🇬🇧
openstrike.co.uk
2026-09-07 05:13:44
(12 hours ago)
311 attacks on VC URLs, config grabbing URLs (type 2), directory traversals, password grabbing URLs, ...
show more
311 attacks on VC URLs, config grabbing URLs (type 2), directory traversals, password grabbing URLs, PHP URLs, env grabbing URLs (type 2), env grabbing URLs:
GET /.git/HEAD HTTP/1.1
GET /src/amplifyconfiguration.json HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/1.1
GET /app_dev.php/_profiler HTTP/1.1
GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1
GET /staging/.env HTTP/1.1
show less
Hacking
Web App Attack
🇧🇾
lns.bz
2026-09-07 00:32:57
(16 hours ago)
.env scanning [BY]
Web App Attack
Anonymous
2026-09-07 00:12:57
(17 hours ago)
PSCSERV WPSCAN 34.173.125.249
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 23:04:33
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.173.125.249 (249.125.173.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.173.125.249 (249.125.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 19:04:29.028060 2026] [security2:error] [pid 22890:tid 22890] [client 34.173.125.249:54190] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.gelatouno.com.salernospizza.com|F|2"] [data ".gelatouno.com.salernospizza.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.gelatouno.com.salernospizza.com"] [uri "/z9x8c7v6b5-debug-trigger-www.gelatouno.com.salernospizza.com"] [unique_id "ap3xfcfgFLDE-9r8NkiviwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
thieuleu
2026-09-06 22:30:41
(18 hours ago)
Unauthorized connection attempt blocked by firewall policy. Web application hardening active.
Brute-Force
Exploited Host
🇨🇭
zynex
2026-09-06 21:06:56
(20 hours ago)
URL Probing: /.env
Web App Attack
🇳🇱
Site.eu
2026-09-06 21:05:27
(20 hours ago)
Excessive multi-domain requests
Brute-Force
🇩🇪
raph
2026-09-06 20:34:09
(20 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 20:05:17
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.173.125.249 (249.125.173.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.125.249 (249.125.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:05:11.640691 2026] [security2:error] [pid 1413:tid 1413] [client 34.173.125.249:43480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.globalaccessau.com.salsberggroup.com"] [uri "/public../.env"] [unique_id "ap3Hd64X7fTXfn3Tr5JSsgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 19:56:44
(21 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 19:35:40
(21 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.173.125.249 (249.125.173.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 34.173.125.249 (249.125.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:35:32.783400 2026] [security2:error] [pid 4503:tid 4503] [client 34.173.125.249:0] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||gibitdigital.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "gibitdigital.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "ap3AhDSTViXE5IMPbe6srgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 18:40:18
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.173.125.249 (249.125.173.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.125.249 (249.125.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 14:40:14.191507 2026] [security2:error] [pid 570523:tid 570523] [client 34.173.125.249:56624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nodepot.com"] [uri "/.env"] [unique_id "ap2zjuDhh1NkQRYx_XJLYQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-09-06 18:18:01
(22 hours ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
🇺🇸
mnsf
2026-09-06 18:05:12
(23 hours ago)
Scanning/Probing (19)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 17:13:33
(1 day ago)
(mod_security) mod_security (id:210580) triggered by 34.173.125.249 (249.125.173.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 34.173.125.249 (249.125.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 13:13:29.433386 2026] [security2:error] [pid 24826:tid 24826] [client 34.173.125.249:54342] ModSecurity: Access denied with code 403 (phase 2). Matched phrase ".ssh/id_rsa" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.free-rein.us.freerein.info|F|2"] [data "Matched Data: .ssh/id_rsa found within ARGS:filename: file:/root/.ssh/id_rsa"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.free-rein.us.freerein.info"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "ap2fObMXD9kW_VYvpGdW4wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack