๐ฌ๐ง
openstrike.co.uk
2026-10-06 05:13:38
(3 days ago)
931 attacks on password/key grabbing URLs, VC URLs, env grabbing URLs (type 2), PHP URLs, env grabbi ...
show more
931 attacks on password/key grabbing URLs, VC URLs, env grabbing URLs (type 2), PHP URLs, env grabbing URLs, shell probes, config grabbing URLs (type 2), directory traversals:
GET /.git-credentials HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /userfiles/x?path=../../../../proc/self/environ HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /core/.env HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /secrets.yml HTTP/1.1
GET /..%2f.env HTTP/1.1
show less
Hacking
Web App Attack
๐ฌ๐ง
pinguin
2026-10-05 15:48:07
(3 days ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST metho ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /cgi-bin/php-cgi
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ณ๐ฑ
middelkoopcc
2026-10-05 13:04:01
(3 days ago)
2026-10-05 15:02:19 GET /static../.env [301] && 2026-10-05 15:02:19 GET /media../.env [301] && 2026- ...
show more
2026-10-05 15:02:19 GET /static../.env [301] && 2026-10-05 15:02:19 GET /media../.env [301] && 2026-10-05 15:02:19 GET /files../.env [301] && 113 more within 20 minutes
show less
Web App Attack
Anonymous
2026-10-05 10:53:12
(3 days ago)
Bot / seems abusive / Apache connections: 20
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 10:05:19
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.197.122.53 (53.122.197.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.197.122.53 (53.122.197.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 06:05:12.864838 2026] [security2:error] [pid 16877:tid 16877] [client 35.197.122.53:41836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zenventures.co.uk"] [uri "/media../.env"] [unique_id "asN2WB2R8JB3dDFLmD_SvgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
spot
2026-10-05 08:59:33
(3 days ago)
35.197.122.53 - - [05/Oct/2026:09:59:31 +0100] "GET /public/plugins/text/../../../../../../../../pro ...
show more
35.197.122.53 - - [05/Oct/2026:09:59:31 +0100] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 539 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Web App Attack
VPN IP
๐ฌ๐ง
AvonleaConsulting
2026-10-05 07:44:44
(3 days ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 07:42:35
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.197.122.53 (53.122.197.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.197.122.53 (53.122.197.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 03:42:30.159596 2026] [security2:error] [pid 5868:tid 5868] [client 35.197.122.53:56034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stpetersplayers.co.uk"] [uri "/static../.env"] [unique_id "asNU5u1AOPB2dyMtrDRkxgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
bensmithurst
2026-10-05 07:28:44
(3 days ago)
35.197.122.53 - - [05/Oct/2026:07:28:42 +0000] "GET /..%2f.env HTTP/1.1" 400 150 "-" "-"
35.197.122. ...
show more
35.197.122.53 - - [05/Oct/2026:07:28:42 +0000] "GET /..%2f.env HTTP/1.1" 400 150 "-" "-"
35.197.122.53 - - [05/Oct/2026:07:28:43 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 150 "-" "-"
35.197.122.53 - - [05/Oct/2026:07:28:43 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 150 "-" "-"
35.197.122.53 - - [05/Oct/2026:07:28:44 +0000] "GET /resources/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 150 "-" "-"
35.197.122.53 - - [05/Oct/2026:07:28:44 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 150 "-" "-"
... [host=LAN***]
show less
Web App Attack
๐ฉ๐ช
SwinT
2026-10-05 07:00:10
(4 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 06:37:37
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.197.122.53 (53.122.197.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.197.122.53 (53.122.197.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 02:37:34.030641 2026] [security2:error] [pid 1872:tid 1872] [client 35.197.122.53:33972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "powersystemprotection.co.uk"] [uri "/.htpasswd"] [unique_id "asNFrtSKUWIqJA20Jt3Q5gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 06:00:41
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.197.122.53 (53.122.197.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.197.122.53 (53.122.197.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 02:00:35.460821 2026] [security2:error] [pid 19952:tid 19952] [client 35.197.122.53:54048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "natashahenry.co.uk"] [uri "/.htpasswd"] [unique_id "asM9A_HPmrzYjddv_Kg7MwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-10-05 05:58:27
(4 days ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-10-05 05:14:19
(4 days ago)
459 attacks on env grabbing URLs (type 2), directory traversals, VC URLs, PHP URLs, env grabbing URL ...
show more
459 attacks on env grabbing URLs (type 2), directory traversals, VC URLs, PHP URLs, env grabbing URLs, config grabbing URLs (type 2), password/key grabbing URLs, shell probes:
GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /.git/HEAD HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /api/.env/public/.env HTTP/1.1
GET /app-config.json HTTP/1.1
GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
svr
2026-10-05 04:38:57
(4 days ago)
Abusive Automated Web Scanner
Web App Attack