🇬🇧
openstrike.co.uk
2026-09-05 05:14:40
(11 hours ago)
13 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php.bak HTTP/1.1
GET /.env HTTP/1.1
Web App Attack
Hacking
🇺🇸
SodaAudit.app
2026-09-04 15:18:48
(1 day ago)
[sodaaudit.app] Web app attack. Timestamp: 2026-09-04T13:34:32.000Z. 5 probe events, 4 distinct path ...
show more
[sodaaudit.app] Web app attack. Timestamp: 2026-09-04T13:34:32.000Z. 5 probe events, 4 distinct path(s). Paths (payload): /.env, /wp-config.php.bak, /storage/logs/laravel.log, /.env.bak
show less
Web App Attack
🇬🇧
Interceptor_HQ
2026-09-04 14:27:32
(1 day ago)
request_uri: /.env.old -- automatic report --
Brute-Force
Hacking
🇩🇪
raph
2026-09-04 14:11:04
(1 day ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 14:00:17
(1 day ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-04 12:33:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.86.254.197 (197.254.86.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.254.197 (197.254.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:33:35.191863 2026] [security2:error] [pid 22622:tid 22622] [client 34.86.254.197:56694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.desoucey.com"] [uri "/wp-config.php.bak"] [unique_id "apq6n-CCTvIYnkukxMhH4QAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
clamehost.it
2026-09-04 12:32:48
(1 day ago)
Automatic report - Brute Force attack using this IP address
Brute-Force
🇫🇷
ELYAZ
2026-09-04 12:29:03
(1 day ago)
(y3) Failed access -byebye- from 34.86.254.197 (US/United States/197.254.86.34.bc.googleusercontent. ...
show more
(y3) Failed access -byebye- from 34.86.254.197 (US/United States/197.254.86.34.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-04 11:45:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.86.254.197 (197.254.86.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.254.197 (197.254.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:45:24.963176 2026] [security2:error] [pid 13665:tid 13665] [client 34.86.254.197:40950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.circleofsound.org"] [uri "/.env.save"] [unique_id "apqvVPqic0v5zqADnZBzTwAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-04 11:00:39
(1 day ago)
Try to access /.env
Web App Attack
Anonymous
2026-09-04 10:54:22
(1 day ago)
Scanner hitting /.env on nats-0.osef.cloud (GOOGL-2) — aaguard
Brute-Force
Port Scan
🇿🇦
conure.sh
2026-09-04 10:51:21
(1 day ago)
csagent: score 24.8: 404 noise floor x3, secrets grab x2, botnet path probe x1; 1 domain(s) in 0s
Web App Attack
🇺🇸
VanKoh
2026-09-04 10:34:39
(1 day ago)
34.86.254.197 - - [04/Sep/2026:04:34:38 -0600] "GET /.env.prod HTTP/1.1" 301 162 "-" "crusader-worke ...
show more
34.86.254.197 - - [04/Sep/2026:04:34:38 -0600] "GET /.env.prod HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
34.86.254.197 - - [04/Sep/2026:04:34:38 -0600] "GET /wp-config.php.bak HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
34.86.254.197 - - [04/Sep/2026:04:34:38 -0600] "GET /actuator/configprops HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
...
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:59:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.86.254.197 (197.254.86.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.254.197 (197.254.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:59:23.044220 2026] [security2:error] [pid 27216:tid 27216] [client 34.86.254.197:57788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "norkyn.austli.com"] [uri "/wp-config.php.bak"] [unique_id "apqWez9GFTpFZRAJhfgKUAAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 09:24:40
(1 day ago)
[ns41.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/actuator/env | /wp-config ...
show more
[ns41.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/actuator/env | /wp-config.php.bak | /.env.production
show less
Hacking
Web App Attack