π¬π§
openstrike.co.uk
2026-10-09 05:15:10
(2 hours ago)
147 attacks on PHP URLs, directory traversals, VC URLs, config grabbing URLs (type 2), shell probes, ...
show more
147 attacks on PHP URLs, directory traversals, VC URLs, config grabbing URLs (type 2), shell probes, env grabbing URLs, env grabbing URLs (type 2), password/key grabbing URLs:
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /..%2f.env HTTP/1.1
GET /.git/config HTTP/1.1
GET /secrets.yml HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /uploads../.env HTTP/1.1
GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1
GET /.aws/credentials HTTP/1.1
show less
Web App Attack
Hacking
π¨π
π¨π Hosting
2026-10-09 05:10:33
(2 hours ago)
Automated WAF report: 200-300 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
π΅π±
srebrakowski.com
2026-10-09 02:39:50
(4 hours ago)
crowdsec/waf-detected-exploits
Brute-Force
πΊπΈ
TPI-Abuse
2026-10-09 02:37:29
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.7.235.233 (233.235.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.235.233 (233.235.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 22:37:24.225107 2026] [security2:error] [pid 15090:tid 15090] [client 34.7.235.233:38460] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mikewakimphotos.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mikewakimphotos.com"] [uri "/z9x8c7v6b5-debug-trigger-mikewakimphotos.com"] [unique_id "ashTZJwuf51bKaukAbTyEQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
dot.mg
2026-10-09 02:04:02
(5 hours ago)
Scan of vulnerable files
Web App Attack
Anonymous
2026-10-09 01:51:36
(5 hours ago)
Banned by Fail2Ban on server
Web App Attack
Anonymous
2026-10-09 01:46:25
(5 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
π«π·
Zundapper
2026-10-09 01:43:28
(5 hours ago)
34.7.235.233 - - [09/Oct/2026:03:43:28 +0200] "GET /0dx2bzc1grtpaks0bitg HTTP/2.0" 404 106 "-" "Mozi ...
show more
34.7.235.233 - - [09/Oct/2026:03:43:28 +0200] "GET /0dx2bzc1grtpaks0bitg HTTP/2.0" 404 106 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.7.235.233 - - [09/Oct/2026:03:43:28 +0200] "GET /z9x8c7v6b5-debug-trigger-michelemontecchi.com HTTP/2.0" 404 106 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
34.7.235.233 - - [09/Oct/2026:03:43:28 +0200] "GET /7twbpna4cmnugioayfg3 HTTP/2.0" 404 106 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.7.235.233 - - [09/Oct/2026:03:43:28 +0200] "GET /userfiles?path=../../.env HTTP/2.0" 404 106 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.7.235.233 - - [09/Oct/2026:03:43:28 +0200] "GET /userfiles?path=../../../.env HTTP/2.0" 404 106 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Web App Attack
Port Scan
πΊπΈ
TPI-Abuse
2026-10-09 01:39:34
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.7.235.233 (233.235.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.235.233 (233.235.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:39:28.449307 2026] [security2:error] [pid 17088:tid 17116] [client 34.7.235.233:46992] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||michaelrandon.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "michaelrandon.com"] [uri "/z9x8c7v6b5-debug-trigger-michaelrandon.com"] [unique_id "ashF0NTdweFe72KbqQyTJAAAAVY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-10-09 01:29:42
(5 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-195)
show less
Hacking
π³π±
Site.eu
2026-10-09 01:02:41
(6 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-10-09 01:00:31
(6 hours ago)
34.7.235.233 - - [09/Oct/2026:03:00:19 +0200] "GET /.htpasswd HTTP/2.0" 403 272 "-" "Mozilla/5.0 (co ...
show more
34.7.235.233 - - [09/Oct/2026:03:00:19 +0200] "GET /.htpasswd HTTP/2.0" 403 272 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
Anonymous
2026-10-09 00:58:16
(6 hours ago)
Web probing (373 hits in 24h) on default-vhost,mezzia.nl: sensitive-path scans and/or 404 bursts. Re ...
show more
Web probing (373 hits in 24h) on default-vhost,mezzia.nl: sensitive-path scans and/or 404 bursts. Reported by CRMON.
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 00:40:56
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.235.233 (233.235.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.235.233 (233.235.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:40:52.563422 2026] [security2:error] [pid 14067:tid 14090] [client 34.7.235.233:48818] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "metropolitanbasel.org"] [uri "/.htpasswd"] [unique_id "asg4FP5IcjALmwcezZCQ8QAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
agenciahypelab.com.br
2026-10-09 00:40:39
(6 hours ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH