๐ฌ๐ง
openstrike.co.uk
2026-09-16 05:14:50
(4 hours ago)
311 attacks on password/key grabbing URLs, env grabbing URLs (type 2), PHP URLs, directory traversal ...
show more
311 attacks on password/key grabbing URLs, env grabbing URLs (type 2), PHP URLs, directory traversals, VC URLs, env grabbing URLs, config grabbing URLs (type 2):
GET /id_ed25519 HTTP/1.1
GET /_image?href=/proc/self/environ HTTP/1.1
POST /icecoder/lib/terminal-xhr.php HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /admin/.env HTTP/1.1
GET /secrets.yml HTTP/1.1
show less
Hacking
Web App Attack
๐ง๐ช
taivas.nl
2026-09-16 04:33:47
(4 hours ago)
Many_bad_calls
Web App Attack
๐ฟ๐ฆ
vanderhost
2026-09-16 00:06:36
(9 hours ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /storage/logs/laravel.lo ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /storage/logs/laravel.log via rule: /storage/logs
show less
Web App Attack
Bad Web Bot
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(9 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐น๐ญ
MWA SOC
2026-09-15 22:56:47
(10 hours ago)
Hacking
๐ช๐ธ
elcruzado.es
2026-09-15 22:51:29
(10 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.23.34.112 (US/Uni ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.23.34.112 (US/United States/112.34.23.34.bc.googleusercontent.com)
show less
Bad Web Bot
๐บ๐ธ
agenciahypelab.com.br
2026-09-15 22:37:23
(10 hours ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-15 22:34:48
(10 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.23.34.112 (112.34.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210580) triggered by 34.23.34.112 (112.34.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:34:43.157781 2026] [security2:error] [pid 30223:tid 30223] [client 34.23.34.112:39334] ModSecurity: Access denied with code 403 (phase 2). Matched phrase ".ssh/id_rsa" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||lopansri.com|F|2"] [data "Matched Data: .ssh/id_rsa found within ARGS:filename: file:/root/.ssh/id_rsa"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "lopansri.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqnIA7axJGCzrgshJHKTywAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-15 21:57:11
(11 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.23.34.112 (US/United States/112.34.23.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.23.34.112 (US/United States/112.34.23.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
Anonymous
2026-09-15 21:47:14
(11 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ซ๐ท
Lacrimosa99
2026-09-15 21:03:58
(12 hours ago)
34.23.34.112 - - [15/Sep/2026:23:03:54 +0200] "GET /admin%2F.env HTTP/2.0" 404 224 "-" "Mozilla/5.0 ...
show more
34.23.34.112 - - [15/Sep/2026:23:03:54 +0200] "GET /admin%2F.env HTTP/2.0" 404 224 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
34.23.34.112 - - [15/Sep/2026:23:03:55 +0200] "GET /api/w/admins/jobs_u/get_log_file/../../../../proc/self/environ HTTP/2.0" 404 224 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
34.23.34.112 - - [15/Sep/2026:23:03:57 +0200] "GET /admin/login HTTP/2.0" 404 224 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
...
show less
Web Spam
Anonymous
2026-09-15 20:57:23
(12 hours ago)
apache vulnerability scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 20:06:47
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.23.34.112 (112.34.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.23.34.112 (112.34.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:06:40.623718 2026] [security2:error] [pid 8609:tid 8609] [client 34.23.34.112:40394] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||clevercad.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "clevercad.com"] [uri "/rclone.conf"] [unique_id "aqmlUKNUPXlL6557Yvj0hwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 19:35:55
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.34.112 (112.34.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.34.112 (112.34.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:35:48.874086 2026] [security2:error] [pid 12451:tid 12456] [client 34.23.34.112:36318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clearwaterpumpservices.com"] [uri "/.git/HEAD"] [unique_id "aqmeFEL9BGJr7jKAlgW9pgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 18:39:58
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.23.34.112 (112.34.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.23.34.112 (112.34.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:39:52.326357 2026] [security2:error] [pid 18856:tid 18856] [client 34.23.34.112:42662] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cleaningmedical.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cleaningmedical.com"] [uri "/z9x8c7v6b5-debug-trigger-cleaningmedical.com"] [unique_id "aqmQ-OFhqAoRyFG9ehwjKAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack