๐ฌ๐ง
openstrike.co.uk
2026-10-01 05:13:34
(3 days ago)
228 attacks on env grabbing URLs (type 2), config grabbing URLs (type 2), password/key grabbing URLs ...
show more
228 attacks on env grabbing URLs (type 2), config grabbing URLs (type 2), password/key grabbing URLs, env grabbing URLs, VC URLs, directory traversals, shell probes, PHP URLs:
GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1
GET /config/storage.yml HTTP/1.1
GET /id_ecdsa HTTP/1.1
GET /.github/.env HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-09-30 06:00:28
(4 days ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Email Spam
๐ช๐ธ
robotstxt
2026-09-30 05:01:39
(4 days ago)
35.234.245.123 - - [30/Sep/2026:05:01:37 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 193 "-" "-" "-" e ...
show more
35.234.245.123 - - [30/Sep/2026:05:01:37 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.234.245.123"
35.234.245.123 - - [30/Sep/2026:05:01:37 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="35.234.245.123"
35.234.245.123 - - [30/Sep/2026:05:01:37 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="35.234.245.123"
...
show less
Web Spam
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-09-30 05:00:09
(4 days ago)
Active Response: IP 35.234.245.123 Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). Re ...
show more
Active Response: IP 35.234.245.123 Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-09-30 04:45:24
(4 days ago)
Remote Command Execution: Direct Unix Command Execution. Pattern match "(?i)(?:^|b (932250-195)
Hacking
๐ฒ๐พ
Rizzy
2026-09-30 03:48:45
(4 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
EGP Abuse Dept
2026-09-30 03:46:19
(4 days ago)
Scanning for web/db/file exploits on www.kerstpakket.expert
SQL Injection
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 03:45:10
(4 days ago)
[30/Sep/2026:13:45:10 +1000] "GET /fvtetmxtq92ewebssnrp HTTP/1.1" 403 239 "Mozilla/5.0 (compatible; ...
show more
[30/Sep/2026:13:45:10 +1000] "GET /fvtetmxtq92ewebssnrp HTTP/1.1" 403 239 "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
[30/Sep/2026:13:45:10 +1000] "GET /yfx94m43xmf8gh9iv553 HTTP/1.1" 403 239 "CCBot/2.0 (https://commoncrawl.org/faq/)"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 03:22:00
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 35.234.245.123 (123.245.234.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.245.123 (123.245.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:21:57.293851 2026] [security2:error] [pid 30311:tid 30311] [client 35.234.245.123:58736] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ken-parker.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ken-parker.com"] [uri "/z9x8c7v6b5-debug-trigger-ken-parker.com"] [unique_id "aryAVc5t5iYkDnWlIwqZeQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-09-30 03:11:18
(4 days ago)
Domain : techoasis.co.za
Rule : env
2026-09-30 03:01:00 ***hidden-privacy*** GET /.env.save - 443 - ...
show more
Domain : techoasis.co.za
Rule : env
2026-09-30 03:01:00 ***hidden-privacy*** GET /.env.save - 443 - 35.234.245.123 HTTP/2 Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] ) - techoasis.co.za 403 0 0 1452 426 288 - -
show less
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-30 03:04:22
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.245.123 (123.245.234.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.245.123 (123.245.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:04:17.235568 2026] [security2:error] [pid 13630:tid 13630] [client 35.234.245.123:35570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keeftone.com"] [uri "/web/.env"] [unique_id "arx8MdSfCrZ8PUKDMS8PwAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 02:49:12
(4 days ago)
Bot / seems abusive / Apache connections: 21
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 02:35:08
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.245.123 (123.245.234.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.245.123 (123.245.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:35:01.893895 2026] [security2:error] [pid 19166:tid 19166] [client 35.234.245.123:60410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keithwatt.powerastronomy.com"] [uri "/.env.example"] [unique_id "arx1VcnoWI9urirM49keHwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 01:55:21
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.245.123 (123.245.234.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.245.123 (123.245.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:55:17.233885 2026] [security2:error] [pid 26859:tid 26859] [client 35.234.245.123:41256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kdgsf.xyz"] [uri "/.git/config"] [unique_id "arxsBRaUcuGtNz_-3OiwfwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-30 01:42:50
(4 days ago)
Web attack/malicious scanning detected
Web App Attack