๐ฌ๐ง
openstrike.co.uk
2026-10-03 05:14:07
(3 days ago)
234 attacks on VC URLs, PHP URLs, env grabbing URLs (type 2), config grabbing URLs (type 2), directo ...
show more
234 attacks on VC URLs, PHP URLs, env grabbing URLs (type 2), config grabbing URLs (type 2), directory traversals, shell probes, password/key grabbing URLs, env grabbing URLs:
GET /.git/config HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /userfiles/x?path=../../../../proc/self/environ HTTP/1.1
GET /config/firebase-admin.json HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /.aws/credentials HTTP/1.1
GET /core/.env HTTP/1.1
show less
Hacking
Web App Attack
๐ธ๐ฌ
simpeg-adm.bandung.go.id
2026-10-03 04:29:13
(3 days ago)
03/Oct/2026:04:29:12 +0000;34.19.214.104;"/zo0ed0qhq0clj80ivk82"
03/Oct/2026:04:29:12 +0000;34.19.21 ...
show more
03/Oct/2026:04:29:12 +0000;34.19.214.104;"/zo0ed0qhq0clj80ivk82"
03/Oct/2026:04:29:12 +0000;34.19.214.104;"/d8hd482amykhgqleit2f"
03/Oct/2026:04:29:12 +0000;34.19.214.104;"/lib/terminal-xhr.php"
03/Oct/2026:04:29:12 +0000;34.19.214.104;"/.vite/manifest.json"
03/Oct/2026:04:29:12 +0000;34.19.214.104;"/dist/.vite/manifest.json"
03/Oct/2026:04:29:12 +0000;34.19.214.104;"/z9x8c7v6b5-debug-trigger-vendors.mashasakhno.com"
03/Oct/2026:04:29:12 +0000;34.19.214.104;"/dist/manifest.json"
...
show less
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
etu brutus
2026-10-02 19:22:37
(3 days ago)
34.19.214.104 has been banned for [WebApp Attack]
...
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 19:00:12
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.19.214.104 (104.214.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.214.104 (104.214.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 15:00:06.291703 2026] [security2:error] [pid 15783:tid 15783] [client 34.19.214.104:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mail-pmg.com"] [uri "/static../.env"] [unique_id "ar__Nvj2SvEpKb2Ex7lrzwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 17:54:51
(3 days ago)
34.19.214.104 - - [02/Oct/2026:19:54:50 +0200] "GET /asset-manifest.json HTTP/1.1" 404 448 "-" "Mozi ...
show more
34.19.214.104 - - [02/Oct/2026:19:54:50 +0200] "GET /asset-manifest.json HTTP/1.1" 404 448 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.19.214.104 - - [02/Oct/2026:19:54:50 +0200] "GET /asset-manifest.json HTTP/1.1" 404 252 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.19.214.104 - - [02/Oct/2026:19:54:50 +0200] "POST /lib/terminal-xhr.php HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.19.214.104 - - [02/Oct/2026:19:54:50 +0200] "GET /model/info HTTP/1.1" 404 448 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.19.214.104 - - [02/Oct/2026:19:54:50 +0200] "GET /model/info HTTP/1.1" 404 252 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.19.214.104 - - [02/Oct/2026:19:54:50 +0200] "GET /z9x8c7v6b5-debug-trigger-www.malizganipc
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-02 17:50:51
(3 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "ccbot" at REQUEST_HEADERS:User-Agent. (1100000-195)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-02 16:06:17
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.19.214.104 (104.214.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.214.104 (104.214.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 12:06:13.106948 2026] [security2:error] [pid 29329:tid 29345] [client 34.19.214.104:49970] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||maroontribe.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "maroontribe.com"] [uri "/z9x8c7v6b5-debug-trigger-maroontribe.com"] [unique_id "ar_WdfEBDmfN5P0vCxLakgAAAMI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 15:13:38
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.19.214.104 (104.214.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.214.104 (104.214.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:13:34.216212 2026] [security2:error] [pid 15892:tid 15892] [client 34.19.214.104:53232] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.matrixpercussiontrio.com|F|2"] [data ".matrixpercussiontrio.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.matrixpercussiontrio.com"] [uri "/z9x8c7v6b5-debug-trigger-www.matrixpercussiontrio.com"] [unique_id "ar_KHheZFu6EduiqYPjkjwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 14:41:38
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.19.214.104 (104.214.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.214.104 (104.214.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:41:32.698353 2026] [security2:error] [pid 28560:tid 28601] [client 34.19.214.104:58080] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.thebiglies.com|F|2"] [data ".thebiglies.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.thebiglies.com"] [uri "/z9x8c7v6b5-debug-trigger-www.thebiglies.com"] [unique_id "ar_CnIGE1rBu_ds00DE76QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-02 14:30:51
(3 days ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-196)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-02 14:11:43
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.19.214.104 (104.214.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.214.104 (104.214.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:11:36.711538 2026] [security2:error] [pid 970978:tid 970978] [client 34.19.214.104:55946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.maledon.com"] [uri "/.env.js"] [unique_id "ar-7mFz-ICf_BYEupEQ9IwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:54:44
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.19.214.104 (104.214.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.214.104 (104.214.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:54:40.694696 2026] [security2:error] [pid 15280:tid 15280] [client 34.19.214.104:57380] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.tonylai.com|F|2"] [data ".tonylai.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.tonylai.com"] [uri "/z9x8c7v6b5-debug-trigger-www.tonylai.com"] [unique_id "ar-3oC91KPQjp2RxxAgUlgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:21:27
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.19.214.104 (104.214.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.214.104 (104.214.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:21:23.443532 2026] [security2:error] [pid 13625:tid 13625] [client 34.19.214.104:54858] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.soviaenterprises.com"] [uri "/.env"] [unique_id "ar-v00JCGL1_iIdVy5ak8AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-10-02 13:16:16
(3 days ago)
Wordlist path sweep | method: POST, GET | path: /lib/terminal-xhr.php, /dist/.vite/manifest.json, /d ...
show more
Wordlist path sweep | method: POST, GET | path: /lib/terminal-xhr.php, /dist/.vite/manifest.json, /dist/manifest.json (+3 more) | ua: Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/), Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36, Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] ) (+2 more)
show less
Port Scan
Web App Attack
๐ฉ๐ช
updown.io
2026-10-02 13:06:40
(3 days ago)
{"level":"info","ts":1790946398.229689,"logger":"http.log.access.log1","msg":"handled request","requ ...
show more
{"level":"info","ts":1790946398.229689,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.19.214.104","remote_port":"51800","client_ip":"34.19.214.104","proto":"HTTP/2.0","method":"GET","host":"status.match2one.com","uri":"/config.js","headers":{"Accept":["*/*"],"Accept-Encoding":["gzip"],"Cookie":["REDACTED"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.match2one.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.001049395,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1790946398.2345045,"logger":"http.log.access.log1","msg":"handl
...
show less
DDoS Attack
Web App Attack