๐ฌ๐ง
openstrike.co.uk
2026-10-06 05:13:41
(3 days ago)
1479 attacks on password/key grabbing URLs, PHP URLs, shell probes, VC URLs, env grabbing URLs (type ...
show more
1479 attacks on password/key grabbing URLs, PHP URLs, shell probes, VC URLs, env grabbing URLs (type 2), env grabbing URLs, directory traversals, config grabbing URLs (type 2):
GET /.aws/credentials HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /userfiles/x?path=../../../../proc/self/environ HTTP/1.1
GET /.env.js HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /app-config.json HTTP/1.1
show less
Hacking
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-10-05 16:15:49
(4 days ago)
34.69.252.191 - - [05/Oct/2026:17:15:48 +0100] "GET /@fs/.env?import&?raw?? HTTP/2.0" 401 410 "-" "M ...
show more
34.69.252.191 - - [05/Oct/2026:17:15:48 +0100] "GET /@fs/.env?import&?raw?? HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-10-05 15:44:35
(4 days ago)
34.69.252.191 - - [05/Oct/2026:16:44:34 +0100] "GET /api/4/config HTTP/2.0" 401 410 "-" "Mozilla/5.0 ...
show more
34.69.252.191 - - [05/Oct/2026:16:44:34 +0100] "GET /api/4/config HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-10-05 15:17:01
(4 days ago)
34.69.252.191 - - [05/Oct/2026:16:17:01 +0100] "GET /api/health HTTP/2.0" 401 410 "-" "Mozilla/5.0 ( ...
show more
34.69.252.191 - - [05/Oct/2026:16:17:01 +0100] "GET /api/health HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ฌ๐ง
noise.agency
2026-10-05 14:53:04
(4 days ago)
34.69.252.191 (US/United States/191.252.69.34.bc.googleusercontent.com), more than 10 Apache 403 hit ...
show more
34.69.252.191 (US/United States/191.252.69.34.bc.googleusercontent.com), more than 10 Apache 403 hits
show less
Hacking
๐ซ๐ฎ
Christopher Hughes
2026-10-05 14:49:30
(4 days ago)
34.69.252.191 - - [05/Oct/2026:15:49:30 +0100] "GET /@fs/app/.env?import&raw?? HTTP/2.0" 401 410 "-" ...
show more
34.69.252.191 - - [05/Oct/2026:15:49:30 +0100] "GET /@fs/app/.env?import&raw?? HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-10-05 14:24:59
(4 days ago)
34.69.252.191 - - [05/Oct/2026:15:24:58 +0100] "GET /.aws/config HTTP/2.0" 401 410 "-" "Mozilla/5.0 ...
show more
34.69.252.191 - - [05/Oct/2026:15:24:58 +0100] "GET /.aws/config HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-10-05 14:08:00
(4 days ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02]
Hacking
SQL Injection
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-10-05 13:07:02
(4 days ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [wa01,wa02]
Hacking
SQL Injection
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-10-05 13:04:14
(4 days ago)
34.69.252.191 - - [05/Oct/2026:14:04:14 +0100] "GET /dist/.env HTTP/2.0" 401 410 "-" "Mozilla/5.0 (c ...
show more
34.69.252.191 - - [05/Oct/2026:14:04:14 +0100] "GET /dist/.env HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
Anonymous
2026-10-05 12:45:05
(4 days ago)
Bot / scanning and/or hacking attempts: [317/317] read: stream 0, , POST /cgi-bin/php-cgi?-d+allow_ ...
show more
Bot / scanning and/or hacking attempts: [317/317] read: stream 0, , POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend, POST /api/v1/node-load-method/customMCP HTTP/2.0
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 12:41:45
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.69.252.191 (191.252.69.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.69.252.191 (191.252.69.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 08:41:38.281170 2026] [security2:error] [pid 7205:tid 7205] [client 34.69.252.191:59018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yourmac.co.uk"] [uri "/.htpasswd"] [unique_id "asObAjnnW-S_GwZagq2MYAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
spamverify.com
2026-10-05 11:56:34
(4 days ago)
Honeypot Hit: WordPress Json
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
๐ฉ๐ช
33three
2026-10-05 11:52:29
(4 days ago)
Fail2Ban jail WebAttack triggered
Brute-Force
๐ณ๐ฑ
Savvii
2026-10-05 11:20:24
(4 days ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack