๐ฌ๐ง
openstrike.co.uk
2026-10-07 05:14:32
(4 days ago)
1154 attacks on env grabbing URLs, env grabbing URLs (type 2), VC URLs, PHP URLs, shell probes, conf ...
show more
1154 attacks on env grabbing URLs, env grabbing URLs (type 2), VC URLs, PHP URLs, shell probes, config grabbing URLs (type 2), directory traversals, password/key grabbing URLs:
GET /@fs/.env?import&?raw?? HTTP/1.1
GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1
GET /.git/config HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /env.json HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /.ssh/id_ed25519 HTTP/1.1
show less
Hacking
Web App Attack
๐ฌ๐ง
Greg Poulson
2026-10-06 18:50:42
(4 days ago)
Our website was hit by this DDOS at a rate of 216 in 5 minutes.
DDoS Attack
Web Spam
Brute-Force
๐ซ๐ท
spot
2026-10-06 17:52:48
(4 days ago)
34.32.224.47 - - [06/Oct/2026:18:52:48 +0100] "GET /admin/login HTTP/1.1" 403 491 "-" "Mozilla/5.0 ( ...
show more
34.32.224.47 - - [06/Oct/2026:18:52:48 +0100] "GET /admin/login HTTP/1.1" 403 491 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
...
show less
Web App Attack
Hacking
๐ฌ๐ง
Steve
2026-10-06 17:27:59
(4 days ago)
Abuse of XMLRPC
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 16:38:17
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.32.224.47 (47.224.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.224.47 (47.224.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:38:12.887709 2026] [security2:error] [pid 8487:tid 8487] [client 34.32.224.47:40072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "skipport.co.uk"] [uri "/.htpasswd"] [unique_id "asUj9Eh8SDpgvGB0Mh_CpgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
sigurg
2026-10-06 16:35:52
(4 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-10-06 16:01:10
(4 days ago)
[Tue Oct 06 16:39:52.507811 2026] [proxy_fcgi:error] [pid 1123:tid 1206] [remote 34.32.224.47:33644] ...
show more
[Tue Oct 06 16:39:52.507811 2026] [proxy_fcgi:error] [pid 1123:tid 1206] [remote 34.32.224.47:33644] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-06 15:41:49
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.32.224.47 (47.224.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.224.47 (47.224.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 11:41:44.546367 2026] [security2:error] [pid 17392:tid 17392] [client 34.32.224.47:60232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "powersystemprotection.co.uk"] [uri "/.htpasswd"] [unique_id "asUWuLE9cu6SMtIlrQNIFgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-10-06 15:37:12
(4 days ago)
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: BLOCK
Protocol: HTTP/2 (POST metho ...
show more
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /cgi-bin/php
UA: Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-06 15:10:39
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.32.224.47 (47.224.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.224.47 (47.224.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 11:10:35.585455 2026] [security2:error] [pid 10756:tid 10756] [client 34.32.224.47:41556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "natashahenry.co.uk"] [uri "/static../.env"] [unique_id "asUPa-zzEI--tAaHXnih6AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-10-06 15:09:44
(4 days ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.32.224. ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.32.224.47 (NL/The Netherlands/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 34.32.224.47 (NL/The Netherlands/47.224.32.34.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-10-06 15:08:39
(4 days ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
cg-design.co.uk
2026-10-06 14:53:50
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.32.224.47 (47.224.32.34.bc.googleuse ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.32.224.47 (47.224.32.34.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-10-06 14:44:47
(4 days ago)
Blocked by ModSec and CSF
Port Scan
๐ฉ๐ช
svr
2026-10-06 14:11:57
(5 days ago)
Abusive Automated Web Scanner
Web App Attack