๐ฌ๐ง
openstrike.co.uk
2026-10-09 05:15:40
(40 minutes ago)
147 attacks on PHP URLs, directory traversals, VC URLs, config grabbing URLs (type 2), shell probes, ...
show more
147 attacks on PHP URLs, directory traversals, VC URLs, config grabbing URLs (type 2), shell probes, env grabbing URLs, env grabbing URLs (type 2), password/key grabbing URLs:
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /.git/config HTTP/1.1
GET /secrets.yml HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /frontend/.env HTTP/1.1
GET /userfiles/x?path=../../../../proc/self/environ HTTP/1.1
GET /.git-credentials HTTP/1.1
show less
Web App Attack
Hacking
๐ฉ๐ช
Hary74656
2026-10-08 22:54:07
(7 hours ago)
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3.
[earlier text truncated]
e. [file ...
show more
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3.
[earlier text truncated]
e. [file "/opt/owasp-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.30.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "admin.aschi.at"] [uri "/docker-compose.yml"] [unique_id "asgfD5zwPtO0FdoQGLJj7wAADRA"]
[Fri Oct 09 00:54:07.162866 2026] [vhost schani.hostmi.at] [security2:error] [pid 528611:tid 139920625903296] [client 34.187.14.39:46872] [realclient 34.187.14.39:46872] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/opt/owasp-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [ver "OWASP_CRS/4.30.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "admin.aschi.at"] [uri "/login"] [unique_id "asgfD5zwPtO0FdoQGLJj7gAADRI"]
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 22:10:41
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.187.14.39 (39.14.187.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.14.39 (39.14.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 18:10:37.924866 2026] [security2:error] [pid 7337:tid 7337] [client 34.187.14.39:51558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stamford.org"] [uri "/.htpasswd"] [unique_id "asgU3QoLilxg1e08OacvngAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Mediashaker
2026-10-08 22:07:53
(7 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.187.14.39 (39.14.187.34.bc.googleuse ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.187.14.39 (39.14.187.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
kkw
2026-10-08 21:59:56
(7 hours ago)
[REDACTED] 34.187.14.39 - - [08/Oct/2026:23:59:56 +0200] "GET /.ssh/id_rsa HTTP/2.0" 404 366 "-" "Mo ...
show more
[REDACTED] 34.187.14.39 - - [08/Oct/2026:23:59:56 +0200] "GET /.ssh/id_rsa HTTP/2.0" 404 366 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-10-08 21:34:11
(8 hours ago)
Scan of vulnerable files
Web App Attack
Anonymous
2026-10-08 21:09:27
(8 hours ago)
Blocked by ModSec and CSF
Port Scan
๐ฌ๐ง
consul.to
2026-10-08 20:56:31
(9 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 20:55:58
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.187.14.39 (39.14.187.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.187.14.39 (39.14.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 16:55:53.680186 2026] [security2:error] [pid 16870:tid 16870] [client 34.187.14.39:52702] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lynellejonsson.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lynellejonsson.com"] [uri "/z9x8c7v6b5-debug-trigger-lynellejonsson.com"] [unique_id "asgDWdmq46Z2jNxb25ifvAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 20:49:31
(9 hours ago)
Aggressive web scan
Web App Attack
๐ฉ๐ช
Hazzard
2026-10-08 20:10:45
(9 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted]): (CF_ENABLE)
Bad Web Bot
๐ฉ๐ช
rh24
2026-10-08 19:48:49
(10 hours ago)
(badbots) Bad bot user-agent [redacted] from 34.187.14.39 (39.14.187.34.bc.googleusercontent.com)
Hacking
๐ฉ๐ช
itsolon
2026-10-08 19:38:28
(10 hours ago)
[08/Oct/2026:21:38:27 +0200] 179148830726.065279 34.187.14.39 0 217.154.7.177 443
[08/Oct/2026:21:38 ...
show more
[08/Oct/2026:21:38:27 +0200] 179148830726.065279 34.187.14.39 0 217.154.7.177 443
[08/Oct/2026:21:38:27 +0200] 179148830768.699584 34.187.14.39 0 217.154.7.177 443
[08/Oct/2026:21:38:27 +0200] 179148830793.686266 34.187.14.39 0 217.154.7.177 443
[08/Oct/2026:21:38:27 +0200] 179148830796.985311 34.187.14.39 0 217.154.7.177 443
[08/Oct/2026:21:38:27 +0200] 179148830781.113419 34.187.14.39 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐จ๐ฆ
Anytech
2026-10-08 19:35:07
(10 hours ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
๐ณ๐ฑ
Savvii
2026-10-08 19:25:03
(10 hours ago)
20 attempts against mh-misbehave-ban on pyrus
Brute-Force
Bad Web Bot
Web App Attack