pid 13998:tid 13998] [client 34.182.219.213:56930] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sunscreenz.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sunscreenz.com"] [uri "/z9x8c7v6b5-debug-trigger-sunscreenz.com"] [unique_id "asg2Nl_PZdjcrn4C07Q-GAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 00:13:43
(22 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
mnsf
2026-10-09 00:05:34
(22 hours ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐จ๐ฆ
Dunham Support
2026-10-09 00:00:41
(22 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.182.219.213 (US/United States/213.21 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.182.219.213 (US/United States/213.219.182.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-08 23:53:45
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.219.213 (213.219.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.219.213 (213.219.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:53:41.635039 2026] [security2:error] [pid 2888:tid 2888] [client 34.182.219.213:53468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sundollsforever.org"] [uri "/.env.example"] [unique_id "asgtBQ8E5CYf9fpanBAtowAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 23:32:22
(22 hours ago)
$f2bV_matches
Brute-Force
๐ฉ๐ช
zumbo.net
2026-10-08 22:49:50
(23 hours ago)
[Fri Oct 09 01:46:17.175665 2026] [proxy_fcgi:error] [pid 1524340:tid 1524350] [client 34.182.219.21 ...
show more
[Fri Oct 09 01:46:17.175665 2026] [proxy_fcgi:error] [pid 1524340:tid 1524350] [client 34.182.219.213:0] AH01071: Got error 'Primary script unknown'
[Fri Oct 09 01:49:48.386519 2026] [proxy_fcgi:error] [pid 1524339:tid 1524359] [client 34.182.219.213:0] AH01071: Got error 'Primary script unknown'
[Fri Oct 09 01:49:48.389196 2026] [proxy_fcgi:error] [pid 1524340:tid 1524384] [client 34.182.219.213:0] AH01071: Got error 'Primary script unknown'
[Fri Oct 09 01:49:48.390200 2026] [proxy_fcgi:error] [pid 1524339:tid 1524349] [client 34.182.219.213:0] AH01071: Got error 'Primary script unknown'
[Fri Oct 09 01:49:48.801638 2026] [proxy_fcgi:error] [pid 1524339:tid 1524345] [client 34.182.219.213:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
๐ง๐ท
radardatelecom
2026-10-08 22:27:15
(23 hours ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ฌ๐ง
AvonleaConsulting
2026-10-08 21:56:34
(1 day ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack