🇬🇧
openstrike.co.uk
2026-09-05 05:13:25
(14 minutes ago)
479 attacks on PHP URLs, env grabbing URLs, config grabbing URLs (type 2), directory traversals, sit ...
show more
479 attacks on PHP URLs, env grabbing URLs, config grabbing URLs (type 2), directory traversals, site downloads, password grabbing URLs, VC URLs:
GET /phpinfo.php HTTP/1.1
GET /static/.env HTTP/1.1
GET /config/environment.json HTTP/1.1
GET /..;/..;/.azure/credentials HTTP/1.1
GET /backup.sql HTTP/1.1
GET /_next/../.aws/credentials HTTP/1.1
GET /.git/HEAD HTTP/1.1
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 13:43:40
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.232.223 (223.232.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.232.223 (223.232.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:43:33.815933 2026] [security2:error] [pid 31770:tid 31770] [client 34.138.232.223:43998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.paintedoverwhite.com"] [uri "/@fs/root/.env"] [unique_id "aprLBRV275gruLhHlqyjGgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-04 13:16:48
(16 hours ago)
Automatically blocked due to distributed attack
Hacking
🇲🇾
Rizzy
2026-09-04 12:02:36
(17 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
dot.mg
2026-09-04 11:42:02
(17 hours ago)
Bad behaviour
Web Spam
🇳🇱
e.fierstra
2026-09-04 11:32:49
(17 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:50:10
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.232.223 (223.232.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.232.223 (223.232.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:49:59.450184 2026] [security2:error] [pid 3314:tid 3314] [client 34.138.232.223:44196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.asian-aerospace.christinepeat.com"] [uri "/@fs/src/.env"] [unique_id "apqUR_h6Wo6bAHKBKg-oswAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 09:35:04
(19 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇷🇺
DZBOT
2026-09-04 09:01:52
(20 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:43:22
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.232.223 (223.232.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.232.223 (223.232.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:43:14.045333 2026] [security2:error] [pid 18819:tid 18819] [client 34.138.232.223:2920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.theseventhcongregationofladderdayvixens.org"] [uri "/@fs/root/.env"] [unique_id "app2kr9zx1yCT_C2XQ2JhwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
clauss
2026-09-04 07:31:35
(21 hours ago)
34.138.232.223 - - [04/Sep/2026:10:31:35 +0300] "GET /@fs/root/.anthropic/config.json?raw?? HTTP/2.0 ...
show more
34.138.232.223 - - [04/Sep/2026:10:31:35 +0300] "GET /@fs/root/.anthropic/config.json?raw?? HTTP/2.0" 404 17149 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:133.10) Gecko/20100101 Firefox/133.10; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot"
34.138.232.223 - - [04/Sep/2026:10:31:35 +0300] "GET /@fs/home/ubuntu/.anthropic/config.json?raw?? HTTP/2.0" 404 17144 "-" "Mozilla/5.0 (Linux; Android 12; Pixel 6) AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot) Chrome/120.0.8340.165 Mobile Safari/537.36"
...
show less
Web App Attack
🇩🇪
maxpower
2026-09-04 06:55:51
(22 hours ago)
(junkbot) REGOLA 8 - Junk Bot Blocked 34.138.232.223 (US/United States/223.232.138.34.bc.googleuserc ...
show more
(junkbot) REGOLA 8 - Junk Bot Blocked 34.138.232.223 (US/United States/223.232.138.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.138.232.223 - - [04/Sep/2026:08:55:49 +0200] "GET /@fs/etc/passwd?raw?? HTTP/1.1" 200 11912 "-" "Mozilla/5.0 (compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "-" host=checkall.cloud
show less
Port Scan
🇫🇷
MatStef132
2026-09-04 06:33:41
(22 hours ago)
MatShield L7: blocked on mathost.eu (suspicious behaviour)
DDoS Attack
🇺🇸
TPI-Abuse
2026-09-04 05:47:49
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.232.223 (223.232.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.232.223 (223.232.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:47:42.689760 2026] [security2:error] [pid 2851:tid 2851] [client 34.138.232.223:34900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brianmindy.com"] [uri "/@fs/.env"] [unique_id "appbfntcKUjwahxFVBjiJwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:32:49
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.232.223 (223.232.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.232.223 (223.232.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:32:42.997811 2026] [security2:error] [pid 27255:tid 27255] [client 34.138.232.223:49558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theburiednews.com"] [uri "/@fs/src/.env"] [unique_id "appX-rG5lEur4WRSoPc84AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack