🇬🇧
openstrike.co.uk
2026-09-05 05:14:32
(17 hours ago)
222 attacks on env grabbing URLs, PHP URLs, password grabbing URLs, VC URLs, config grabbing URLs (t ...
show more
222 attacks on env grabbing URLs, PHP URLs, password grabbing URLs, VC URLs, config grabbing URLs (type 2):
GET /app/.env.local HTTP/1.1
GET /pi.php HTTP/1.1
GET /root/.aws/credentials HTTP/1.1
GET /.git/config HTTP/1.1
GET /application_default_credentials.json HTTP/1.1
show less
Hacking
Web App Attack
🇳🇱
e.fierstra
2026-09-04 12:45:56
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:14:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.129.68 (68.129.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.129.68 (68.129.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:14:07.560771 2026] [security2:error] [pid 15301:tid 15301] [client 34.104.129.68:61212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "p-co.com"] [uri "/@fs/.env"] [unique_id "apq2D-x33VkrXC6l5M83bgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-04 12:05:07
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
masterguru
2026-09-04 11:42:28
(1 day ago)
Restricted File Access Attempt. Matched phrase "proc/self" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
Anonymous
2026-09-04 11:35:17
(1 day ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
🇺🇸
TPI-Abuse
2026-09-04 11:31:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.129.68 (68.129.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.129.68 (68.129.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:30:58.459149 2026] [security2:error] [pid 26105:tid 26105] [client 34.104.129.68:40436] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.myouenji.org"] [uri "/@fs/app/.env"] [unique_id "apqr8uzSsIYMYKjWZvVBRQAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:39:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.129.68 (68.129.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.129.68 (68.129.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:39:15.228146 2026] [security2:error] [pid 694:tid 694] [client 34.104.129.68:26480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thehappywillow.com"] [uri "/@fs/.env"] [unique_id "apqRw7n0L-G_TkvDPeq66gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-04 08:51:10
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:44:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.129.68 (68.129.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.129.68 (68.129.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:44:32.217243 2026] [security2:error] [pid 3200:tid 3200] [client 34.104.129.68:34166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mhebert.com"] [uri "/@fs/app/.env"] [unique_id "app24DeHX2a3aaonZocGZwAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:26:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.129.68 (68.129.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.129.68 (68.129.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:26:34.306529 2026] [security2:error] [pid 9713:tid 9713] [client 34.104.129.68:31568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.hatefmusic.com"] [uri "/@fs/.env"] [unique_id "appyqj55sSuF7xZ8Zj8duAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇿
Antinson
2026-09-04 07:13:35
(1 day ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇩🇪
maxpower
2026-09-04 07:06:37
(1 day ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.104.129.68 (JP/Japan/68.129.104.34.bc ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.104.129.68 (JP/Japan/68.129.104.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.104.129.68 - - [04/Sep/2026:09:06:34 +0200] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.1" 200 11943 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:143.3) Gecko/20100101 Firefox/143.3; compatible; Google-Extended/1.0; +http://www.google.com/bot.html" "-" host=www.insegnesolution.emmeccisolution.it
show less
Port Scan
🇩🇪
grassau.com
2026-09-04 06:51:22
(1 day ago)
*Port Scan* detected from 34.104.129.68 (JP/Japan/Tokyo/Tokyo/68.129.104.34.bc.googleusercontent.com ...
show more
*Port Scan* detected from 34.104.129.68 (JP/Japan/Tokyo/Tokyo/68.129.104.34.bc.googleusercontent.com).
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-04 06:26:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.129.68 (68.129.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.129.68 (68.129.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:26:34.500655 2026] [security2:error] [pid 8828:tid 8828] [client 34.104.129.68:63864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.billfried.net"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "appkmsfmD3Botu7X3veo8wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack