๐ฌ๐ง
openstrike.co.uk
2026-10-08 05:15:30
(6 hours ago)
3 attacks on env grabbing URLs:
GET /.env.local HTTP/1.1
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 04:42:54
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:42:46.203231 2026] [security2:error] [pid 14943:tid 14943] [client 104.23.170.87:12024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cestcaryntravel.com"] [uri "/.env.old"] [unique_id "ascfRjbjFXY6qDhPQ98VCQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-07 12:23:49
(23 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 11:34:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 07:34:14.891263 2026] [security2:error] [pid 14805:tid 14813] [client 104.23.170.87:9264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotairwelder.com"] [uri "/.env.save"] [unique_id "asYuNqCF7sfLKPcQq7Y0-AAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 08:06:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 04:06:51.603807 2026] [security2:error] [pid 19964:tid 19964] [client 104.23.170.87:11622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pseudospace.com"] [uri "/wp-config.php.save"] [unique_id "asX9m2yE4NecJpwKBOeSfwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-10-06 23:35:31
(1 day ago)
Accessed trap at '/.git/config'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 16:04:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:03:52.909818 2026] [security2:error] [pid 30254:tid 30254] [client 104.23.170.87:10308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "foundintranslation.net"] [uri "/wp-config.php"] [unique_id "asUb6KjMWMtBc26mbpBM2AAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 14:35:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 10:35:49.804374 2026] [security2:error] [pid 6480:tid 6480] [client 104.23.170.87:12178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mobresearchinc.com"] [uri "/.htaccess"] [unique_id "asUHRea9ETT24-6_QXKMcgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-06 14:25:07
(1 day ago)
[06/Oct/2026:17:25:06 +0300] -- 104.23.170.87 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-c ...
show more
[06/Oct/2026:17:25:06 +0300] -- 104.23.170.87 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-config.php.old HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-06 06:31:10
(2 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 23:51:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 19:51:03.906139 2026] [security2:error] [pid 7477:tid 7477] [client 104.23.170.87:9347] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brbcash.com"] [uri "/wp-config.php.bak"] [unique_id "asQ35ya9Ox4aeYorCi88fgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 20:46:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 16:46:02.098810 2026] [security2:error] [pid 6006:tid 6006] [client 104.23.170.87:10126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rangerroma.com"] [uri "/.env.staging"] [unique_id "asQMipldKgN6rB6GakiumQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 07:50:47
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 03:50:38.642702 2026] [security2:error] [pid 4524:tid 4555] [client 104.23.170.87:11921] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "captainpurpleproductions.com"] [uri "/.env.production"] [unique_id "asIFTgfDvbyFfOCH8ELb-QAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 07:11:02
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 03:10:59.636482 2026] [security2:error] [pid 20466:tid 20466] [client 104.23.170.87:9291] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thehomemailbox.com"] [uri "/.env.dev"] [unique_id "asH8A-67o5zoxiYCkE8w4wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-01 15:30:34
(6 days ago)
[01/Oct/2026:18:30:34 +0300] -- 104.23.170.87 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[01/Oct/2026:18:30:34 +0300] -- 104.23.170.87 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /secrets.json HTTP/1.1
show less
Bad Web Bot
Web App Attack