🇬🇧
openstrike.co.uk
2026-09-05 05:13:21
(3 hours ago)
13 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php.swp HTTP/1.1
GET /.env.save HTTP/1.1
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 15:20:20
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.105.244.86 (86.244.105.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.105.244.86 (86.244.105.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:20:15.866999 2026] [security2:error] [pid 5666:tid 5666] [client 34.105.244.86:42302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.bencramerinc.com"] [uri "/.env.production"] [unique_id "aprhr2RYKO6QrcFylY5p9wAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 14:41:15
(18 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:08:24
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.105.244.86 (86.244.105.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.105.244.86 (86.244.105.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:08:18.013162 2026] [security2:error] [pid 24161:tid 24161] [client 34.105.244.86:33464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jcrluthier.com"] [uri "/.env.save"] [unique_id "aprQ0oKXC7xFEsVxgXpzQwAAAHI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
MusicLibrary
2026-09-04 13:46:12
(19 hours ago)
Attempted access to sensitive configuration files (.env, .git, etc.)
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 13:21:36
(19 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 12:35:30
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.105.244.86 (86.244.105.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.105.244.86 (86.244.105.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:35:25.428567 2026] [security2:error] [pid 23002:tid 23022] [client 34.105.244.86:59362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ahsdistance.org"] [uri "/wp-config.php.swp"] [unique_id "apq7DcUEohzoiyy4PKURAwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:43:51
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.105.244.86 (86.244.105.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.105.244.86 (86.244.105.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:43:48.057312 2026] [security2:error] [pid 8356:tid 8356] [client 34.105.244.86:53656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.brinkworthmodels.com"] [uri "/.env.bak"] [unique_id "apqu9InA5-UUy_QRQxRohwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:04:04
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.105.244.86 (86.244.105.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.105.244.86 (86.244.105.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:03:57.044742 2026] [security2:error] [pid 30214:tid 30214] [client 34.105.244.86:59414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hillconsultants.alhill.com"] [uri "/.env.old"] [unique_id "apqlnbDCiHL7h8RECKC2yAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
larse99
2026-09-04 10:59:41
(22 hours ago)
Detected Scanning / Hacking activity
Port Scan
Hacking
🇬🇧
SafBH
2026-09-04 10:19:11
(22 hours ago)
CrowdSec Decision: Attempted to access a forbidden path / Vulnerability probing: "[/.env]"
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:15:01
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.105.244.86 (86.244.105.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.105.244.86 (86.244.105.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:14:54.658075 2026] [security2:error] [pid 4300:tid 4300] [client 34.105.244.86:46414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jacinc.net"] [uri "/wp-config.php~"] [unique_id "apqaHuL48susQVujGYB_hAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:56:17
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.105.244.86 (86.244.105.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.105.244.86 (86.244.105.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:56:12.107870 2026] [security2:error] [pid 13617:tid 13617] [client 34.105.244.86:40170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ohioprocleaners.com"] [uri "/wp-config.php~"] [unique_id "apqVvIqWy6MWmIaWbsqIxAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
thedreamer.nl
2026-09-04 09:35:32
(23 hours ago)
34.105.244.86 - - [04/Sep/2026:11:33:56 +0200] "GET /.env.local HTTP/1.1" 404 14 "-" "crusader-worke ...
show more
34.105.244.86 - - [04/Sep/2026:11:33:56 +0200] "GET /.env.local HTTP/1.1" 404 14 "-" "crusader-worker/1.0" "GB" "City of London" "51.51640" "-0.09300"
34.105.244.86 - - [04/Sep/2026:11:33:56 +0200] "GET /.env.old HTTP/1.1" 404 14 "-" "crusader-worker/1.0" "GB" "City of London" "51.51640" "-0.09300"
34.105.244.86 - - [04/Sep/2026:11:33:56 +0200] "GET /.env.prod HTTP/1.1" 404 14 "-" "crusader-worker/1.0" "GB" "City of London" "51.51640" "-0.09300"
34.105.244.86 - - [04/Sep/2026:11:33:56 +0200] "GET /.env HTTP/1.1" 404 14 "-" "crusader-worker/1.0" "GB" "City of London" "51.51640" "-0.09300"
...
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-04 09:19:21
(23 hours ago)
csagent: score 20.0: wp-config backup grab x1, secrets grab x1; 1 domain(s) in 0s
Web App Attack