๐ฌ๐ง
openstrike.co.uk
2026-09-30 05:14:18
(12 hours ago)
181 attacks on config grabbing URLs (type 2), password/key grabbing URLs, shell probes, PHP URLs, VC ...
show more
181 attacks on config grabbing URLs (type 2), password/key grabbing URLs, shell probes, PHP URLs, VC URLs, directory traversals, env grabbing URLs (type 2), env grabbing URLs:
GET /config/storage.yml HTTP/1.1
GET /id_ecdsa HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /.git/config HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1
GET /utils/.env HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-30 05:10:51
(12 hours ago)
(PERMBLOCK) 34.95.247.152 (BR/Brazil/Sรฃo Paulo/Sรฃo Paulo/152.247.95.34.bc.googleusercontent.com/[red ...
show more
(PERMBLOCK) 34.95.247.152 (BR/Brazil/Sรฃo Paulo/Sรฃo Paulo/152.247.95.34.bc.googleusercontent.com/[redacted]) has had more than 4 temp blocks
show less
Hacking
๐ง๐ช
taivas.nl
2026-09-30 04:33:04
(13 hours ago)
Many_bad_calls
Web App Attack
Anonymous
2026-09-30 01:40:05
(16 hours ago)
| [Dangerous/Brazil] Aggressive IP 34.95.247.152 (~30 hits). Type: DoS Defender- Web server 400 erro ...
show more
| [Dangerous/Brazil] Aggressive IP 34.95.247.152 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-30 01:37:52
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.247.152 (152.247.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.247.152 (152.247.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:37:45.509745 2026] [security2:error] [pid 16705:tid 16705] [client 34.95.247.152:50386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "westerncarolinabass.org"] [uri "/.env.save"] [unique_id "arxn6W6D7QdMws702Rvy-gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
NoaQT
2026-09-30 01:10:14
(16 hours ago)
2026-09-30T01:10:13.986483+00:00 ingress-1 haproxy[16887]: 34.95.247.152:56396 [30/Sep/2026:01:10:13 ...
show more
2026-09-30T01:10:13.986483+00:00 ingress-1 haproxy[16887]: 34.95.247.152:56396 [30/Sep/2026:01:10:13.986] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 66/66/0/0/0 0/0 "GET https://mentis.si/secrets.yml HTTP/2.0"
2026-09-30T01:10:13.999618+00:00 ingress-1 haproxy[16887]: 34.95.247.152:56396 [30/Sep/2026:01:10:13.999] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 66/66/0/0/0 0/0 "GET https://mentis.si/.env.local HTTP/2.0"
2026-09-30T01:10:14.007093+00:00 ingress-1 haproxy[16887]: 34.95.247.152:56396 [30/Sep/2026:01:10:14.006] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 66/66/0/0/0 0/0 "GET https://mentis.si/firebase-adminsdk.json HTTP/2.0"
2026-09-30T01:10:14.008520+00:00 ingress-1 haproxy[16887]: 34.95.247.152:56396 [30/Sep/2026:01:10:14.008] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 66/66/0/0/0 0/0 "GET https://mentis.si/env.json HTTP/2.0"
2026-09-30T01:10:14.013041+00:00 ingress-1 haproxy[16887]: 34.95.247.152:56396 [30/Sep/2026:01:10
...
show less
DDoS Attack
๐ฉ๐ช
altenglaner
2026-09-30 00:03:21
(17 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-29 23:25:09
(18 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-29 23:10:54
(18 hours ago)
3.429 requests from abuseipdb.com blacklisted IP (1yr2mos2w)
Brute-Force
Bad Web Bot
๐ง๐ท
radardatelecom
2026-09-29 22:26:02
(19 hours ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-29 22:17:13
(19 hours ago)
Crawler ignoring refusals | ua: Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/), Moz ...
show more
Crawler ignoring refusals | ua: Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/), Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot), Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/ (+8 more) | path: /lib/terminal-xhr.php, /ox3tmtc0g30w41gyhlhi, /lx92ttqds1x7vi7gsaa8 (+12 more) | 2026-09-29 22:17 UTC
show less
Bad Web Bot
๐ต๐ฑ
sefinek.net
2026-09-29 22:09:50
(19 hours ago)
Triggered Cloudflare WAF (firewallCustom) from BR.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint ...
show more
Triggered Cloudflare WAF (firewallCustom) from BR.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: /dashboard%2F.env | UA: CCBot/2.0 (https://commoncrawl.org/faq/) โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-29 22:06:21
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.95.247.152 (152.247.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.247.152 (152.247.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:06:15.126206 2026] [security2:error] [pid 24384:tid 24384] [client 34.95.247.152:55078] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||grimone.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "grimone.com"] [uri "/z9x8c7v6b5-debug-trigger-grimone.com"] [unique_id "arw2V2mNMqy7OCqSrdE0ogAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 21:43:50
(19 hours ago)
34.95.247.152 - - [29/Sep/2026:23:43:49 +0200] "GET /auth HTTP/1.1" 404 495 "-" "Mozilla/5.0 (Window ...
show more
34.95.247.152 - - [29/Sep/2026:23:43:49 +0200] "GET /auth HTTP/1.1" 404 495 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" ...
show less
Web App Attack
๐ฉ๐ช
pscriptos
2026-09-29 21:27:13
(20 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking