🇬🇧
openstrike.co.uk
2026-09-07 05:13:43
(1 hour ago)
244 attacks on config grabbing URLs (type 2), PHP URLs, directory traversals, env grabbing URLs, env ...
show more
244 attacks on config grabbing URLs (type 2), PHP URLs, directory traversals, env grabbing URLs, env grabbing URLs (type 2), password grabbing URLs:
GET /config.yaml HTTP/1.1
GET /pi.php HTTP/1.1
GET /..%2f.env HTTP/1.1
GET /_image?href=/../../../.env HTTP/1.1
GET /_image?href=/proc/self/environ HTTP/1.1
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc HTTP/1.1
show less
Hacking
Web App Attack
🇩🇪
larse99
2026-09-07 00:51:13
(6 hours ago)
Detected Scanning / Hacking activity
Port Scan
Hacking
🇩🇪
Gwyneth Llewelyn
2026-09-07 00:35:13
(6 hours ago)
2026/09/07 01:35:11 [error] 380594#380594: *3352620 access forbidden by rule, client: 207.175.15.84, ...
show more
2026/09/07 01:35:11 [error] 380594#380594: *3352620 access forbidden by rule, client: 207.175.15.84, server: api.betatechnologies.info, request: "GET /static//app/.env HTTP/2.0", host: "api.betatechnologies.info"
2026/09/07 01:35:11 [error] 380594#380594: *3352621 access forbidden by rule, client: 207.175.15.84, server: api.betatechnologies.info, request: "GET /files../.env HTTP/2.0", host: "api.betatechnologies.info"
2026/09/07 01:35:11 [error] 380595#380595: *3352622 access forbidden by rule, client: 207.175.15.84, server: api.betatechnologies.info, request: "GET /static//home/user/.env HTTP/2.0", host: "api.betatechnologies.info"
show less
Brute-Force
Web App Attack
🇩🇪
grassau.com
2026-09-06 23:55:00
(7 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 207.175.15.84 (BE/Be ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 207.175.15.84 (BE/Belgium/Brussels Capital/Brussels/84.15.175.207.bc.googleusercontent.com)
show less
Bad Web Bot
🇳🇱
Site.eu
2026-09-06 22:32:07
(8 hours ago)
Excessive multi-domain requests
Brute-Force
🇬🇧
thetomtaylor.co.uk
2026-09-06 22:20:05
(8 hours ago)
Fail2Ban - [WAF]ModSecurity rule violation on modsecurity ... [wa01,wa02]
Hacking
SQL Injection
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-06 20:48:22
(10 hours ago)
[06/Sep/2026:23:48:21 +0300] -- 207.175.15.84 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[06/Sep/2026:23:48:21 +0300] -- 207.175.15.84 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /rclone.conf HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇩🇪
Savvii
2026-09-06 18:24:53
(12 hours ago)
20 attempts against mh-misbehave-ban on train
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Gwyneth Llewelyn
2026-09-06 17:38:41
(13 hours ago)
2026/09/06 18:38:37 [error] 380594#380594: *3275107 access forbidden by rule, client: 207.175.15.84, ...
show more
2026/09/06 18:38:37 [error] 380594#380594: *3275107 access forbidden by rule, client: 207.175.15.84, server: streaming.betatechnologies.info, request: "GET /static../.env HTTP/2.0", host: "streaming.betatechnologies.info"
2026/09/06 18:38:38 [error] 380594#380594: *3275107 access forbidden by rule, client: 207.175.15.84, server: streaming.betatechnologies.info, request: "GET /files../.env HTTP/2.0", host: "streaming.betatechnologies.info"
2026/09/06 18:38:38 [error] 380594#380594: *3275107 access forbidden by rule, client: 207.175.15.84, server: streaming.betatechnologies.info, request: "GET /.//.env HTTP/2.0", host: "streaming.betatechnologies.info"
show less
Brute-Force
Web App Attack
Anonymous
2026-09-06 17:03:24
(14 hours ago)
Observed scanned 1 known-sensitive endpoint(s), e.g.: /.aws/credentials
Bad Web Bot
Web App Attack
🇩🇪
verlon
2026-09-06 15:58:12
(15 hours ago)
2026/09/06 17:57:58 [error] 1150031#1150031: *499536 access forbidden by rule, client: 207.175.15.84 ...
show more
2026/09/06 17:57:58 [error] 1150031#1150031: *499536 access forbidden by rule, client: 207.175.15.84, server: suitandmore.hu, request: "GET /.github/.env HTTP/2.0", host: "suitandmore.hu"
2026/09/06 17:57:58 [error] 1150031#1150031: *499536 access forbidden by rule, client: 207.175.15.84, server: suitandmore.hu, request: "GET /.svn/entries HTTP/2.0", host: "suitandmore.hu"
2026/09/06 17:58:09 [error] 1150031#1150031: *499536 access forbidden by rule, client: 207.175.15.84, server: suitandmore.hu, request: "GET /.gitconfig HTTP/2.0", host: "suitandmore.hu"
...
show less
Hacking
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 14:35:10
(16 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 14:13:40
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 207.175.15.84 (84.15.175.207.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 207.175.15.84 (84.15.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:13:35.168649 2026] [security2:error] [pid 20105:tid 20105] [client 207.175.15.84:52308] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.greighhouse.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.greighhouse.com"] [uri "/rclone.conf"] [unique_id "ap11D5X4pEvROpQQ-2fBSgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ipoac.nl
2026-09-06 14:07:57
(16 hours ago)
[Sun Sep 06 16:07:55.313013 2026] [core:error] [pid 1051267:tid 1051396] [remote 207.175.15.84:33704 ...
show more
[Sun Sep 06 16:07:55.313013 2026] [core:error] [pid 1051267:tid 1051396] [remote 207.175.15.84:33704] AH10244: invalid URI path (/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-06 13:49:12
(17 hours ago)
(mod_security) mod_security (id:210580) triggered by 207.175.15.84 (84.15.175.207.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 207.175.15.84 (84.15.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 09:49:07.014893 2026] [security2:error] [pid 12196:tid 12196] [client 207.175.15.84:52980] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.riverflow.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: ../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.riverflow.com"] [uri "/userfiles"] [unique_id "ap1vU-aAHPNX5HQyPeiTpgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack