๐ฌ๐ง
openstrike.co.uk
2026-09-16 05:14:42
(3 days ago)
173 attacks on VC URLs, directory traversals, config grabbing URLs (type 2), env grabbing URLs, pass ...
show more
173 attacks on VC URLs, directory traversals, config grabbing URLs (type 2), env grabbing URLs, password/key grabbing URLs, PHP URLs, env grabbing URLs (type 2):
GET /.git/HEAD HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /application.yml HTTP/1.1
GET /.env.js HTTP/1.1
GET /@fs/root/.aws/credentials?raw?? HTTP/1.1
POST /icecoder/lib/terminal-xhr.php HTTP/1.1
GET /_image?href=/proc/self/environ HTTP/1.1
show less
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-16 03:12:15
(3 days ago)
excessive HTTP 404 errors
Bad Web Bot
๐ฌ๐ง
andypiper
2026-09-16 01:01:26
(3 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-16 00:13:51
(3 days ago)
[ti-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.59.1.41 - - [16/Sep/2026:02:13:43 +0200] "GET /__/firebase/init.json HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.59.1.41 - - [16/Sep/2026:02:13:43 +0200] "GET /config.json HTTP/2.0" 404 1887 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.59.1.41 - - [16/Sep/2026:02:13:44 +0200] "GET /app-config.json HTTP/2.0" 404 1878 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.59.1.41 - - [16/Sep/2026:02:13:44 +0200] "GET /api/account HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
34.59.1.41 - - [16/Sep/2026:02:13:44 +0200] "GET /api/settings HTTP/2.0" 404
...
show less
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(3 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ช๐ธ
robotstxt
2026-09-15 23:38:00
(3 days ago)
34.59.1.41 - - [15/Sep/2026:23:37:25 +0000] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/ ...
show more
34.59.1.41 - - [15/Sep/2026:23:37:25 +0000] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/2.0" 403 20 "https://starship.xyz/__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" "-" edge="34.59.1.41"
34.59.1.41 - - [15/Sep/2026:23:37:25 +0000] "GET /@fs/var/run/secrets/kubernetes.io/serviceaccount/ca.crt?raw?? HTTP/2.0" 403 20 "https://starship.xyz/@fs/var/run/secrets/kubernetes.io/serviceaccount/ca.crt?raw??" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "-" edge="34.59.1.41"
34.59.1.41 - - [15/Sep/2026:23:37:25 +0000] "GET /build/manifest.json HTTP/2.0" 403 2 "https://starship.xyz/build/manifest.json" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0" "-" edge="34.59.1.41"
34.59.1.41 - - [15/Sep/2026:23:37:25 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 2 "ht
...
show less
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-15 23:34:41
(3 days ago)
20 attempts against mh-misbehave-ban on solar
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-09-15 23:15:19
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.59.1.41 (US/United States/41.1.59.34.bc.goog ...
show more
(mod_security) mod_security (id:210492) triggered by 34.59.1.41 (US/United States/41.1.59.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐จ๐ฆ
Mediashaker
2026-09-15 23:09:42
(3 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.59.1.41 (US/Unite ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.59.1.41 (US/United States/41.1.59.34.bc.googleusercontent.com)
show less
Bad Web Bot
๐น๐ญ
MWA SOC
2026-09-15 23:00:39
(3 days ago)
Hacking
๐ซ๐ท
Cuteminded
2026-09-15 22:46:09
(3 days ago)
Highly suspect IP
Web Spam
Bad Web Bot
๐บ๐ธ
helios.live
2026-09-15 22:33:29
(3 days ago)
2026/09/15 22:33:26 [error] 938973#938973: *3296598 access forbidden by rule, client: 34.59.1.41, se ...
show more
2026/09/15 22:33:26 [error] 938973#938973: *3296598 access forbidden by rule, client: 34.59.1.41, server: kocerroxy.com, request: "GET /.vite/manifest.json HTTP/1.1", host: "kocerroxy.com"
2026/09/15 22:33:26 [error] 938973#938973: *3296598 access forbidden by rule, client: 34.59.1.41, server: kocerroxy.com, request: "GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/1.1", host: "kocerroxy.com"
2026/09/15 22:33:26 [error] 938973#938973: *3296598 access forbidden by rule, client: 34.59.1.41, server: kocerroxy.com, request: "GET /dist/.vite/manifest.json HTTP/1.1", host: "kocerroxy.com"
2026/09/15 22:33:26 [error] 938973#938973: *3296608 access forbidden by rule, client: 34.59.1.41, server: kocerroxy.com, request: "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/1.1", host: "kocerroxy.com"
2026/09/15 22:33:29 [error] 938973#938973: *3296721 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 34.59.1.41, server: kocerroxy.com, request: "
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:55:16
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.59.1.41 (41.1.59.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.59.1.41 (41.1.59.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:55:10.851564 2026] [security2:error] [pid 9264:tid 9264] [client 34.59.1.41:36214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hyps.net"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqm-vh4uzPh05ayWYRyuRwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
legionMCCXV
2026-09-15 21:54:06
(3 days ago)
Non-HTTP protocol data (e.g. MQTT/TLS handshake bytes) sent to HTTP(S) port.
Port Scan
Hacking
๐ฉ๐ช
konseptit
2026-09-15 20:51:43
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.59.1.41 (US/United States/41.1.59.34 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.59.1.41 (US/United States/41.1.59.34.bc.googleusercontent.com)
show less
SQL Injection