🇬🇧
openstrike.co.uk
2026-09-06 05:13:13
(14 hours ago)
13 attacks on env grabbing URLs, PHP URLs:
GET /.env.example HTTP/1.1
GET /wp-config.php.swp HTTP/1. ...
show more
13 attacks on env grabbing URLs, PHP URLs:
GET /.env.example HTTP/1.1
GET /wp-config.php.swp HTTP/1.1
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:49:22
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.182.131 (131.182.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.182.131 (131.182.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:49:13.713406 2026] [security2:error] [pid 32235:tid 32235] [client 34.104.182.131:51672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.whaletailbikini.com"] [uri "/.env.backup"] [unique_id "apziuQ6dCl87EFa0QT41RgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 03:40:18
(15 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
big-cloud.nl
2026-09-06 03:39:51
(15 hours ago)
Try to access /.env
Web App Attack
🇫🇷
✨
2026-09-06 03:19:10
(16 hours ago)
Domain : desiredimage.co.uk
Rule : env
2026-09-06 03:17:10 ***hidden-privacy*** GET /.env - 443 - 34 ...
show more
Domain : desiredimage.co.uk
Rule : env
2026-09-06 03:17:10 ***hidden-privacy*** GET /.env - 443 - 34.104.182.131 HTTP/1.1 crusader-worker/1.0 - desiredimage.co.uk 404 0 2 1564 94 249 - -
show less
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 03:19:07
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.182.131 (131.182.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.182.131 (131.182.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:19:03.727371 2026] [security2:error] [pid 11165:tid 11173] [client 34.104.182.131:42738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "delapiazza.piazza9.com"] [uri "/wp-config.php.bak"] [unique_id "apzbp_1pRt8N7QnZBIkcZQAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:00:40
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.182.131 (131.182.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.182.131 (131.182.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:00:31.624849 2026] [security2:error] [pid 3661543:tid 3661543] [client 34.104.182.131:46296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.sdwsk8.com"] [uri "/wp-config.php.swp"] [unique_id "apzXT5L-jZPPZIbx1CHKLAAAAGQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:42:27
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.182.131 (131.182.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.182.131 (131.182.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:42:20.670009 2026] [security2:error] [pid 14109:tid 14109] [client 34.104.182.131:47466] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agrizel.com"] [uri "/.env.production"] [unique_id "apzTDKtu_9S1bcJIZF7wFAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-06 02:36:49
(16 hours ago)
URL Probing: /wp-config.php.bak
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 01:37:40
(17 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 00:54:36
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.182.131 (131.182.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.182.131 (131.182.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:54:31.846866 2026] [security2:error] [pid 3505775:tid 3505867] [client 34.104.182.131:39456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "evan-hotel.com"] [uri "/.env.old"] [unique_id "apy5x78ERl7gWgWoAPLocAAAAYk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
ALPHANET
2026-09-06 00:54:25
(18 hours ago)
web exploits
Hacking
Exploited Host
Web App Attack
🇫🇷
Octopuce
2026-09-06 00:38:44
(18 hours ago)
Aggressive web search of vulnerable pages: /.env.local /.env /backup.tgz /backup.tar.gz /web.zip /db ...
show more
Aggressive web search of vulnerable pages: /.env.local /.env /backup.tgz /backup.tar.gz /web.zip /db.sql /backup.zip ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:35:09
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.182.131 (131.182.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.182.131 (131.182.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:35:01.479876 2026] [security2:error] [pid 16575:tid 16575] [client 34.104.182.131:41574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bobrossi.gregorii.com"] [uri "/.env.prod"] [unique_id "apy1NVI9YUHdRzo6C_nSngAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-06 00:20:17
(19 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack