๐ฌ๐ง
openstrike.co.uk
2026-10-09 05:15:18
(12 hours ago)
136 attacks on password/key grabbing URLs, env grabbing URLs (type 2), config grabbing URLs (type 2) ...
show more
136 attacks on password/key grabbing URLs, env grabbing URLs (type 2), config grabbing URLs (type 2), VC URLs, directory traversals, PHP URLs, env grabbing URLs, shell probes:
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/1.1
GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/proc/self/environ HTTP/1.1
GET /app-config.json HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 05:01:29
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.198.151 (151.198.186.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.198.151 (151.198.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 01:01:21.852552 2026] [security2:error] [pid 1279:tid 1279] [client 34.186.198.151:32906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sguard.co"] [uri "/build../.env"] [unique_id "ash1IWEfbfHA8UK7ZmhijQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 04:44:15
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.186.198.151 (151.198.186.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.186.198.151 (151.198.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 00:44:10.872438 2026] [security2:error] [pid 28668:tid 28668] [client 34.186.198.151:47562] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pghsea.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pghsea.com"] [uri "/z9x8c7v6b5-debug-trigger-pghsea.com"] [unique_id "ashxGgilvVGJPqiRFngpfgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hbrks
2026-10-09 04:42:00
(13 hours ago)
200 attack(s) detected, such as these: {"event":"web_block","ip":"34.186.198.151","host":"p4u.xyz"," ...
show more
200 attack(s) detected, such as these: {"event":"web_block","ip":"34.186.198.151","host":"p4u.xyz","request":"POST /flowise/api/v1/node-load-method/customMCP HTTP/2.0","user_agent":"","reason":"Status-404","timestamp":"2026-10-09T04:42:00 00:00","logentry":"p4u.xyz 34.186.198.151 - - [09/Oct/2026:04:42:00 0000] \"POST /flowise/api/v1/node-load-method/customMCP HTTP/2.0\" 404 0 \"-\" \"Mozilla/5.0 (compatible; cohere-ai; https://cohere.com/crawler)\" \"172.25.79.37:5000\""} * Report Details *: https://p4u.xyz/FCTK73LLZ1V/1* IP Details *: https://p4u.xyz/FCTK73LLZ1V/2
show less
Web Spam
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-09 04:21:37
(13 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.186.198.151 (151.198.186.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 34.186.198.151 (151.198.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 00:21:33.392791 2026] [security2:error] [pid 7088:tid 7088] [client 34.186.198.151:36652] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||mecme.co|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "mecme.co"] [uri "/api/fs/read"] [unique_id "ashrzSRWePn0PBd-sOWQ3gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
lns.bz
2026-10-09 04:05:01
(13 hours ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
๐บ๐ธ
infra-monitor
2026-10-09 04:00:07
(14 hours ago)
Automated ban via infra-monitor: suspicious-probe, mgmt-path-probe, crowdsecurity/http-cve-2021-4177 ...
show more
Automated ban via infra-monitor: suspicious-probe, mgmt-path-probe, crowdsecurity/http-cve-2021-41773, +5 more
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-09 03:52:30
(14 hours ago)
20 attempts against mh-misbehave-ban on onion
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-10-09 03:36:08
(14 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.186.198.151 (CA/C ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.186.198.151 (CA/Canada/Quebec/Montreal/151.198.186.34.bc.googleusercontent.com)
show less
Bad Web Bot
๐ฉ๐ช
palla89
2026-10-09 03:24:36
(14 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.186.198.151 (CA/Canada/151.198.186.3 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.186.198.151 (CA/Canada/151.198.186.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
Jarda_H
2026-10-09 03:19:43
(14 hours ago)
http-probing
Web App Attack
Anonymous
2026-10-09 03:18:49
(14 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ฉ๐ช
Hazzard
2026-10-09 03:18:00
(14 hours ago)
(PERMBLOCK) 34.186.198.151 (CA/Canada/Quebec/Montreal/151.198.186.34.bc.googleusercontent.com/[redac ...
show more
(PERMBLOCK) 34.186.198.151 (CA/Canada/Quebec/Montreal/151.198.186.34.bc.googleusercontent.com/[redacted]) has had more than 4 temp blocks
show less
Hacking
๐ณ๐ฑ
Savvii
2026-10-09 03:17:59
(14 hours ago)
20 attempts against mh-misbehave-ban on ethyl
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 03:17:08
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.186.198.151 (151.198.186.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.186.198.151 (151.198.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 23:16:59.529923 2026] [security2:error] [pid 3208:tid 3208] [client 34.186.198.151:57556] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||maeandtheguys.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "maeandtheguys.com"] [uri "/z9x8c7v6b5-debug-trigger-maeandtheguys.com"] [unique_id "ashcq40Ts_SrA03Hp9BnpgAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack