🇬🇧
openstrike.co.uk
2026-09-05 05:13:31
(10 hours ago)
13 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php.swp HTTP/1.1
GET /.env.backup HTTP/1.1
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 15:20:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.19.222.189 (189.222.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.222.189 (189.222.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:20:04.476988 2026] [security2:error] [pid 5550:tid 5550] [client 34.19.222.189:41644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.yevid.com"] [uri "/wp-config.php~"] [unique_id "aprhpCFegSdHeGW3Ur3epwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:18:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.19.222.189 (189.222.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.222.189 (189.222.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:18:30.997041 2026] [security2:error] [pid 5635:tid 5635] [client 34.19.222.189:34796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.summitmediawv.com"] [uri "/.env.bak"] [unique_id "aprTNu8B89K_7EvJ9z6wiQAAAHw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:52:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.19.222.189 (189.222.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.222.189 (189.222.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:52:17.484402 2026] [security2:error] [pid 23106:tid 23106] [client 34.19.222.189:55532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adventiststoday1.satanisdead.com"] [uri "/.env.local"] [unique_id "aprNET7k_3dzO-xPWjwVjQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
netclix.gr
2026-09-04 12:47:56
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.19.222.189 (CA/Canada/189.222.19.34. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.19.222.189 (CA/Canada/189.222.19.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
🇵🇱
Budyn
2026-09-04 12:31:09
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: goblinpot.store | URI: /actuator/configprops | UA: crusader-worker/1.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇬🇧
Apache
2026-09-04 12:18:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.19.222.189 (CA/Canada/189.222.19.34.bc.googl ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.222.189 (CA/Canada/189.222.19.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
🇳🇴
jad-abuse
2026-09-04 12:16:57
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, scanner_ua, source_backup, actuator, ignition_debug, config_backup. Observed by 1 sensor(s); 19 hits.
show less
Hacking
Web App Attack
🇫🇮
as211431.net
2026-09-04 12:12:26
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env.
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 11:22:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.19.222.189 (189.222.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.222.189 (189.222.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:22:10.458240 2026] [security2:error] [pid 22746:tid 22746] [client 34.19.222.189:58968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eventsetcinc.com"] [uri "/.env.bak"] [unique_id "apqp4iOy4tSs_zr6vajZYAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:34:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.19.222.189 (189.222.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.222.189 (189.222.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:33:59.009892 2026] [security2:error] [pid 22631:tid 22631] [client 34.19.222.189:46906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alessiaalessandra.com"] [uri "/.env.dev"] [unique_id "apqelxYCL4lIRcdFZTcyFQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-04 10:33:45
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.bak (+12 more) | 2026-09-04 10:33 UTC
show less
Hacking
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 09:19:46
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.19.222.189 (CA/Canada/189.222.19.34.bc.googl ...
show more
(mod_security) mod_security (id:949110) triggered by 34.19.222.189 (CA/Canada/189.222.19.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:10:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.19.222.189 (189.222.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.222.189 (189.222.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:10:22.283788 2026] [security2:error] [pid 21502:tid 21502] [client 34.19.222.189:38932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kmindonesia.com.kairoslogammakmur.com"] [uri "/.env.bak"] [unique_id "apqK_swK2QySpJOo3R3xYgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:55:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.19.222.189 (189.222.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.222.189 (189.222.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:55:03.030268 2026] [security2:error] [pid 5180:tid 5180] [client 34.19.222.189:52966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "teamwakimphotography.com"] [uri "/.env.bak"] [unique_id "apqHZynROINw0cMGDI5GrgAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack