π¬π§
openstrike.co.uk
2026-09-23 05:14:38
(1 day ago)
13 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php.swp HTTP/1.1
GET /.env.local HTTP/1.1
Web App Attack
Hacking
π«π·
COMAITE
2026-09-22 16:25:32
(1 day ago)
Suspicious URL access.
Web App Attack
Anonymous
2026-09-22 15:26:52
(1 day ago)
Web application attack detected.
Web App Attack
πΊπ¦
URAN Publishing Service
2026-09-22 15:15:02
(1 day ago)
[22/Sep/2026:18:15:01 +0300] -- 34.50.8.201 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-con ...
show more
[22/Sep/2026:18:15:01 +0300] -- 34.50.8.201 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-config.php~ HTTP/1.1
show less
Bad Web Bot
Web App Attack
π«π·
mrcrassi
2026-09-22 15:01:10
(2 days ago)
Triggered Cloudflare WAF (firewallManaged) from KR.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from KR.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-config.php.swp
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-22 14:34:01
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.50.8.201 (201.8.50.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.8.201 (201.8.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:33:54.385842 2026] [security2:error] [pid 7935:tid 8027] [client 34.50.8.201:52430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "livingalegacybulldogges.com"] [uri "/.env.prod"] [unique_id "arKR0hWMfQto_oQu_QiG4gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Alt255
2026-09-22 14:11:33
(2 days ago)
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.50.8.201 - - [22/Sep/2026:16:11:13 +0200] "GET /.env.save HTTP/1.1" 301 5775 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-09-22 14:07:05
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
Charlesiv
2026-09-22 14:02:44
(2 days ago)
Triggered Cloudflare WAF (firewallCustom) from KR.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from KR.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env/
Timestamp: 2026-09-22T13:43:50Z
Ray ID: a3f1bdaa6da6a0c0
UA: crusader-worker/1.0
show less
Bad Web Bot
π©πͺ
Nevermind
2026-09-22 13:36:37
(2 days ago)
34.50.8.201 - - [22/Sep/2026:15:36:36 +0200] "GET /.env HTTP/1.1" 403 6271 "-" "crusader-worker/1.0" ...
show more
34.50.8.201 - - [22/Sep/2026:15:36:36 +0200] "GET /.env HTTP/1.1" 403 6271 "-" "crusader-worker/1.0"
34.50.8.201 - - [22/Sep/2026:15:36:36 +0200] "GET /.env.prod HTTP/1.1" 403 6271 "-" "crusader-worker/1.0"
34.50.8.201 - - [22/Sep/2026:15:36:36 +0200] "GET /.env.dev HTTP/1.1" 403 6271 "-" "crusader-worker/1.0"
34.50.8.201 - - [22/Sep/2026:15:36:36 +0200] "GET /.env.production HTTP/1.1" 403 6271 "-" "crusader-worker/1.0"
...
show less
Web App Attack
π³π±
e.fierstra
2026-09-22 12:11:43
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 11:48:32
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.50.8.201 (201.8.50.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.8.201 (201.8.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:48:25.302337 2026] [security2:error] [pid 28792:tid 28792] [client 34.50.8.201:47982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.robtown.com"] [uri "/.env.save"] [unique_id "arJrCeXctYkocpIhMS11VgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 11:28:28
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.50.8.201 (201.8.50.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.8.201 (201.8.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:28:22.905090 2026] [security2:error] [pid 22555:tid 22555] [client 34.50.8.201:53094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carjinn.net"] [uri "/.env.example"] [unique_id "arJmVmjl4PRB8VRh7zhm6QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 11:11:10
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.50.8.201 (201.8.50.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.8.201 (201.8.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:11:04.228616 2026] [security2:error] [pid 5974:tid 5974] [client 34.50.8.201:60896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bawaselcenter.iahksa.com"] [uri "/.env"] [unique_id "arJiSPeK04CfmkKurG4EeAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
4server
2026-09-22 10:54:18
(2 days ago)
[TueSep2212:54:13.1349562026][security2:error][pid3289078:tid3289137][client34.50.8.201:0]ModSecurit ...
show more
[TueSep2212:54:13.1349562026][security2:error][pid3289078:tid3289137][client34.50.8.201:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"associazione-iris.ch\"][uri\"/.env.old\"][unique_id\"arJeVSzngkQTY-VBZp2GUAAAAFY\"]
show less
Hacking
Web App Attack