🇬🇧
openstrike.co.uk
2026-09-07 05:13:20
(10 hours ago)
296 attacks on config grabbing URLs (type 2), VC URLs, password grabbing URLs, env grabbing URLs (ty ...
show more
296 attacks on config grabbing URLs (type 2), VC URLs, password grabbing URLs, env grabbing URLs (type 2), env grabbing URLs, directory traversals, PHP URLs:
GET /secrets.yml HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/1.1
GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1
GET /@fs/proc/self/cwd/.env?raw?? HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /wp-config.php.swp HTTP/1.1
show less
Hacking
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-07 02:13:40
(13 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 23:26:41
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.255.242.128 (128.242.255.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.255.242.128 (128.242.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 19:26:32.340570 2026] [security2:error] [pid 32743:tid 32743] [client 35.255.242.128:39818] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.stagemadrid.com|F|2"] [data ".stagemadrid.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.stagemadrid.com"] [uri "/z9x8c7v6b5-debug-trigger-www.stagemadrid.com"] [unique_id "ap32qEeCSGFipdENK6m8PQAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 22:02:09
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.255.242.128 (128.242.255.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.255.242.128 (128.242.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:02:01.947687 2026] [security2:error] [pid 28686:tid 28686] [client 35.255.242.128:40400] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||leeu100.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "leeu100.com"] [uri "/z9x8c7v6b5-debug-trigger-leeu100.com"] [unique_id "ap3i2d8uL2Fz8RqQzanTawAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-06 22:00:16
(17 hours ago)
Auto-ban: >3000 req/min op 2026-09-06
Web App Attack
SSH
Hacking
🇳🇱
Savvii
2026-09-06 21:51:21
(17 hours ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-06 21:24:21
(18 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇳🇱
Savvii
2026-09-06 21:18:56
(18 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 21:13:51
(18 hours ago)
(mod_security) mod_security (id:210580) triggered by 35.255.242.128 (128.242.255.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 35.255.242.128 (128.242.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:13:44.545334 2026] [security2:error] [pid 12101:tid 12101] [client 35.255.242.128:49120] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||parkplacemotel.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "parkplacemotel.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "ap3XiIpN3qH_7QbqJlHtyQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-06 20:36:26
(18 hours ago)
137 requests with url.path *.oci/*
108 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 20:10:15
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.255.242.128 (128.242.255.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.242.128 (128.242.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:10:11.016373 2026] [security2:error] [pid 28918:tid 28918] [client 35.255.242.128:39134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "haco.us"] [uri "/@fs/var/task/.env"] [unique_id "ap3Io4rMrf6AeTxybim6uwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-06 19:08:23
(20 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /static//app/.env (+3 more) | 2026-09-06 19:08 UTC
show less
Hacking
Web App Attack
🇺🇸
mnsf
2026-09-06 19:05:23
(20 hours ago)
Scanning/Probing (16)
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-06 18:56:49
(20 hours ago)
Excessive multi-domain requests
Brute-Force
🇳🇱
maxxsense
2026-09-06 18:08:25
(21 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.255.242.128 (US/United States/128.24 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.255.242.128 (US/United States/128.242.255.35.bc.googleusercontent.com)
show less
SQL Injection