๐ฌ๐ง
openstrike.co.uk
2026-10-06 05:13:56
(1 day ago)
714 attacks on shell probes, env grabbing URLs, directory traversals, config grabbing URLs (type 2), ...
show more
714 attacks on shell probes, env grabbing URLs, directory traversals, config grabbing URLs (type 2), PHP URLs, env grabbing URLs (type 2), VC URLs, password/key grabbing URLs:
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /?allowOutsideWorkspace=true&path=/app/.env HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /app-config.json HTTP/1.1
GET /?modulepart=systemtools&file=../conf/conf.php&hashp=shared HTTP/1.1
GET /?file=/proc/self/environ HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/1.1
show less
Hacking
Web App Attack
๐ฎ๐ช
Jim Keir
2026-10-05 14:47:27
(2 days ago)
2026-10-05 14:47:27 35.194.169.4 File scanning, blocking 35.194.169.4 for 5 minutes
2026-10-05 14:47 ...
show more
2026-10-05 14:47:27 35.194.169.4 File scanning, blocking 35.194.169.4 for 5 minutes
2026-10-05 14:47:27 35.194.169.4 File scanning, blocking 35.194.169.4 for 5 minutes
2026-10-05 14:47:27 35.194.169.4 File scanning, blocking 35.194.169.4 for 5 minutes
2026-10-05 14:47:27 35.194.169.4 File scanning, blocking 35.194.169.4 for 5 minutes
show less
Web App Attack
Anonymous
2026-10-05 14:14:29
(2 days ago)
Aggressive web scan
Web App Attack
๐จ๐ญ
zynex
2026-10-05 13:49:36
(2 days ago)
URL Probing: /@fs/src/.env
Web App Attack
Anonymous
2026-10-05 12:56:22
(2 days ago)
CrowdSec detection: crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-05 07:32:27
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.194.169.4 (4.169.194.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.169.4 (4.169.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 03:32:23.001815 2026] [security2:error] [pid 1432:tid 1432] [client 35.194.169.4:48822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zenventures.co.uk"] [uri "/media../.env"] [unique_id "asNSh9FJ9rSFLPVYmIDOFAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ELYAZ
2026-10-05 07:08:54
(2 days ago)
(y3) Failed access -byebye- from 35.194.169.4 (TW/Taiwan/4.169.194.35.bc.googleusercontent.com): (C ...
show more
(y3) Failed access -byebye- from 35.194.169.4 (TW/Taiwan/4.169.194.35.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
๐ฌ๐ง
WebNiraj
2026-10-05 06:13:26
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 35.194.169.4 (TW/Taiwan/4.169.194.35.bc.googleu ...
show more
(mod_security) mod_security (id:949110) triggered by 35.194.169.4 (TW/Taiwan/4.169.194.35.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
๐ฌ๐ง
Aetherweb Ark
2026-10-05 05:58:00
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 35.194.169.4 (TW/Taiwan/4.169.194.35.bc.googleu ...
show more
(mod_security) mod_security (id:949110) triggered by 35.194.169.4 (TW/Taiwan/4.169.194.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ซ๐ท
spot
2026-10-05 05:45:37
(2 days ago)
35.194.169.4 - - [05/Oct/2026:06:45:36 +0100] "GET /public/plugins/text/../../../../../../../../proc ...
show more
35.194.169.4 - - [05/Oct/2026:06:45:36 +0100] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 539 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Web App Attack
VPN IP
๐ซ๐ฎ
Christopher Hughes
2026-10-05 05:17:16
(2 days ago)
.env scan
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-10-05 05:14:20
(2 days ago)
393 attacks on VC URLs, config grabbing URLs (type 2), PHP URLs, env grabbing URLs, password/key gra ...
show more
393 attacks on VC URLs, config grabbing URLs (type 2), PHP URLs, env grabbing URLs, password/key grabbing URLs, shell probes, directory traversals, env grabbing URLs (type 2):
GET /.git/config HTTP/1.1
GET /app-config.json HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env HTTP/1.1
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/proc/self/environ HTTP/1.1
show less
Hacking
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-10-05 04:59:34
(2 days ago)
35.194.169.4 - - [05/Oct/2026:05:59:32 +0100] "GET /user/login HTTP/1.1" 404 6476 "-" "Mozilla/5.0 ( ...
show more
35.194.169.4 - - [05/Oct/2026:05:59:32 +0100] "GET /user/login HTTP/1.1" 404 6476 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
35.194.169.4 - - [05/Oct/2026:05:59:32 +0100] "POST /lib/terminal-xhr.php HTTP/1.1" 403 6475 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
35.194.169.4 - - [05/Oct/2026:05:59:32 +0100] "GET /users/login HTTP/1.1" 404 6476 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
๐ฉ๐ช
33three
2026-10-05 04:52:46
(3 days ago)
Fail2Ban jail WebAttack triggered
Brute-Force
๐ฌ๐ง
Yosi
2026-10-05 03:40:51
(3 days ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force