๐ฌ๐ง
openstrike.co.uk
2026-09-16 05:14:52
(16 hours ago)
180 attacks on env grabbing URLs, config grabbing URLs (type 2), VC URLs, directory traversals, env ...
show more
180 attacks on env grabbing URLs, config grabbing URLs (type 2), VC URLs, directory traversals, env grabbing URLs (type 2), PHP URLs, password/key grabbing URLs:
GET /.env?raw HTTP/1.1
GET /app-config.json HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /proc/self/cmdline HTTP/1.1
POST /icecoder/lib/terminal-xhr.php HTTP/1.1
GET /.ssh/id_ed25519 HTTP/1.1
show less
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-16 04:35:14
(17 hours ago)
excessive HTTP 404 errors
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-09-16 02:31:28
(19 hours ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
โจ
2026-09-16 01:38:08
(20 hours ago)
Domain : *.sylviepoggio.com
Rule : env
2026-09-16 01:36:31 ***hidden-privacy*** GET /.env.production ...
show more
Domain : *.sylviepoggio.com
Rule : env
2026-09-16 01:36:31 ***hidden-privacy*** GET /.env.production - 443 - 35.202.173.56 HTTP/2 Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] ) - account2.sylviepoggio.com 302 0 0 0 461 305 - -
show less
Hacking
SQL Injection
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-15 21:08:02
(1 day ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02 ...
show more
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02]
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 20:28:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.202.173.56 (56.173.202.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.202.173.56 (56.173.202.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:28:29.243448 2026] [security2:error] [pid 32390:tid 32390] [client 35.202.173.56:51510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "suffe.cool"] [uri "/.env.production"] [unique_id "aqmqbZPJGTw0doXX35fyiQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-15 20:25:35
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ฉ๐ช
rh24
2026-09-15 20:18:45
(1 day ago)
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 35.202.173.56 (US/United States/56.173.20 ...
show more
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 35.202.173.56 (US/United States/56.173.202.35.bc.googleusercontent.com)
show less
Hacking
๐บ๐ธ
Lee Daniel
2026-09-15 19:42:54
(1 day ago)
35.202.173.56 - - [15/Sep/2026:15:42:53 -0400] "GET /.aws/credentials HTTP/1.1" 403 6284 "-" "Mozill ...
show more
35.202.173.56 - - [15/Sep/2026:15:42:53 -0400] "GET /.aws/credentials HTTP/1.1" 403 6284 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-15 19:30:07
(1 day ago)
Fail2Ban - [WAF]ModSecurity rule violation on modsecurity ... [wa01,wa02]
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 19:10:42
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.202.173.56 (56.173.202.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.202.173.56 (56.173.202.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:10:37.989956 2026] [security2:error] [pid 1437269:tid 1437269] [client 35.202.173.56:48276] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sublimetiles.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sublimetiles.com"] [uri "/z9x8c7v6b5-debug-trigger-sublimetiles.com"] [unique_id "aqmYLQmk6w-xPJUfLEGMiQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Stylottica
2026-09-15 18:16:58
(1 day ago)
PrestaShop Security Module: suspicious probe path detected (/admin/)
Web App Attack
๐จ๐ญ
zynex
2026-09-15 17:26:11
(1 day ago)
URL Probing: /.env
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-15 17:18:24
(1 day ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 16:53:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.202.173.56 (56.173.202.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.202.173.56 (56.173.202.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:53:39.597011 2026] [security2:error] [pid 14174:tid 14174] [client 35.202.173.56:57692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stufflebeam.name"] [uri "/%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env"] [unique_id "aql4E7SMLq1NhFqdu8Qa0QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack