🇬🇧
openstrike.co.uk
2026-09-05 05:14:26
(20 hours ago)
13 attacks on env grabbing URLs, PHP URLs:
GET /.env HTTP/1.1
GET /wp-config.php.bak HTTP/1.1
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:21:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.158.20.30 (30.20.158.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.20.30 (30.20.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:21:37.131206 2026] [security2:error] [pid 16101:tid 16101] [client 34.158.20.30:59862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.wisdomwfm.com"] [uri "/wp-config.php.swp"] [unique_id "apriAejjKkwm9n1Nvuf3PQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
oh.mg
2026-09-04 14:37:20
(1 day ago)
[Fri Sep 04 16:37:19.626396 2026] [security2:error] [pid 3276298:tid 3276313] [client 34.158.20.30:3 ...
show more
[Fri Sep 04 16:37:19.626396 2026] [security2:error] [pid 3276298:tid 3276313] [client 34.158.20.30:39960] [client 34.158.20.30] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "deadinternet.ohno.es"] [uri "/.env.old"] [unique_id "aprXn4gJmkV_A-NkLRm4GAAAAM0"]
[Fri Sep 04 16:37:19.627011 2026] [security2:error] [pid 3249679:tid 3249698] [client 34.158.20.30:39970] [client 34.158.20.30] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"
...
show less
Web App Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 14:08:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.158.20.30 (30.20.158.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.20.30 (30.20.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:08:32.577410 2026] [security2:error] [pid 22797:tid 22797] [client 34.158.20.30:56180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ifilemuseum.com"] [uri "/.env.backup"] [unique_id "aprQ4Pn3BHpg32fxd8vTwQAAAGo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
yitzhaq
2026-09-04 13:39:31
(1 day ago)
34.158.20.30 - - [04/Sep/2026:15:39:27 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 103621 "-" "crus ...
show more
34.158.20.30 - - [04/Sep/2026:15:39:27 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 103621 "-" "crusader-worker/1.0"
34.158.20.30 - - [04/Sep/2026:15:39:27 +0200] "GET /wp-config.php~ HTTP/1.1" 404 103621 "-" "crusader-worker/1.0"
34.158.20.30 - - [04/Sep/2026:15:39:27 +0200] "GET /_ignition/health-check HTTP/1.1" 404 103622 "-" "crusader-worker/1.0"
34.158.20.30 - - [04/Sep/2026:15:39:27 +0200] "GET /.env HTTP/1.1" 404 95995 "-" "crusader-worker/1.0"
34.158.20.30 - - [04/Sep/2026:15:39:27 +0200] "GET /env HTTP/1.1" 404 103622 "-" "crusader-worker/1.0"
34.158.20.30 - - [04/Sep/2026:15:39:27 +0200] "GET /.env.production HTTP/1.1" 404 103622 "-" "crusader-worker/1.0"
34.158.20.30 - - [04/Sep/2026:15:39:27 +0200] "GET /.env.example HTTP/1.1" 404 103623 "-" "crusader-worker/1.0"
34.158.20.30 - - [04/Sep/2026:15:39:27 +0200] "GET /.env.prod HTTP/1.1" 404 103637 "-" "crusader-worker/1.0"
34.158.20.30 - - [04/Sep/2026:15:39:27 +0200] "GET /.env.backup HTTP/1.1" 404 95994 "-" "crusader-worker/
show less
Web App Attack
Brute-Force
🇧🇷
noconex
2026-09-04 13:02:19
(1 day ago)
Wazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SERVER Tilde in URI - potential .php ...
show more
Wazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability) 34.158.20.30
show less
Port Scan
Brute-Force
SSH
🇫🇷
UnixPrime
2026-09-04 12:55:04
(1 day ago)
34.158.20.30 - - [04/Sep/2026:14:55:02 +0200] "GET /.env.local HTTP/1.1" 404 14026 "-" "crusader-wor ...
show more
34.158.20.30 - - [04/Sep/2026:14:55:02 +0200] "GET /.env.local HTTP/1.1" 404 14026 "-" "crusader-worker/1.0"
34.158.20.30 - - [04/Sep/2026:14:55:03 +0200] "GET /.env HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 11:24:20
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-04 10:51:13
(1 day ago)
[04/Sep/2026:13:51:13 +0300] -- 34.158.20.30 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-co ...
show more
[04/Sep/2026:13:51:13 +0300] -- 34.158.20.30 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-config.php.swp HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 10:25:43
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
Dominik Lysiak
2026-09-04 10:01:16
(1 day ago)
34.158.20.30 - - [04/Sep/2026:12:01:16 +0200] "GET /.env.local HTTP/1.1" 404 146 "-" "crusader-worke ...
show more
34.158.20.30 - - [04/Sep/2026:12:01:16 +0200] "GET /.env.local HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.158.20.30 - - [04/Sep/2026:12:01:16 +0200] "GET /.env.prod HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.158.20.30 - - [04/Sep/2026:12:01:16 +0200] "GET /.env.dev HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:10:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.158.20.30 (30.20.158.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.20.30 (30.20.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:10:08.492760 2026] [security2:error] [pid 28300:tid 28300] [client 34.158.20.30:41618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "legalnexusbali.com"] [uri "/wp-config.php~"] [unique_id "apqK8Jt6M7ztXiog7rE7YgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:40:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.158.20.30 (30.20.158.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.20.30 (30.20.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:39:54.542705 2026] [security2:error] [pid 24221:tid 24221] [client 34.158.20.30:37068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "register-yacht-belgium.com"] [uri "/.env.example"] [unique_id "apqD2u-f8lZrjuzxM-UOegAAAGg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-04 08:29:21
(1 day ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.158.20.30 (CH/Switzerland/30.20.158.3 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.158.20.30 (CH/Switzerland/30.20.158.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.158.20.30 - - [04/Sep/2026:10:29:19 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusader-worker/1.0" "-" host=mail.conapipescara.it
show less
Port Scan
🇩🇪
4server
2026-09-04 08:29:18
(1 day ago)
[FriSep0410:29:13.6142382026][security2:error][pid4082805:tid4082813][client34.158.20.30:0]ModSecuri ...
show more
[FriSep0410:29:13.6142382026][security2:error][pid4082805:tid4082813][client34.158.20.30:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"mail.danielasilvia.ch\"][uri\"/.env.bak\"][unique_id\"apqBWbEBb8SjkyB5TnIrpgAAAUU\"]
show less
Port Scan
Brute-Force
Web App Attack