๐ฌ๐ง
openstrike.co.uk
2026-05-13 05:13:34
(4 months ago)
109 attacks on env grabbing URLs, VC URLs, config grabbing URLs (type 2), site downloads, password g ...
show more
109 attacks on env grabbing URLs, VC URLs, config grabbing URLs (type 2), site downloads, password grabbing URLs, PHP URLs:
GET /.env.example HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /config/local.json HTTP/1.1
GET /db.sql HTTP/1.1
GET /.aws/credentials HTTP/1.1
GET /config/config.inc.php HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
updown.io
2026-05-10 15:35:10
(4 months ago)
{"level":"info","ts":1778427304.0876956,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1778427304.0876956,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"2a04:52c0:102:e516::1","remote_port":"36500","client_ip":"2a04:52c0:102:e516::1","proto":"HTTP/1.1","method":"GET","host":"status.gpltimes.com","uri":"/_next/static/chunks/app/layout.js","headers":{"User-Agent":["Mozilla/5.0 (compatible; xAI-SearchBot/1.0; +https://x.ai)"],"Accept":["*/*"],"Accept-Encoding":["gzip, deflate"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"http/1.1","server_name":"status.gpltimes.com"}},"bytes_read":0,"user_id":"","duration":0.000095311,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1778427304.090257,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"2a04:52c0:102:e516::1","remote_port":"36570","client_ip":"2a04:52c0:102:e516::1","proto":"HTTP/1.1","method":"GET","host":"status.gpltimes.com","uri":"
...
show less
DDoS Attack
Web App Attack
๐ซ๐ท
fenogent.com
2026-05-04 00:35:04
(4 months ago)
CrowdSec: crowdsecurity/recidive (1 events)
Web App Attack
๐บ๐ธ
Charlesiv
2026-05-01 20:01:35
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 60404 (The Infrastructur ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 60404 (The Infrastructure Group B.V.)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-05-01T18:30:28Z
Ray ID: 9f50db8ea8280c49
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.3.26
show less
Bad Web Bot
๐บ๐ธ
Charlesiv
2026-04-30 04:02:03
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 60404 (The Infrastructur ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 60404 (The Infrastructure Group B.V.)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-04-29T23:41:56Z
Ray ID: 9f42290b2a71970b
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/126.0.0.0 Safari/537.36
show less
Bad Web Bot
๐ฉ๐ช
4server
2026-04-29 21:04:50
(4 months ago)
[WedApr2923:04:47.6893812026][security2:error][pid2445841:tid2445865][client2a04:52c0:102:e516::1:0] ...
show more
[WedApr2923:04:47.6893812026][security2:error][pid2445841:tid2445865][client2a04:52c0:102:e516::1:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"hopitalprovidence.org\"][uri\"/\"][unique_id\"afJyb8HrLv55FO8HHzgD7wAAAI0\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
Charlesiv
2026-04-29 16:00:13
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 60404 (The Infrastructur ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 60404 (The Infrastructure Group B.V.)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-04-29T15:54:05Z
Ray ID: 9f3f7bb6d9f60e14
UA: Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-29 04:08:05
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:102:e516::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:102:e516::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 00:07:55.317314 2026] [security2:error] [pid 25937:tid 25937] [client 2a04:52c0:102:e516::1:54518] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "highfydelity.com.fydelity.net"] [uri "/.env"] [unique_id "afGEGxwbD8b99Ta8tVZUfQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-29 02:42:32
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:102:e516::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:102:e516::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 22:42:27.076955 2026] [security2:error] [pid 19067:tid 19067] [client 2a04:52c0:102:e516::1:46726] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hiddenhistory.info"] [uri "/.env.production"] [unique_id "afFwE2MB5WPHroj_nHVVXAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 22:53:05
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:102:e516::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:102:e516::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 18:52:55.692547 2026] [security2:error] [pid 30424:tid 30424] [client 2a04:52c0:102:e516::1:45002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.iberhome.net"] [uri "/.env"] [unique_id "afE6R0HH_wfjPgeA_05NmwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
monn45888
2026-04-28 21:51:51
(4 months ago)
$f2bV_matches
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 20:55:22
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:102:e516::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:102:e516::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 16:55:19.123284 2026] [security2:error] [pid 8998:tid 9088] [client 2a04:52c0:102:e516::1:58308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.soyjuantrece.com.emehache.net"] [uri "/.env"] [unique_id "afEet-pQe9n5pmG5AHur4AAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 11:17:13
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:102:e516::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:102:e516::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 07:17:05.719185 2026] [security2:error] [pid 26628:tid 26628] [client 2a04:52c0:102:e516::1:55580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tijuana-bibles.tijuanabible.org"] [uri "/.env"] [unique_id "afCXMQIQe13U4V7F6Xi8cgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 09:06:55
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:102:e516::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:102:e516::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 05:06:45.423382 2026] [security2:error] [pid 21407:tid 21407] [client 2a04:52c0:102:e516::1:32946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.quantumacceleration.org"] [uri "/.env"] [unique_id "afB4pUKQSQmaPzZx_THlqQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 06:18:49
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:102:e516::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:102:e516::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 02:18:43.277151 2026] [security2:error] [pid 7507:tid 7507] [client 2a04:52c0:102:e516::1:57652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "danzadance.org"] [uri "/.env"] [unique_id "afBRQzmj-p4VHX5UaVoOSgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack