🇬🇧
openstrike.co.uk
2026-09-06 05:13:37
(1 hour ago)
13 attacks on env grabbing URLs, PHP URLs:
GET /.env.prod HTTP/1.1
GET /wp-config.php.swp HTTP/1.1
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:53:34
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.63.81 (81.63.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.63.81 (81.63.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:53:26.817010 2026] [security2:error] [pid 6234:tid 6234] [client 136.66.63.81:39654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.vespaitaliancafe.com"] [uri "/.env"] [unique_id "apzjtlHWYrwWCPX6BytkmAAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
poundawebsiteltd
2026-09-06 03:51:46
(2 hours ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 136.66.63. ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 136.66.63.81 (US/United States/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 136.66.63.81 (US/United States/81.63.66.136.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:39:28
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.63.81 (81.63.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.63.81 (81.63.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:39:22.968919 2026] [security2:error] [pid 23099:tid 23099] [client 136.66.63.81:48120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ieas.org"] [uri "/.env.backup"] [unique_id "apzSWnv-N3e-trn0gUGZvgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-06 02:28:19
(4 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 136.66.63.81 (US/United States/81.63. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 136.66.63.81 (US/United States/81.63.66.136.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
🇺🇸
mnsf
2026-09-06 02:05:17
(4 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇳🇱
e.fierstra
2026-09-06 01:55:57
(4 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:40:42
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.63.81 (81.63.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.63.81 (81.63.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:40:37.921986 2026] [security2:error] [pid 1360:tid 1360] [client 136.66.63.81:40464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yeejia.net"] [uri "/.env.example"] [unique_id "apzElZGGzekcU8lD1FKWMAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:55:18
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.63.81 (81.63.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.63.81 (81.63.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:55:12.640897 2026] [security2:error] [pid 16900:tid 16906] [client 136.66.63.81:43950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bobchaos.com"] [uri "/.env.local"] [unique_id "apyr4KTNKh2FGrL4HnSAfwAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:58:49
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.63.81 (81.63.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.63.81 (81.63.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:58:43.839164 2026] [security2:error] [pid 4005:tid 4005] [client 136.66.63.81:60334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.dd214chronicle.org"] [uri "/wp-config.php.bak"] [unique_id "apyeo4rv6ArAINOP2FImSwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-05 22:45:57
(7 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:35:59
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.63.81 (81.63.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.63.81 (81.63.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:35:53.427995 2026] [security2:error] [pid 24605:tid 24605] [client 136.66.63.81:53248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gmroyalties.soviaenterprises.com"] [uri "/.env.local"] [unique_id "apyZSTH__Y1lKP4Z4wBizwAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-05 22:19:37
(8 hours ago)
Aggressive web search of vulnerable pages: /.env.local /.env /mysql.sql /backup.tar.gz /dump.tar.gz ...
show more
Aggressive web search of vulnerable pages: /.env.local /.env /mysql.sql /backup.tar.gz /dump.tar.gz /web.zip /backup.zip ...
show less
Web App Attack
🇩🇪
webanyone
2026-09-05 22:17:53
(8 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:15:25
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.63.81 (81.63.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.63.81 (81.63.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:15:18.362228 2026] [security2:error] [pid 3505780:tid 3505896] [client 136.66.63.81:38754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nicholsinvest.com"] [uri "/.env.old"] [unique_id "apyUdqeVUu6W99IeSwH9uAAAAgU"]
show less
Brute-Force
Bad Web Bot
Web App Attack