๐ฌ๐ง
openstrike.co.uk
2026-09-02 05:13:57
(8 hours ago)
13 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php.bak HTTP/1.1
GET /.env.example HTTP/1. ...
show more
13 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php.bak HTTP/1.1
GET /.env.example HTTP/1.1
show less
Web App Attack
Hacking
Anonymous
2026-09-01 13:45:36
(23 hours ago)
Observed scanned 12 known-sensitive endpoint(s), e.g.: /, /%2eenv, /.ENV, /.env, /.env.bak, /.env.ol ...
show more
Observed scanned 12 known-sensitive endpoint(s), e.g.: /, /%2eenv, /.ENV, /.env, /.env.bak, /.env.old
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
AvonleaConsulting
2026-09-01 09:59:50
(1 day ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-09-01 09:41:21
(1 day ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.13.255.88 (88.255.13.34.bc.googleuser ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.13.255.88 (88.255.13.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.13.255.88 - - [01/Sep/2026:11:41:15 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusader-worker/1.0" "-" host=spacehosting.ovh
show less
Port Scan
๐ฉ๐ช
Viveronese
2026-09-01 09:31:18
(1 day ago)
HTTP vulnerability scanning
Web App Attack
Anonymous
2026-09-01 09:20:32
(1 day ago)
Observed scanned 1 known-sensitive endpoint(s), e.g.: /.env.production
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-01 08:33:11
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.13.255.88 (88.255.13.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.13.255.88 (88.255.13.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐จ๐ฆ
lakered
2026-09-01 08:20:19
(1 day ago)
Detectors: [NGINX, SURICATA] | Reasons: Nginx Honeypot: Sensitive configuration file search | Surica ...
show more
Detectors: [NGINX, SURICATA] | Reasons: Nginx Honeypot: Sensitive configuration file search | Suricata: Web Server attack | Evidence: High-Criminality-Signature (ja4:t13d1011h1 - Ratio:0.97), High-Criminality-Signature (ja4h:5cf9f33397d2cfab2c8ca2fd9e424522 - Ratio:0.97) | UA: crusader-worker/1.0 | TCP Fingerprint: Modern Linux (Kernel 3.x+) (Link:generic tunnel or VPN, Uptime:3326m)
show less
Hacking
Web App Attack
๐ง๐ท
Halux
2026-09-01 07:47:24
(1 day ago)
34.13.255.88 Probing protected path or service
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-09-01 07:33:10
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-01 05:19:58
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:43:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.13.255.88 (88.255.13.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.13.255.88 (88.255.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:43:25.837414 2026] [security2:error] [pid 4237:tid 4237] [client 34.13.255.88:37832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "andrewweigel.andrew.weigel.name"] [uri "/.env.dev"] [unique_id "apZJ3Q5PMz5YMSqh16Om1gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 03:10:03
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:03:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.13.255.88 (88.255.13.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.13.255.88 (88.255.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:03:09.158931 2026] [security2:error] [pid 24539:tid 24539] [client 34.13.255.88:60998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kayelynn.com"] [uri "/.env.bak"] [unique_id "apZAbXmuV4ejt0N2oiWNRgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:41:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.13.255.88 (88.255.13.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.13.255.88 (88.255.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:41:38.234042 2026] [security2:error] [pid 30520:tid 30520] [client 34.13.255.88:59222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.fundingangelinvestors.com"] [uri "/.env.bak"] [unique_id "apY7YhuYM5VJF53bFBAqeQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack