๐ฌ๐ง
openstrike.co.uk
2026-10-09 05:14:47
(12 hours ago)
103 attacks on shell probes, env grabbing URLs, PHP URLs, config grabbing URLs (type 2), VC URLs, en ...
show more
103 attacks on shell probes, env grabbing URLs, PHP URLs, config grabbing URLs (type 2), VC URLs, env grabbing URLs (type 2), password/key grabbing URLs:
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /css../.env HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /app-config.json HTTP/1.1
GET /.git/config HTTP/1.1
GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/1.1
show less
Hacking
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-09 01:32:02
(16 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/grafana-cve-2021-43798
Web App Attack
Hacking
๐ฌ๐ง
andypiper
2026-10-09 01:00:21
(16 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-09 00:54:38
(16 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฉ๐ช
ghostwarriors
2026-10-09 00:50:08
(16 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-09 00:43:07
(17 hours ago)
2026/10/09 01:43:04 [error] 4060693#4060693: *1360678 access forbidden by rule, client: 34.84.49.19, ...
show more
2026/10/09 01:43:04 [error] 4060693#4060693: *1360678 access forbidden by rule, client: 34.84.49.19, server: api.betatechnologies.info, request: "GET /js../.env HTTP/2.0", host: "api.betatechnologies.info"
2026/10/09 01:43:04 [error] 4060693#4060693: *1360665 access forbidden by rule, client: 34.84.49.19, server: api.betatechnologies.info, request: "GET /assets../.env HTTP/2.0", host: "api.betatechnologies.info"
2026/10/09 01:43:04 [error] 4060693#4060693: *1360678 access forbidden by rule, client: 34.84.49.19, server: api.betatechnologies.info, request: "GET /img../.env HTTP/2.0", host: "api.betatechnologies.info"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
FD-IX
2026-10-09 00:16:55
(17 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 00:05:08
(17 hours ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐ซ๐ท
dynamix
2026-10-09 00:03:19
(17 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
rh24
2026-10-08 23:55:35
(17 hours ago)
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 34.84.49.19 (JP/Japan/19.49.84.34.bc.goog ...
show more
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 34.84.49.19 (JP/Japan/19.49.84.34.bc.googleusercontent.com)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 23:45:47
(18 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.84.49.19 (19.49.84.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210580) triggered by 34.84.49.19 (19.49.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:45:43.040228 2026] [security2:error] [pid 25824:tid 25824] [client 34.84.49.19:46162] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:apis. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||visionremota.info|F|2"] [data "Matched Data: proc/self/environ found within ARGS:apis: ../../../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "visionremota.info"] [uri "/api/console/api_server"] [unique_id "asgrJ4cnepUQ63Hm348b2gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-10-08 23:45:04
(18 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 23:22:11
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.49.19 (19.49.84.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.49.19 (19.49.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:22:03.710386 2026] [security2:error] [pid 11349:tid 11349] [client 34.84.49.19:56644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "progresstraining.info"] [uri "/.htpasswd"] [unique_id "asglm5jJcVTLIN_WrCNvNQAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-08 23:21:30
(18 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 23:02:49
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.49.19 (19.49.84.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.49.19 (19.49.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:02:45.950028 2026] [security2:error] [pid 24210:tid 24210] [client 34.84.49.19:46990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "megastorebuilders.info"] [uri "/static//.env"] [unique_id "asghFbQaeCrZHAjHQTfZpgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack