🇬🇧
openstrike.co.uk
2026-09-06 05:12:54
(1 hour ago)
13 attacks on env grabbing URLs, PHP URLs:
GET /.env.old HTTP/1.1
GET /wp-config.php.bak HTTP/1.1
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:51:41
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.119.89.65 (65.89.119.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.119.89.65 (65.89.119.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:51:37.731285 2026] [security2:error] [pid 26254:tid 26254] [client 136.119.89.65:36578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.littlestarbookspub.com"] [uri "/.env.prod"] [unique_id "apzjScUMYJLGebyhu7NZzQAAAHI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
4server
2026-09-06 03:49:59
(3 hours ago)
[SunSep0605:49:54.0778642026][security2:error][pid3170032:tid3170242][client136.119.89.65:0]ModSecur ...
show more
[SunSep0605:49:54.0778642026][security2:error][pid3170032:tid3170242][client136.119.89.65:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"cpcalendars.mondo-it.ch\"][uri\"/.env.dev\"][unique_id\"apzi4hBW4mWQEeIXXivc7wAAAUY\"]
show less
Hacking
Web App Attack
🇫🇷
COMAITE
2026-09-06 02:55:54
(4 hours ago)
Suspicious URL access.
Web App Attack
🇸🇪
vaia.cloud
2026-09-06 02:55:48
(4 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇫🇷
✨
2026-09-06 02:44:14
(4 hours ago)
Domain : afrikkaengines.co.za
Rule : hack
2026-09-06 02:41:30 ***hidden-privacy*** GET /wp-config.ph ...
show more
Domain : afrikkaengines.co.za
Rule : hack
2026-09-06 02:41:30 ***hidden-privacy*** GET /wp-config.php.bak - 443 - 136.119.89.65 HTTP/1.1 crusader-worker/1.0 - afrikkaengines.co.za 403 0 64 0 109 1169 - -
show less
Hacking
SQL Injection
Brute-Force
🇲🇾
Rizzy
2026-09-06 02:08:02
(4 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇳🇱
debestelapp
2026-09-06 01:30:11
(5 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:47:40
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.119.89.65 (65.89.119.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.119.89.65 (65.89.119.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:47:34.582611 2026] [security2:error] [pid 25243:tid 25243] [client 136.119.89.65:45568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.satanisdead.com"] [uri "/.env.backup"] [unique_id "apy4JnFepf-aFo6oFKvawwAAAGc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
Inartis
2026-09-06 00:45:09
(6 hours ago)
136.119.89.65 - - [06/Sep/2026:02:45:08 +0200] "GET /.env HTTP/1.1" 301 5744 "-" "crusader-worker/1. ...
show more
136.119.89.65 - - [06/Sep/2026:02:45:08 +0200] "GET /.env HTTP/1.1" 301 5744 "-" "crusader-worker/1.0"
136.119.89.65 - - [06/Sep/2026:02:45:09 +0200] "GET /.env.local HTTP/1.1" 301 503 "-" "crusader-worker/1.0"
136.119.89.65 - - [06/Sep/2026:02:45:09 +0200] "GET /.env.prod HTTP/1.1" 301 5754 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
paissangroup
2026-09-06 00:36:37
(6 hours ago)
Multiple WAF Violations
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 00:30:41
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 23:54:38
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.119.89.65 (65.89.119.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.119.89.65 (65.89.119.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:54:33.201665 2026] [security2:error] [pid 6667:tid 6667] [client 136.119.89.65:54176] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.oceandrivebeach.net"] [uri "/.env.prod"] [unique_id "apyruft-PExO56vB_x249AAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:27:17
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.119.89.65 (65.89.119.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.119.89.65 (65.89.119.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:27:13.394406 2026] [security2:error] [pid 28335:tid 28335] [client 136.119.89.65:32936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.annpietrangelo.com"] [uri "/.env.bak"] [unique_id "apylUYxH-esVnCytt8gEZwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:32:14
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.119.89.65 (65.89.119.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.119.89.65 (65.89.119.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:32:07.897511 2026] [security2:error] [pid 29018:tid 29018] [client 136.119.89.65:60192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toppress.ca"] [uri "/.env.example"] [unique_id "apyYZ41swMude9a1w4uQaQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack