🇬🇧
openstrike.co.uk
2026-09-07 05:13:48
(1 hour ago)
191 attacks on VC URLs, config grabbing URLs (type 2), PHP URLs, directory traversals, password grab ...
show more
191 attacks on VC URLs, config grabbing URLs (type 2), PHP URLs, directory traversals, password grabbing URLs, env grabbing URLs, env grabbing URLs (type 2):
GET /.git/HEAD HTTP/1.1
GET /config/secrets.yml HTTP/1.1
GET /wp-config.php.swp HTTP/1.1
GET /..%2f.env HTTP/1.1
GET /.aws/credentials HTTP/1.1
GET /v2/.env HTTP/1.1
GET /userfiles?path=../../../../proc/self/environ HTTP/1.1
show less
Hacking
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-07 04:08:01
(2 hours ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice02,wa01]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 02:53:31
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.155.169 (169.155.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.155.169 (169.155.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 22:53:26.437475 2026] [security2:error] [pid 25273:tid 25377] [client 35.194.155.169:60900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tieco.salvoni.com"] [uri "/.env"] [unique_id "ap4nJg-v8jLfElhPvSsjZwAAAUY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 02:52:12
(3 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-09-07 02:12:12
(4 hours ago)
[osotir.org] httpd-config-scan: sites=www.thisavros.prostiniki.gr; logs=/var/log/httpd/domains/prost ...
show more
[osotir.org] httpd-config-scan: sites=www.thisavros.prostiniki.gr; logs=/var/log/httpd/domains/prostiniki.gr.thisavros.log; samples=/.oci/config | /.oci/oci_api_key.pem | /.oci/oci_api_key_public.pem
show less
Hacking
Web App Attack
Anonymous
2026-09-07 00:32:04
(6 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.194.155.169 (TW/Taiwan/169.155.194.35.bc. ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.194.155.169 (TW/Taiwan/169.155.194.35.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.194.155.169 - - [07/Sep/2026:02:32:01 +0200] "GET /server.key HTTP/2.0" 406 317 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
35.194.155.169 - - [07/Sep/2026:02:32:01 +0200] "GET /privatekey.key HTTP/2.0" 406 317 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
35.194.155.169 - - [07/Sep/2026:02:32:01 +0200] "GET /host.key HTTP/2.0" 406 317 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-07 00:25:43
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.194.155.169 (169.155.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.155.169 (169.155.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 20:25:35.684133 2026] [security2:error] [pid 13448:tid 13448] [client 35.194.155.169:44586] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dashboard.alitcogroup.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dashboard.alitcogroup.com"] [uri "/localhost.key"] [unique_id "ap4Ef63CwfQM7bNaS7TeAgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
WizardsToolkit
2026-09-06 22:49:43
(7 hours ago)
tried to access forbidden files; attempted to access /static//app/.env
Web App Attack
🇫🇮
Shaik Sai Meera
2026-09-06 21:55:08
(8 hours ago)
IM360 WAF: Laravel .env file access
Brute-Force
Open Proxy
Anonymous
2026-09-06 20:00:07
(10 hours ago)
| [Dangerous/Taiwan] Aggressive IP 35.194.155.169 (~30 hits). Type: DoS Defender- Web server 400 err ...
show more
| [Dangerous/Taiwan] Aggressive IP 35.194.155.169 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
🇨🇭
zynex
2026-09-06 17:49:07
(12 hours ago)
URL Probing: /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 16:35:52
(13 hours ago)
(mod_security) mod_security (id:210580) triggered by 35.194.155.169 (169.155.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 35.194.155.169 (169.155.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 12:35:44.805403 2026] [security2:error] [pid 4184:tid 4184] [client 35.194.155.169:52182] ModSecurity: Access denied with code 403 (phase 2). Matched phrase ".ssh/id_rsa" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.smilingorc.com|F|2"] [data "Matched Data: .ssh/id_rsa found within ARGS:filename: file:/root/.ssh/id_rsa"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.smilingorc.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "ap2WYO3qL-gZ8enoA0B9jAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
grassau.com
2026-09-06 16:26:50
(14 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.194.155.169 (TW/T ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.194.155.169 (TW/Taiwan/Taipei City/Taipei/169.155.194.35.bc.googleusercontent.com)
show less
Bad Web Bot
🇳🇱
Site.eu
2026-09-06 15:12:44
(15 hours ago)
Excessive multi-domain requests
Brute-Force
🇩🇪
LRob
2026-09-06 15:04:24
(15 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.aws/config (+1 more) | 2026-09-06 15:04 UTC
show less
Hacking
Web App Attack