๐ฌ๐ง
openstrike.co.uk
2026-08-26 05:16:09
(2 hours ago)
5 attacks on VC URLs, config grabbing URLs (type 2), PHP URLs, env grabbing URLs:
GET /.git/config H ...
show more
5 attacks on VC URLs, config grabbing URLs (type 2), PHP URLs, env grabbing URLs:
GET /.git/config HTTP/1.1
GET /config.json HTTP/1.1
GET /wp-config.php-backup HTTP/1.1
GET /.env.bak HTTP/1.1
show less
Hacking
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-26 03:14:11
(4 hours ago)
Multiple WAF Violations
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-08-26 02:04:04
(5 hours ago)
[Wed Aug 26 12:04:03.267223 2026] [security2:error] [pid 320131] [client 35.192.41.74:62190] [client ...
show more
[Wed Aug 26 12:04:03.267223 2026] [security2:error] [pid 320131] [client 35.192.41.74:62190] [client 35.192.41.74] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "shotbysuzanne.com.au"] [uri "/.env"] [unique_id "ao5Jk_UJjGtnEeoZePuidwAAAAg"]
...
show less
Web App Attack
๐ธ๐ช
SkyDancer
2026-08-26 00:04:59
(7 hours ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
๐ฌ๐ง
consul.to
2026-08-25 21:23:13
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
mnsf
2026-08-25 21:05:13
(10 hours ago)
Abuse Detected (24)
Brute-Force
Web App Attack
Anonymous
2026-08-25 20:16:33
(11 hours ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 18:03:09
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.41.74 (74.41.192.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.41.74 (74.41.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 14:03:02.568461 2026] [security2:error] [pid 7509:tid 7509] [client 35.192.41.74:47324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shipthunder.com"] [uri "/.env"] [unique_id "ao3Y1vlLwHzjMFwXvZz16QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
findlab
2026-08-25 18:00:01
(13 hours ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
Anonymous
2026-08-25 17:30:03
(14 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 17:29:04
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.41.74 (74.41.192.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.41.74 (74.41.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 13:28:56.474877 2026] [security2:error] [pid 24547:tid 24547] [client 35.192.41.74:14340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shinynew.com"] [uri "/.env"] [unique_id "ao3Q2HX6OjYpteuc1Oxv-wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-25 17:05:19
(14 hours ago)
Abuse Detected (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 16:41:42
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.41.74 (74.41.192.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.41.74 (74.41.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 12:41:38.730163 2026] [security2:error] [pid 18993:tid 18993] [client 35.192.41.74:46354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shine-x.com"] [uri "/.env"] [unique_id "ao3FwqqPn8w8WjWeA-CbDQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-25 16:35:14
(15 hours ago)
[25/Aug/2026:19:35:14 +0300] -- 35.192.41.74 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/ ...
show more
[25/Aug/2026:19:35:14 +0300] -- 35.192.41.74 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-08-25 16:24:54
(15 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack