Anonymous
2026-08-29 05:29:21
(23 minutes ago)
apache vulnerability scan
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-08-29 05:13:19
(39 minutes ago)
111 attacks on env grabbing URLs, config grabbing URLs (type 2), VC URLs, PHP URLs, password grabbin ...
show more
111 attacks on env grabbing URLs, config grabbing URLs (type 2), VC URLs, PHP URLs, password grabbing URLs:
GET /.env.anthropic HTTP/1.1
GET /config/anthropic.json HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /pi.php HTTP/1.1
GET /root/.aws/credentials HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
pcpiefke
2026-08-29 05:05:47
(47 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 35.200.25.232 (JP/Japan/232.25.200.35.b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.200.25.232 (JP/Japan/232.25.200.35.bc.googleusercontent.com)
show less
SQL Injection
๐ง๐ช
taivas.nl
2026-08-29 04:33:42
(1 hour ago)
Many_bad_calls
Web App Attack
๐ซ๐ท
masterguru
2026-08-29 04:11:09
(1 hour ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.200.25.232 (JP/Japan/232.25.200.35 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.200.25.232 (JP/Japan/232.25.200.35.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
๐ณ๐ฑ
e.fierstra
2026-08-29 03:59:17
(1 hour ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 03:28:47
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.25.232 (232.25.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.25.232 (232.25.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:28:40.512303 2026] [security2:error] [pid 31677:tid 31683] [client 35.200.25.232:2316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.classactionlawsuit.org"] [uri "/@fs/app/.env"] [unique_id "apJR6Nb8JZEbKsYLT05gYAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 03:05:06
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.25.232 (232.25.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.25.232 (232.25.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:04:59.534642 2026] [security2:error] [pid 12490:tid 12490] [client 35.200.25.232:35714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.homeschoolwv.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apJMW4adi4rDk_cM0sOSYgAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-08-29 02:52:55
(3 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:35:34
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.25.232 (232.25.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.25.232 (232.25.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:35:28.682060 2026] [security2:error] [pid 12986:tid 12986] [client 35.200.25.232:54492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.grsquared.com"] [uri "/@fs/.env"] [unique_id "apJFcBsLwZp3eM70EFQSXQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:12:46
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.25.232 (232.25.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.25.232 (232.25.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:12:42.078334 2026] [security2:error] [pid 8238:tid 8238] [client 35.200.25.232:43462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.davidwoodard.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apJAGg-adk4MAvD0QvGaGQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-08-29 02:07:56
(3 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 01:31:51
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.25.232 (232.25.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.25.232 (232.25.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:31:47.205020 2026] [security2:error] [pid 17142:tid 17142] [client 35.200.25.232:55350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.walterjhoodco.com"] [uri "/@fs/src/.env"] [unique_id "apI2g9j-cNQ5isUMp0PhUwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 01:30:18
(4 hours ago)
[dev.backorder.gr] httpd-config-scan: sites=global; logs=/var/log/nginx/access.log; samples=/@fs/.en ...
show more
[dev.backorder.gr] httpd-config-scan: sites=global; logs=/var/log/nginx/access.log; samples=/@fs/.env.staging?raw?? | /@fs/home/node/.aws/config?raw?? | /@fs/app/rootkey.csv?raw??
show less
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-08-29 01:20:20
(4 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack