🇬🇧
openstrike.co.uk
2026-09-05 05:13:30
(17 hours ago)
111 attacks on VC URLs, password grabbing URLs, config grabbing URLs (type 2), env grabbing URLs, PH ...
show more
111 attacks on VC URLs, password grabbing URLs, config grabbing URLs (type 2), env grabbing URLs, PHP URLs:
GET /.git/HEAD HTTP/1.1
GET /root/.aws/credentials HTTP/1.1
GET /config/openai.json HTTP/1.1
GET /dev/.env HTTP/1.1
GET /pi.php HTTP/1.1
show less
Hacking
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 17:11:23
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇨🇭
4server
2026-09-04 15:52:48
(1 day ago)
[FriSep0417:52:44.7110112026][security2:error][pid1266190:tid1266557][client34.142.158.148:0]ModSecu ...
show more
[FriSep0417:52:44.7110112026][security2:error][pid1266190:tid1266557][client34.142.158.148:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"viaggi-marocco-ticino.ch\"][uri\"/@fs/..%2f..%2f..%2f..%2f..%2fapp/.env\"][unique_id\"aprpTACWAO1v3aZmGlnKDAAAARY\"]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:54:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.142.158.148 (148.158.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.158.148 (148.158.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:53:55.331965 2026] [security2:error] [pid 23004:tid 23121] [client 34.142.158.148:30124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.myrtlebeachdiet.com"] [uri "/@fs/src/.env"] [unique_id "aprbg84Kl8MzvCwEZxJ6cgAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:01:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.142.158.148 (148.158.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.158.148 (148.158.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:01:01.499421 2026] [security2:error] [pid 706008:tid 706008] [client 34.142.158.148:4890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.davidfiss.com"] [uri "/@fs/../.env"] [unique_id "aprBDZi-hHS0bwxkVVQYUAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 12:56:48
(1 day ago)
Blocked by ModSec and CSF
Port Scan
🇺🇸
WellSpring
2026-09-04 12:55:00
(1 day ago)
good bot honeypot on 509.today/@fs/home/ubuntu/.env — WellSpr.ing/NetSentinel civic-AI security laye ...
show more
good bot honeypot on 509.today/@fs/home/ubuntu/.env — WellSpr.ing/NetSentinel civic-AI security layer
show less
Bad Web Bot
🇧🇪
taivas.nl
2026-09-04 12:32:12
(1 day ago)
Site scraper
Web App Attack
🇦🇺
rubixstudios
2026-09-04 11:42:02
(1 day ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
Anonymous
2026-09-04 10:55:01
(1 day ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:53:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.142.158.148 (148.158.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.158.148 (148.158.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:53:34.769689 2026] [security2:error] [pid 28411:tid 28411] [client 34.142.158.148:20012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.vgforever.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "apqjLko5Gb6eVvPQqniiSAAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:32:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.142.158.148 (148.158.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.158.148 (148.158.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:32:03.930370 2026] [security2:error] [pid 10258:tid 10258] [client 34.142.158.148:12588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.britanniapilates.com"] [uri "/@fs/src/.env"] [unique_id "apqeI-N_PORKWHU5jaMKLgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:01:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.142.158.148 (148.158.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.158.148 (148.158.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:01:52.203094 2026] [security2:error] [pid 13061:tid 13061] [client 34.142.158.148:62234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.webersource.com"] [uri "/@fs/root/.env"] [unique_id "apqXEC73blWMBFXjj8G12gAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dwmp
2026-09-04 09:56:20
(1 day ago)
Url probing: /@fs/.env.production
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:38:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.142.158.148 (148.158.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.158.148 (148.158.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:37:54.438135 2026] [security2:error] [pid 3588:tid 3588] [client 34.142.158.148:8156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "register-yacht-gibraltar.com"] [uri "/@fs/app/.env"] [unique_id "apqRcgp6BRwivvjAr2vQpQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack