Anonymous
2026-10-09 13:45:08
(4 hours ago)
Observed scanned 3 known-sensitive endpoint(s), e.g.: /.next/.env, /dashboard%2F.env, /openapi.json
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-10-09 05:15:33
(12 hours ago)
142 attacks on env grabbing URLs, shell probes, VC URLs, config grabbing URLs (type 2), PHP URLs, di ...
show more
142 attacks on env grabbing URLs, shell probes, VC URLs, config grabbing URLs (type 2), PHP URLs, directory traversals, password/key grabbing URLs, env grabbing URLs (type 2):
GET /@fs/app/.env?import&raw?? HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /.git/config HTTP/1.1
GET /secrets.yml HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/1.1
GET /__vite_rsc_findSourceMapURL?filename=file:///proc/self/environ&environmentName=rsc HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
deskpass.com
2026-10-09 05:11:21
(12 hours ago)
POST /index.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 05:00:04
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.24.92 (92.24.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.24.92 (92.24.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 00:59:56.165434 2026] [security2:error] [pid 15462:tid 15462] [client 34.80.24.92:50220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "analytics.wholesalelivelobsters.com"] [uri "/build../.env"] [unique_id "ash0zEemE-JIdkIWj7tQ3gAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-09 04:32:22
(13 hours ago)
[ftpbd] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.80 ...
show more
[ftpbd] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.80.24.92 - - \[09/Oct/2026:06:32:18 +0200\] "GET /files../.env HTTP/1.1" 404 2101 "-" "Mozilla/5.0 \(compatible\; Hunyuan/1.0\; +https://hunyuan.tencent.com/\)"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-10-09 04:06:57
(13 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
billyw0nka
2026-10-09 03:37:47
(14 hours ago)
pattern: .env
Hacking
๐ฉ๐ช
Marc
2026-10-09 03:12:06
(14 hours ago)
34.80.24.92 - - [09/Oct/2026:05:12:06 +0200] "GET /6q5u93e98vtpuw2wxmkf HTTP/2.0" 404 314 "-" "Mozil ...
show more
34.80.24.92 - - [09/Oct/2026:05:12:06 +0200] "GET /6q5u93e98vtpuw2wxmkf HTTP/2.0" 404 314 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" 34.80.24.92 - - [09/Oct/2026:05:12:06 +0200] "GET /forgot-password HTTP/2.0" 404 269 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" 34.80.24.92 - - [09/Oct/2026:05:12:06 +0200] "GET /account HTTP/2.0" 404 269 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
show less
Brute-Force
Anonymous
2026-10-09 03:07:02
(14 hours ago)
Automated web scanner. Requested suspicious paths: /dist/.vite/manifest.json | /.vite/manifest.json ...
show more
Automated web scanner. Requested suspicious paths: /dist/.vite/manifest.json | /.vite/manifest.json | /dist/manifest.json | /z9x8c7v6b5-debug-trigger-tigzig.com | /build/manifest.json. UTC: 2026-10-09 02:21:02.
show less
Web App Attack
๐ฉ๐ช
Nightreaver
2026-10-09 03:02:16
(14 hours ago)
34.80.24.92 - - [09/Oct/2026:05:02:16 0200] "GET /z9x8c7v6b5-debug-trigger-account.[snip] HTTP/1.1" ...
show more
34.80.24.92 - - [09/Oct/2026:05:02:16 0200] "GET /z9x8c7v6b5-debug-trigger-account.[snip] HTTP/1.1" 404 5722 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; https://brave.com/search/)"
34.80.24.92 - - [09/Oct/2026:05:02:16 0200] "GET /vqujzy7x6167y2qvlvou HTTP/1.1" 404 5722 "-" "Mozilla/5.0 (compatible; YouBot/1.0; https://you.com/bot)"
34.80.24.92 - - [09/Oct/2026:05:02:16 0200] "GET /manifest.json HTTP/1.1" 404 5722 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.80.24.92 - - [09/Oct/2026:05:02:16 0200] "GET /asset-manifest.json HTTP/1.1" 404 5722 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.80.24.92 - - [09/Oct/2026:05:02:16 0200] "GET /webpack-stats.json HTTP/1.1" 404 5722 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"[...]
show less
Bad Web Bot
Web App Attack
๐ง๐ท
Caue Henrique
2026-10-09 03:00:01
(14 hours ago)
Multiple common web attacks, XSS, Web Server 500 Error
Web Spam
Hacking
Web App Attack
๐บ๐ธ
JustMeHere
2026-10-09 02:49:31
(14 hours ago)
[Thu Oct 08 22:49:26.462781 2026] [security2:error] [pid 1249:tid 1290] [client 34.80.24.92:57234] M ...
show more
[Thu Oct 08 22:49:26.462781 2026] [security2:error] [pid 1249:tid 1290] [client 34.80.24.92:57234] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "yorknation.com"] [uri "/"] [unique_id "ashWNpGlSUsbYuhhFIAgvAAAAM0"]
...
show less
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-09 02:37:46
(15 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 01:48:28
(15 hours ago)
Blocked by fail2ban on a public web server.
Web App Attack
๐จ๐ฆ
lakered
2026-10-09 01:43:54
(16 hours ago)
Detectors: [SURICATA, NGINX] | Reasons: Automated scan targeting an unauthorized host or default ser ...
show more
Detectors: [SURICATA, NGINX] | Reasons: Automated scan targeting an unauthorized host or default server sinkhole | Suricata: Web Server attack | TCP Fingerprint: Modern Linux (Kernel 3.x+) (Link:generic tunnel or VPN, Uptime:0m)
show less
Web App Attack
Hacking
Port Scan
Bad Web Bot