๐ฌ๐ง
openstrike.co.uk
2026-09-01 05:14:14
(2 hours ago)
13 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php.swp HTTP/1.1
GET /.env.bak HTTP/1.1
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 05:06:53
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.52.176.58 (58.176.52.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.52.176.58 (58.176.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:06:48.026207 2026] [security2:error] [pid 11993:tid 11993] [client 34.52.176.58:60992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.carbonless.net"] [uri "/wp-config.php~"] [unique_id "apZdaK5G1Zrezfo7yqPVvgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:46:55
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.52.176.58 (58.176.52.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.52.176.58 (58.176.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:46:50.740889 2026] [security2:error] [pid 3251:tid 3251] [client 34.52.176.58:44064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hshr.com"] [uri "/.env"] [unique_id "apZYuqLzHGunleg_lIsD2QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Major Hostility
2026-09-01 04:40:55
(3 hours ago)
"GET /.env.old HTTP/1.1" 404
"GET /.env.production HTTP/1.1" 404
"GET /.env.bak HTTP/1.1" 404
Web App Attack
Anonymous
2026-09-01 04:30:02
(3 hours ago)
suspicious request in access.log
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 04:12:36
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-01 04:12:07
(3 hours ago)
Detected by CrowdSec: crowdsecurity/http-sensitive-files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:53:00
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.52.176.58 (58.176.52.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.52.176.58 (58.176.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:52:56.621481 2026] [security2:error] [pid 23170:tid 23170] [client 34.52.176.58:52336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lewpratt.com"] [uri "/wp-config.php~"] [unique_id "apZMGHmaey6PaKxH68Yn7gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 03:51:57
(3 hours ago)
[da.kdns.gr] httpd-config-scan: sites=www.anyfantis.gr; logs=/var/log/httpd/domains/anyfantis.gr.log ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.anyfantis.gr; logs=/var/log/httpd/domains/anyfantis.gr.log; samples=/wp-config.php~ | /wp-config.php.bak | /wp-config.php.swp
show less
Hacking
Web App Attack
๐ฌ๐ง
Apache
2026-09-01 02:40:43
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.52.176.58 (BE/Belgium/58.176.52.34.bc.google ...
show more
(mod_security) mod_security (id:210492) triggered by 34.52.176.58 (BE/Belgium/58.176.52.34.bc.googleusercontent.com): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:35:56
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.52.176.58 (58.176.52.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.52.176.58 (58.176.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:35:50.090401 2026] [security2:error] [pid 29165:tid 29165] [client 34.52.176.58:54754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.gellertdealers.com"] [uri "/.env.production"] [unique_id "apY6BvDp8phQqVQgGVT5UAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 02:17:01
(5 hours ago)
Bot / scanning and/or hacking attempts: GET /wp-config.php.swp HTTP/1.1, GET /wp-config.php~ HTTP/1. ...
show more
Bot / scanning and/or hacking attempts: GET /wp-config.php.swp HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /wp-config.php.bak HTTP/1.1
show less
Hacking
Web App Attack
๐จ๐ฆ
polycoda
2026-09-01 01:29:19
(6 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based) - โช๏ธ Excessive 30X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-01 01:23:57
(6 hours ago)
cloudlinux2 fail2ban: 2026-09-01 03:20:17,935 fail2ban.filter [1605]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-01 03:20:17,935 fail2ban.filter [1605]: INFO [plesk-wordpress] Found 23.108.2.219 - 2026-09-01 03:20:17cloudlinux2 fail2ban: 2026-09-01 03:20:30,332 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 180.153.236.218 - 2026-09-01 03:20:30cloudlinux2 fail2ban: 2026-09-01 03:20:28,338 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 180.153.236.174 - 2026-09-01 03:20:28cloudlinux2 fail2ban: 2026-09-01 03:20:41,802 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 34.52.176.58 - 2026-09-01 03:20:41cloudlinux2 fail2ban: 2026-09-01 03:20:41,712 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 34.52.176.58 - 2026-09-01 03:20:41cloudlinux2 fail2ban: 2026-09-01 03:20:41,740 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 34.52.176.58 - 2026-09-01 03:20:41cloudlinux2 fail2ban: 2026-09-01 03:20:41,761 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 34.52.176.58 - 2026-09-01 03:20:
show less
Web App Attack
๐บ๐ธ
antlac1
2026-09-01 01:04:21
(6 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack