๐ฌ๐ง
openstrike.co.uk
2026-08-02 05:13:52
(4 hours ago)
10 attacks on env grabbing URLs:
GET /.env.production HTTP/1.1
Hacking
Anonymous
2026-08-01 17:35:03
(16 hours ago)
suspicious request in access.log
Web App Attack
๐ฎ๐น
clamehost.it
2026-08-01 17:10:51
(16 hours ago)
Automatic report - Brute Force attack using this IP address
Brute-Force
๐บ๐ธ
mnsf
2026-08-01 17:05:21
(16 hours ago)
Too many Status 40X (20)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:50:12
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.184.36 (36.184.64.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.184.36 (36.184.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:50:05.937759 2026] [security2:error] [pid 109031:tid 109031] [client 34.64.184.36:47404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hollistercomputer.com"] [uri "/.env.bak"] [unique_id "am4jvdyFHCMn1IkRIEfqKQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-01 16:27:40
(17 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-08-01 16:17:03
(17 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.production HTTP/1.1, GET /.env.old HTTP/1.1, GET / ...
show more
Bot / scanning and/or hacking attempts: GET /.env.production HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env.example HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
Keith Beucler
2026-08-01 15:20:20
(18 hours ago)
K5 Services fail2ban jail nginx-k5-web-probes detected high-confidence web abuse. Local web ban appl ...
show more
K5 Services fail2ban jail nginx-k5-web-probes detected high-confidence web abuse. Local web ban applied. Categories: 19,21.
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 15:11:19
(18 hours ago)
34.64.184.36 - - [01/Aug/2026:17:11:19 +0200] "GET /.env.backup HTTP/1.1" 403 1453 "-" "crusader-wor ...
show more
34.64.184.36 - - [01/Aug/2026:17:11:19 +0200] "GET /.env.backup HTTP/1.1" 403 1453 "-" "crusader-worker/1.0"
34.64.184.36 - - [01/Aug/2026:17:11:19 +0200] "GET /.env.backup HTTP/1.1" 403 210 "-" "crusader-worker/1.0"
34.64.184.36 - - [01/Aug/2026:17:11:19 +0200] "GET /.env.bak HTTP/1.1" 403 1453 "-" "crusader-worker/1.0"
34.64.184.36 - - [01/Aug/2026:17:11:19 +0200] "GET /.env.bak HTTP/1.1" 403 210 "-" "crusader-worker/1.0"
34.64.184.36 - - [01/Aug/2026:17:11:19 +0200] "GET /.env.old HTTP/1.1" 403 1453 "-" "crusader-worker/1.0"
34.64.184.36 - - [01/Aug/2026:17:11:19 +0200] "GET /.env.old HTTP/1.1" 403 210 "-" "crusader-worker/1.0"
34.64.184.36 - - [01/Aug/2026:17:11:19 +0200] "GET /.env.example HTTP/1.1" 404 6330 "-" "crusader-worker/1.0"
34.64.184.36 - - [01/Aug/2026:17:11:19 +0200] "GET /.env.example HTTP/1.1" 404 5093 "-" "crusader-worker/1.0"
34.64.184.36 - - [01/Aug/2026:17:11:19 +0200] "GET /.env.prod HTTP/1.1" 404 6330 "-" "crusader-worker/1.0"
34.64.184.36 - - [01/Aug/2026:17:1
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:49:28
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.184.36 (36.184.64.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.184.36 (36.184.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:49:22.067503 2026] [security2:error] [pid 1811484:tid 1811484] [client 34.64.184.36:59960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nsightsound.com"] [uri "/.env.dev"] [unique_id "am4Hcj6nzJXNRf6_mT057wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-01 14:49:25
(18 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.64.184.36 (KR/South Korea/36.184.6 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.64.184.36 (KR/South Korea/36.184.64.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 14:12:21
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.184.36 (36.184.64.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.184.36 (36.184.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:12:15.591394 2026] [security2:error] [pid 2334682:tid 2334682] [client 34.64.184.36:40308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sp.cloudex.link"] [uri "/.env.save"] [unique_id "am3-v6rCcfJagPE2PiaG-QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-08-01 14:03:19
(19 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-08-01 13:56:48
(19 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 13:55:08
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.184.36 (36.184.64.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.184.36 (36.184.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:55:02.140622 2026] [security2:error] [pid 812976:tid 812976] [client 34.64.184.36:50754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "airintakesonline.com"] [uri "/.env.production"] [unique_id "am36tmVRTiXR59xBslQr4gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack