π¬π§
openstrike.co.uk
2026-10-10 05:13:52
(1 day ago)
147 attacks on shell probes, PHP URLs, env grabbing URLs, VC URLs, directory traversals, password/ke ...
show more
147 attacks on shell probes, PHP URLs, env grabbing URLs, VC URLs, directory traversals, password/key grabbing URLs, env grabbing URLs (type 2), config grabbing URLs (type 2):
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /core/.env HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /.aws/credentials HTTP/1.1
GET /userfiles/x?path=../../../../proc/self/environ HTTP/1.1
GET /secrets.json HTTP/1.1
show less
Hacking
Web App Attack
π³π±
homeshowdomain.nl
2026-10-09 21:59:56
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-10-08.
show less
Web App Attack
SSH
Hacking
π¬π§
openstrike.co.uk
2026-10-09 05:15:33
(2 days ago)
147 attacks on shell probes, env grabbing URLs, PHP URLs, directory traversals, config grabbing URLs ...
show more
147 attacks on shell probes, env grabbing URLs, PHP URLs, directory traversals, config grabbing URLs (type 2), VC URLs, env grabbing URLs (type 2), password/key grabbing URLs:
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /_image?href=/../../../.env HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /secrets.yml HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1
GET /.git-credentials HTTP/1.1
show less
Hacking
Web App Attack
π³π±
Alt255
2026-10-09 04:58:21
(2 days ago)
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.80.210.152 - - [09/Oct/2026:06:58:14 +0200] "GET /.ssh/id_rsa HTTP/2.0" 403 372 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
Sling
2026-10-09 04:31:54
(2 days ago)
Automated detection: IP accessed 19 sensitive endpoints within 30s on slingexe.me. Paths: /.env, /.e ...
show more
Automated detection: IP accessed 19 sensitive endpoints within 30s on slingexe.me. Paths: /.env, /.env.local, /.env.production, /pages/index.astro.mjs.map, /pages/api/index.astro.mjs.map, /config.json, /.env.example, /.env.backup, /config/.env, /app/.env. UA: Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/).
show less
Web App Attack
Bad Web Bot
Hacking
π©πͺ
Skyrider
2026-10-09 03:26:15
(2 days ago)
crowdsecurity/http-admin-interface-probing
Web App Attack
π¬π§
noise.agency
2026-10-09 01:40:53
(2 days ago)
34.80.210.152 (TW/Taiwan/152.210.80.34.bc.googleusercontent.com), more than 30 Apache 404 hits
Hacking
πΊπΈ
TPI-Abuse
2026-10-09 01:25:42
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.80.210.152 (152.210.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.210.152 (152.210.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:25:35.969877 2026] [security2:error] [pid 17723:tid 17773] [client 34.80.210.152:50730] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sleazysexquiz.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sleazysexquiz.com"] [uri "/z9x8c7v6b5-debug-trigger-sleazysexquiz.com"] [unique_id "ashCj2h-X-eGWXNzvbS56AAAAZU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
maxpower
2026-10-09 01:22:29
(2 days ago)
(junkbot) REGOLA 8 - Junk Bot Blocked 34.80.210.152 (TW/Taiwan/152.210.80.34.bc.googleusercontent.co ...
show more
(junkbot) REGOLA 8 - Junk Bot Blocked 34.80.210.152 (TW/Taiwan/152.210.80.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.80.210.152 - - [09/Oct/2026:03:22:26 +0200] "GET /config/gcp-credentials.json HTTP/2.0" 200 11929 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "-" host=slccgilabruzzomolise.it
show less
Port Scan
π¬π§
andypiper
2026-10-09 01:01:15
(2 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
π©πͺ
Skyrider
2026-10-09 00:31:25
(2 days ago)
crowdsecurity/http-probing
Web App Attack
πΊπΈ
slay3r9903
2026-10-09 00:26:53
(2 days ago)
IP address blocked by Cloudflare security rules due to suspicious activity and security violations.
Hacking
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-10-09 00:25:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.210.152 (152.210.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.210.152 (152.210.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:25:21.313575 2026] [security2:error] [pid 3482:tid 3482] [client 34.80.210.152:46328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "slc.com.gt"] [uri "/.htpasswd"] [unique_id "asg0cbsFfdc8DrBM88ZL7QAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-10-09 00:15:00
(2 days ago)
20 attempts against mh-misbehave-ban on ethyl
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Skyrider
2026-10-08 23:52:45
(2 days ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack