๐ฌ๐ง
openstrike.co.uk
2026-08-27 05:14:13
(2 days ago)
216 attacks on env grabbing URLs, directory traversals, VC URLs, password grabbing URLs, site downlo ...
show more
216 attacks on env grabbing URLs, directory traversals, VC URLs, password grabbing URLs, site downloads, PHP URLs, config grabbing URLs (type 2):
GET /aws/.env.production HTTP/1.1
GET /..%252F..%252F..%252F..%252F..%252Fproc/self/environ HTTP/1.1
GET /.git/config HTTP/1.1
GET /.vscode/sftp.json HTTP/1.1
GET /backup.sql HTTP/1.1
GET /info.php HTTP/1.1
GET /appspec.yml HTTP/1.1
show less
Hacking
Web App Attack
๐ฎ๐น
paoloartone
2026-08-27 05:00:22
(2 days ago)
Reverse proxy TCO: 590 richieste malevole bloccate (scan/exploit/brute-force WordPress) il 26/08/202 ...
show more
Reverse proxy TCO: 590 richieste malevole bloccate (scan/exploit/brute-force WordPress) il 26/08/2026.
show less
Web App Attack
Hacking
Port Scan
๐ฉ๐ช
grassau.com
2026-08-26 18:56:34
(2 days ago)
*Port Scan* detected from 34.125.238.85 (US/United States/Nevada/Las Vegas/85.238.125.34.bc.googleus ...
show more
*Port Scan* detected from 34.125.238.85 (US/United States/Nevada/Las Vegas/85.238.125.34.bc.googleusercontent.com).
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-26 18:17:47
(2 days ago)
(mod_security) mod_security (id:210580) triggered by 34.125.238.85 (85.238.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 34.125.238.85 (85.238.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 14:17:41.070733 2026] [security2:error] [pid 29424:tid 29424] [client 34.125.238.85:36886] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:url. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||wevfc.org|F|2"] [data "Matched Data: proc/self/environ found within ARGS:url: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "wevfc.org"] [uri "/read"] [unique_id "ao8txSmrsUBOq9B3gM1aagAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 17:20:13
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.238.85 (85.238.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.238.85 (85.238.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 13:20:09.146378 2026] [security2:error] [pid 2295:tid 2316] [client 34.125.238.85:22234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.woadwellness.com"] [uri "/static../.env"] [unique_id "ao8gSU2yrhsZ09cMtpGyPAAAAVM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 16:14:06
(2 days ago)
(mod_security) mod_security (id:211190) triggered by 34.125.238.85 (85.238.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:211190) triggered by 34.125.238.85 (85.238.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:14:00.057066 2026] [security2:error] [pid 8379:tid 8379] [client 34.125.238.85:24630] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||riverflow.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /download?file=../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "riverflow.com"] [uri "/download"] [unique_id "ao8QyMep6uLYHE3wvH6zKwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 15:10:31
(2 days ago)
34.125.238.85 - - [26/Aug/2026:17:10:30 +0200] "GET /static../.env HTTP/1.1" 403 124 "-" "Mozilla/5. ...
show more
34.125.238.85 - - [26/Aug/2026:17:10:30 +0200] "GET /static../.env HTTP/1.1" 403 124 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user"
34.125.238.85 - - [26/Aug/2026:17:10:30 +0200] "GET /media../.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 12; Pixel 6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.2999.76 Mobile Safari/537.36; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot"
34.125.238.85 - - [26/Aug/2026:17:10:30 +0200] "GET /download?file=../../../../etc/passwd HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user) Chrome/134.0.1764.210 Safari/537.36"
34.125.238.85 - - [26/Aug/2026:17:10:30 +0200] "GET /.env.local HTTP/1.1" 403 124 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; LinkedInBot/1.0; +http://www.linkedin.com)"
34.
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 13:47:02
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.238.85 (85.238.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.238.85 (85.238.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 09:46:55.450774 2026] [security2:error] [pid 51450:tid 51482] [client 34.125.238.85:47192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marinkovich.us"] [uri "/static../.env"] [unique_id "ao7uTw5IujEbOVUlEFqMcQAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-08-26 13:11:03
(2 days ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
๐ซ๐ท
masterguru
2026-08-26 12:48:22
(2 days ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 34.125.238.85 (US/United States/85.238.125.34. ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 34.125.238.85 (US/United States/85.238.125.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
mnsf
2026-08-26 12:05:10
(2 days ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-26 12:01:51
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
Site.eu
2026-08-26 11:36:00
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
grassau.com
2026-08-26 10:39:53
(2 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.125.238.85 (US/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.125.238.85 (US/United States/Nevada/Las Vegas/85.238.125.34.bc.googleusercontent.com)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-26 09:38:55
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.238.85 (85.238.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.238.85 (85.238.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 05:38:47.240844 2026] [security2:error] [pid 22209:tid 22209] [client 34.125.238.85:8232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "perlcreativedesign.com"] [uri "/static../.env"] [unique_id "ao60J93l9PQNvBvXtsQNswAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack