🇬🇧
openstrike.co.uk
2026-09-05 05:14:34
(13 hours ago)
138 attacks on VC URLs, password grabbing URLs, config grabbing URLs (type 2), PHP URLs, env grabbin ...
show more
138 attacks on VC URLs, password grabbing URLs, config grabbing URLs (type 2), PHP URLs, env grabbing URLs:
GET /.git/config HTTP/1.1
GET /.aws/credentials.old HTTP/1.1
GET /config/aws.yml HTTP/1.1
GET /config/aws.php HTTP/1.1
GET /aws/.env.production HTTP/1.1
show less
Hacking
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 22:02:42
(20 hours ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇺🇸
WellSpring
2026-09-04 15:22:18
(1 day ago)
env leak on 325.today/@fs/home/ubuntu/.env — WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
🇺🇸
dot.mg
2026-09-04 14:41:12
(1 day ago)
Bad behaviour
Web Spam
🇺🇸
TPI-Abuse
2026-09-04 13:12:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.205.138.120 (120.138.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.138.120 (120.138.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:12:38.403287 2026] [security2:error] [pid 14209:tid 14209] [client 35.205.138.120:62510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fatbastardcompetition.com"] [uri "/@fs/app/.env"] [unique_id "aprDxgF07F00XiS-qj9zBgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-04 13:04:33
(1 day ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted]): (CF_ENABLE)
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 12:57:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.205.138.120 (120.138.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.138.120 (120.138.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:57:16.476062 2026] [security2:error] [pid 30811:tid 30811] [client 35.205.138.120:33232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.bigskyprints.com"] [uri "/@fs/app/.env"] [unique_id "aprALAfxzNmr9fOV6dECXQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-04 12:35:11
(1 day ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:42:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.205.138.120 (120.138.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.138.120 (120.138.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:42:03.617535 2026] [security2:error] [pid 14832:tid 14832] [client 35.205.138.120:59370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.srosa.com"] [uri "/@fs/src/.env"] [unique_id "apqui6lW7hW9caf6DfOE_QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
rubixstudios
2026-09-04 09:57:02
(1 day ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇮🇩
Burayot
2026-09-04 09:31:58
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.205.138.120 (BE/Belgium/120.138.2 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.205.138.120 (BE/Belgium/120.138.205.35.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
🇩🇪
maxpower
2026-09-04 09:23:58
(1 day ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.205.138.120 (BE/Belgium/120.138.205.3 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.205.138.120 (BE/Belgium/120.138.205.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.205.138.120 - - [04/Sep/2026:11:23:57 +0200] "GET /@fs/root/.aws/credentials.bak?raw?? HTTP/1.1" 200 12013 "-" "Mozilla/5.0 (Linux; Android 15; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.4032.54 Mobile Safari/537.36; compatible; GrokBot/1.0; +https://x.ai/grokbot" "-" host=mail.qmcorporation.net
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-04 08:00:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.205.138.120 (120.138.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.138.120 (120.138.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:00:13.299467 2026] [security2:error] [pid 344:tid 344] [client 35.205.138.120:62016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whiteblackbird.com"] [uri "/@fs/../.env"] [unique_id "app6jWaSdHOKnoaXt9qI0wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-04 07:38:38
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:24:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.205.138.120 (120.138.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.138.120 (120.138.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:24:05.684352 2026] [security2:error] [pid 18437:tid 18437] [client 35.205.138.120:1402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ted.krakowski.net"] [uri "/@fs/app/.env"] [unique_id "appyFVZuIulRAPSOh4GxGAAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack