🇬🇧
openstrike.co.uk
2026-09-10 05:13:51
(20 hours ago)
161 attacks on PHP URLs, VC URLs, env grabbing URLs:
GET /smtp/phpinfo.php HTTP/1.1
GET /.git/config ...
show more
161 attacks on PHP URLs, VC URLs, env grabbing URLs:
GET /smtp/phpinfo.php HTTP/1.1
GET /.git/config HTTP/1.1
GET /bulk/.env HTTP/1.1
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-10 05:09:45
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.163.25.208 (208.25.163.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.163.25.208 (208.25.163.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 01:09:39.547780 2026] [security2:error] [pid 32252:tid 32252] [client 34.163.25.208:57340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "weddingcakenapkins.com"] [uri "/.git/config"] [unique_id "aqI7kwRNZOlFojqZcZxktgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 04:18:09
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.163.25.208 (208.25.163.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.163.25.208 (208.25.163.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 00:18:00.626562 2026] [security2:error] [pid 4694:tid 4694] [client 34.163.25.208:57992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "timetemple.org"] [uri "/.git/config"] [unique_id "aqIvePV_xFZYo7BgTJ8lOgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-10 00:06:36
(1 day ago)
Try to access /.git/config
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 23:55:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.163.25.208 (208.25.163.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.163.25.208 (208.25.163.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 19:55:33.623644 2026] [security2:error] [pid 7622:tid 7622] [client 34.163.25.208:49216] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "skanksex.com"] [uri "/.git/config"] [unique_id "aqHx9XG9uaK7EUzDs5FCdwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-09 23:30:16
(1 day ago)
4.025 requests with url.path *.env
509 requests with url.path *phpinfo.php
Brute-Force
Bad Web Bot
🇩🇪
Bedios GmbH
2026-09-09 22:09:38
(1 day ago)
Login credentials theft attempt
Hacking
🇩🇪
LRob
2026-09-09 20:17:50
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-09-09 20:17 UTC
show less
Hacking
Web App Attack
🇦🇺
Klaverstyn
2026-09-09 17:57:25
(1 day ago)
Repeated 403 Forbidden responses
Web App Attack
🇩🇪
kkw
2026-09-09 17:16:01
(1 day ago)
[REDACTED] 34.163.25.208 - - [09/Sep/2026:19:16:00 +0200] "GET /.git/config HTTP/1.1" 404 557 "-" "M ...
show more
[REDACTED] 34.163.25.208 - - [09/Sep/2026:19:16:00 +0200] "GET /.git/config HTTP/1.1" 404 557 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-09-09 12:20:09
(1 day ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-09 12:09:54
(1 day ago)
34.163.25.208 - - [09/Sep/2026:14:09:49 +0200] "GET /.env.development HTTP/1.1" 404 29101 "-" "Mozil ...
show more
34.163.25.208 - - [09/Sep/2026:14:09:49 +0200] "GET /.env.development HTTP/1.1" 404 29101 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.163.25.208 - - [09/Sep/2026:14:09:50 +0200] "GET /.env.test HTTP/1.1" 404 29101 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.163.25.208 - - [09/Sep/2026:14:09:50 +0200] "GET /.env.remote HTTP/1.1" 404 29101 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.163.25.208 - - [09/Sep/2026:14:09:50 +0200] "GET /.env.bak HTTP/1.1" 404 29101 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.163.25.208 - - [09/Sep/2026:14:09:50 +0200] "GET /.env.backup HTTP/1.1" 404 29101 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML,
show less
Web App Attack
Hacking
🇮🇹
VHosting
2026-09-09 09:55:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-09 06:56:35
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking