๐ฌ๐ง
openstrike.co.uk
2026-10-09 05:14:43
(14 hours ago)
156 attacks on env grabbing URLs, shell probes, directory traversals, PHP URLs, VC URLs, config grab ...
show more
156 attacks on env grabbing URLs, shell probes, directory traversals, PHP URLs, VC URLs, config grabbing URLs (type 2), env grabbing URLs (type 2), password/key grabbing URLs:
GET /_nuxt/../.env HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /config/gcp-credentials.json HTTP/1.1
GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1
GET /@fs/root/.aws/credentials?raw?? HTTP/1.1
show less
Hacking
Web App Attack
๐ง๐ช
taivas.nl
2026-10-09 04:33:08
(15 hours ago)
Many_bad_calls
Web App Attack
๐บ๐ธ
NXTwoThou
2026-10-09 02:34:57
(17 hours ago)
/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh
Web App Attack
๐ฌ๐ง
venus.launch.bz
2026-10-09 01:27:30
(18 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.19.223.188 (CA/Canada/188.223.19.34. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.19.223.188 (CA/Canada/188.223.19.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
BlueWire Hosting
2026-10-09 01:19:00
(18 hours ago)
Aggressive scanning resulting into 404
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-09 01:18:49
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.19.223.188 (188.223.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.223.188 (188.223.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:18:43.814114 2026] [security2:error] [pid 21115:tid 21115] [client 34.19.223.188:36968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wisk.org"] [uri "/.htpasswd"] [unique_id "ashA887-A5glrVoKXxo8mgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
andypiper
2026-10-09 01:00:23
(18 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 00:54:46
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.19.223.188 (188.223.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.223.188 (188.223.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:54:41.681582 2026] [security2:error] [pid 831:tid 831] [client 34.19.223.188:54426] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||wisconsinstatehuntingexpo.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wisconsinstatehuntingexpo.com"] [uri "/z9x8c7v6b5-debug-trigger-wisconsinstatehuntingexpo.com"] [unique_id "asg7UVjeXGF6evF64ojUvQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 00:48:26
(18 hours ago)
$f2bV_matches
Brute-Force
Web App Attack
๐ฉ๐ช
palzer.IT
2026-10-09 00:40:14
(18 hours ago)
Fail2ban automatic report for plesk-apache-badbot: 34.19.223.188 - - [09/Oct/2026:02:39:42 +0200] GE ...
show more
Fail2ban automatic report for plesk-apache-badbot: 34.19.223.188 - - [09/Oct/2026:02:39:42 +0200] GET /s8rwnsuk5r7807tmj1fe [DOMAIN_REMOVED] 303 5719 - Mozilla/5.0 (compatible; Amazonbot/0.1; +[DOMAIN_REMOVED]
show less
Bad Web Bot
๐ง๐ช
taivas.nl
2026-10-09 00:32:11
(19 hours ago)
Bad_requests
Bad Web Bot
Anonymous
2026-10-09 00:16:46
(19 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: CA, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: CA, Attack patterns: WordPress scanning, Cloud secrets probing, Directory traversal
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 00:00:35
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.19.223.188 (188.223.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.223.188 (188.223.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:00:26.644129 2026] [security2:error] [pid 1178:tid 1178] [client 34.19.223.188:32924] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wintercypher.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wintercypher.com"] [uri "/z9x8c7v6b5-debug-trigger-wintercypher.com"] [unique_id "asgumqm5bL7nMQMqfWQ9wgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Manuel Braeuer
2026-10-08 23:56:55
(19 hours ago)
34.19.223.188 - - [09/Oct/2026:01:56:45 +0200] "GET /.htpasswd HTTP/2.0" 403 106 "https://winsvr-ber ...
show more
34.19.223.188 - - [09/Oct/2026:01:56:45 +0200] "GET /.htpasswd HTTP/2.0" 403 106 "https://winsvr-berlin.de/.htpasswd" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.19.223.188 - - [09/Oct/2026:01:56:47 +0200] "GET /@fs/proc/self/cwd/.env?raw?? HTTP/2.0" 403 106 "https://winsvr-berlin.de/@fs/proc/self/cwd/.env?raw??" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
34.19.223.188 - - [09/Oct/2026:01:56:52 +0200] "GET /api/v1/keys HTTP/2.0" 403 106 "https://winsvr-berlin.de/api/v1/keys" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
34.19.223.188 - - [09/Oct/2026:01:56:54 +0200] "GET /telescope/requests HTTP/2.0" 403 106 "https://winsvr-berlin.de/telescope/requests" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
34.19.223.188 - - [09/Oct/2026:01:56:54 +0200] "GET /trace.axd HTTP/2.0" 403 106 "https://winsvr-berlin.de/trace.axd" "Mozilla/5.0 (compatible; Bai
...
show less
Web App Attack
๐บ๐ธ
www.winos.me
2026-10-08 23:41:39
(19 hours ago)
Scanning for sensitive files/paths: /@fs/
Hacking
Web App Attack