๐ฌ๐ง
openstrike.co.uk
2026-10-06 05:13:53
(15 hours ago)
9 attacks on password/key grabbing URLs:
GET /.aws/credentials HTTP/1.1
Hacking
๐ซ๐ท
SpaceHost-Server
2026-10-05 22:17:15
(22 hours ago)
Brute-Force
Web App Attack
Anonymous
2026-10-05 19:24:21
(1 day ago)
600 WAF signature matches (APPFW_SIGNATURE_MATCH / APPFW_INV_RFC) in 48h
Web App Attack
Hacking
๐ฉ๐ช
Dominik Lysiak
2026-10-05 17:42:42
(1 day ago)
34.74.165.37 - - [05/Oct/2026:19:42:41 +0200] "GET /wp-json HTTP/2.0" 404 179 "-" "Mozilla/5.0 (comp ...
show more
34.74.165.37 - - [05/Oct/2026:19:42:41 +0200] "GET /wp-json HTTP/2.0" 404 179 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.74.165.37 - - [05/Oct/2026:19:42:41 +0200] "GET /.ssh/id_rsa HTTP/2.0" 404 179 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.74.165.37 - - [05/Oct/2026:19:42:41 +0200] "GET /.ssh/id_ed25519 HTTP/2.0" 404 179 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
...
show less
Web App Attack
๐ฉ๐ช
macrob
2026-10-05 14:27:50
(1 day ago)
2026/10/05 14:27:47 [error] 3671660#3671660: *19180646 access forbidden by rule, client: 34.74.165.3 ...
show more
2026/10/05 14:27:47 [error] 3671660#3671660: *19180646 access forbidden by rule, client: 34.74.165.37, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "account.wellbin.org"
2026/10/05 14:27:48 [error] 3671657#3671657: *19180662 access forbidden by rule, client: 34.74.165.37, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "account.wellbin.org"
2026/10/05 14:27:48 [error] 3671661#3671661: *19180638 access forbidden by rule, client: 34.74.165.37, server: fn.binixo.es, request: "GET /.npmrc HTTP/2.0", host: "account.wellbin.org"
...
show less
Web App Attack
Anonymous
2026-10-05 13:52:56
(1 day ago)
$f2bV_matches
Brute-Force
Web App Attack
๐บ๐ธ
factor1
2026-10-05 12:57:05
(1 day ago)
CrowdSec at saturn Reports Abuse
Web App Attack
๐บ๐ธ
EvilTurkey
2026-10-05 12:50:47
(1 day ago)
Web app attack against financial institution website.
Web App Attack
Hacking
๐ฉ๐ช
Blexyel
2026-10-05 12:14:00
(1 day ago)
34.74.165.37 - - [05/Oct/2026:14:13:59 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 ( ...
show more
34.74.165.37 - - [05/Oct/2026:14:13:59 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
dot.mg
2026-10-05 11:48:06
(1 day ago)
Scan of vulnerable files
Web App Attack
๐ซ๐ฎ
oh.mg
2026-10-05 11:18:16
(1 day ago)
[Mon Oct 05 13:18:10.207293 2026] [security2:error] [pid 2830107:tid 2830119] [client 34.74.165.37:0 ...
show more
[Mon Oct 05 13:18:10.207293 2026] [security2:error] [pid 2830107:tid 2830119] [client 34.74.165.37:0] [client 34.74.165.37] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "eu.mmn.ca"] [uri "/"] [unique_id "asOHcsDTY9SLC0tRhM1XbgAAAIk"]
[Mon Oct 05 13:18:15.769413 2026] [security2:error] [pid 2830107:tid 2830117] [client 34.74.165.37:0] [client 34.74.165.37] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
Sonoflet
2026-10-05 11:01:00
(1 day ago)
CrowdSec detection | scenario: http-probing
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 10:45:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.74.165.37 (37.165.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.165.37 (37.165.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 06:45:03.713017 2026] [security2:error] [pid 22774:tid 22774] [client 34.74.165.37:38394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "joshuashands.org"] [uri "/.htpasswd"] [unique_id "asN_r_g6hVYwesXvXEw2SQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Comberton
2026-10-05 10:30:17
(1 day ago)
Ban via by F2B apache-wordfence jail
Brute-Force
๐ฉ๐ช
tentwentyfour
2026-10-05 09:33:20
(1 day ago)
Blocked for probing for sensitive web application components
Brute-Force
Web App Attack