๐ฌ๐ง
openstrike.co.uk
2026-08-29 05:14:03
(2 days ago)
13 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php.swp HTTP/1.1
GET /.env.bak HTTP/1.1
Web App Attack
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-08-28 22:01:47
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-27.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 12:38:11
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.172.152.163 (163.152.172.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.172.152.163 (163.152.172.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:38:03.215748 2026] [security2:error] [pid 12079:tid 12079] [client 34.172.152.163:45634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kraftrealestate.kraftrentals.com"] [uri "/.env.prod"] [unique_id "apGBK3kjGEFhXtR529tj7AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-28 12:35:04
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฌ๐ง
WebNiraj
2026-08-28 12:33:32
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 34.172.152.163 (US/United States/163.152.172.34 ...
show more
(mod_security) mod_security (id:949110) triggered by 34.172.152.163 (US/United States/163.152.172.34.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-28 11:59:19
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.172.152.163 (163.152.172.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.172.152.163 (163.152.172.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:59:14.401968 2026] [security2:error] [pid 25424:tid 25424] [client 34.172.152.163:46160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tees4three.gamedayincentives.com"] [uri "/.env.bak"] [unique_id "apF4EjvmbeZKlyxh8QqAWQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 10:58:25
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.172.152.163 (163.152.172.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.172.152.163 (163.152.172.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 06:58:20.669321 2026] [security2:error] [pid 26850:tid 26850] [client 34.172.152.163:46688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sigi.biz"] [uri "/.env.dev"] [unique_id "apFpzCb56y13vMM8uvGNEgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mccsoft.io
2026-08-28 10:55:17
(3 days ago)
Web application attack / vulnerability scanning against our public nginx web server (TCP 80/443). So ...
show more
Web application attack / vulnerability scanning against our public nginx web server (TCP 80/443). Source matched a blocked-path security rule (jail nginx-444); server returned HTTP 444 (connection closed without response). TCP three-way handshake completed (full HTTP request received).
show less
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-28 10:37:50
(3 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-28 04:25:47
(3 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
Anonymous
2026-08-27 22:19:31
(3 days ago)
IKE Enforcement Violation.
Hacking
๐ฉ๐ช
Nightreaver
2026-08-27 22:16:34
(3 days ago)
34.172.152.163 - - [28/Aug/2026:00:16:33 0200] "GET /env HTTP/1.1" 404 437 "-" "crusader-worker/1.0 ...
show more
34.172.152.163 - - [28/Aug/2026:00:16:33 0200] "GET /env HTTP/1.1" 404 437 "-" "crusader-worker/1.0"
34.172.152.163 - - [28/Aug/2026:00:16:33 0200] "GET /.env.production HTTP/1.1" 404 437 "-" "crusader-worker/1.0"
34.172.152.163 - - [28/Aug/2026:00:16:33 0200] "GET /.env.old HTTP/1.1" 404 437 "-" "crusader-worker/1.0"
34.172.152.163 - - [28/Aug/2026:00:16:33 0200] "GET /_ignition/health-check HTTP/1.1" 404 437 "-" "crusader-worker/1.0"
34.172.152.163 - - [28/Aug/2026:00:16:33 0200] "GET /actuator/configprops HTTP/1.1" 404 437 "-" "crusader-worker/1.0"[...]
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-27 21:17:39
(3 days ago)
Multiple WAF Violations
Web App Attack
๐ง๐พ
lns.bz
2026-08-27 20:02:41
(3 days ago)
.env scanning [BY]
Web App Attack
๐ง๐ท
SOC Blue Team
2026-08-27 19:26:07
(3 days ago)
IPs get by Hunting on SIEM
Phishing
Web Spam
Port Scan
Hacking