๐ณ๐ฑ
e.fierstra
2026-09-16 06:46:47
(2 hours ago)
excessive HTTP 404 errors
Bad Web Bot
๐ฌ๐ง
openstrike.co.uk
2026-09-16 05:14:20
(4 hours ago)
173 attacks on env grabbing URLs (type 2), PHP URLs, password/key grabbing URLs, config grabbing URL ...
show more
173 attacks on env grabbing URLs (type 2), PHP URLs, password/key grabbing URLs, config grabbing URLs (type 2), env grabbing URLs, directory traversals, VC URLs:
GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/proc/self/environ HTTP/1.1
POST /icecoder/lib/terminal-xhr.php HTTP/1.1
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/1.1
GET /src/amplifyconfiguration.json HTTP/1.1
GET /@fs/../.env?import&raw?? HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /.git/config HTTP/1.1
show less
Hacking
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-16 04:06:27
(5 hours ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
Anonymous
2026-09-16 03:04:35
(6 hours ago)
2026/09/16 03:04:34 [error] 199229#199229: *588710 [client 34.42.40.216] ModSecurity: Access denied ...
show more
2026/09/16 03:04:34 [error] 199229#199229: *588710 [client 34.42.40.216] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "11st.ingeltechgh.com"] [uri "/.aws/config"] [unique_id "178952787413.989724"] [ref ""], client: 34.42.40.216, server: srv.ingeltechgh.com, request: "GET /.aws/config HTTP/2.0", host: "11st.ingeltechgh.com"
2026/09/16 03:04:34 [error] 199229#199229: *588710 [client 34.42.40.216] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/
...
show less
Brute-Force
๐จ๐ฟ
antihack.anarchista.xyz
2026-09-16 02:20:56
(7 hours ago)
404 burst: 20 hits in 5 min, URI /config.json, Ref , UA Mozilla/5.0 (compatible; MistralAI-User/1.0; ...
show more
404 burst: 20 hits in 5 min, URI /config.json, Ref , UA Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)
show less
Brute-Force
Web App Attack
Bad Web Bot
๐ฟ๐ฆ
vanderhost
2026-09-16 02:19:24
(7 hours ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /storage/logs/laravel.lo ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /storage/logs/laravel.log via rule: /storage/logs
show less
Web App Attack
Bad Web Bot
๐ฆ๐บ
AWW-Admin
2026-09-16 02:10:52
(7 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.42.40.216 (US/United States/216.40.4 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.42.40.216 (US/United States/216.40.42.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-16 01:58:00
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.42.40.216 (216.40.42.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.40.216 (216.40.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:57:55.544916 2026] [security2:error] [pid 25629:tid 25629] [client 34.42.40.216:32866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "socialstudiesforkids.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqn3o64qiY2Bc27aAC-sawAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jormaster3k
2026-09-16 01:45:02
(7 hours ago)
Attack against Apache (too many 404s)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 01:31:04
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.42.40.216 (216.40.42.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.42.40.216 (216.40.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:31:00.701281 2026] [security2:error] [pid 27702:tid 27702] [client 34.42.40.216:48350] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pamplonaserviciotecnico.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pamplonaserviciotecnico.com"] [uri "/z9x8c7v6b5-debug-trigger-pamplonaserviciotecnico.com"] [unique_id "aqnxVGObwVStRfZqUVRKqwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-09-16 01:18:09
(8 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 01:13:41
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.42.40.216 (216.40.42.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.42.40.216 (216.40.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:13:36.512539 2026] [security2:error] [pid 25135:tid 25135] [client 34.42.40.216:40584] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||monmouthbottleshop.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "monmouthbottleshop.com"] [uri "/rclone.conf"] [unique_id "aqntQLeslABSXGqYuL3AagAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-16 00:28:52
(9 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.42.40.216 (US/United States/216.40.42.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.42.40.216 (US/United States/216.40.42.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
Anonymous
2026-09-16 00:20:08
(9 hours ago)
Aggressive web scan
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-15 22:52:34
(10 hours ago)
Modsecurity: probe or injection attempt
SQL Injection
Web App Attack