๐ฌ๐ง
openstrike.co.uk
2026-08-28 05:14:30
(3 hours ago)
13 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php.swp HTTP/1.1
GET /.env HTTP/1.1
Web App Attack
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 22:02:55
(10 hours ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
๐ฉ๐ช
gadix
2026-08-27 19:14:08
(13 hours ago)
[27/Aug/2026:21:14:05.249997 +0200] apCMfUgupJ6loDrqufoLiQAAAAc 35.231.15.145 36042 127.0.0.1 7081
[ ...
show more
[27/Aug/2026:21:14:05.249997 +0200] apCMfUgupJ6loDrqufoLiQAAAAc 35.231.15.145 36042 127.0.0.1 7081
[27/Aug/2026:21:14:05.253708 +0200] apCMfbUJH6QQKtRG5F1xHwAAAAg 35.231.15.145 36058 127.0.0.1 7081
[27/Aug/2026:21:14:05.256639 +0200] apCMfezyXZJejToYwPnLKQAAAAE 35.231.15.145 36078 127.0.0.1 7081
...
show less
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-08-27 17:41:24
(15 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฉ๐ช
LRob
2026-08-27 16:51:47
(15 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.old (+10 more) | 2026-08-27 16:51 UTC
show less
Hacking
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-27 15:50:17
(16 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
Major Hostility
2026-08-27 15:44:33
(16 hours ago)
"GET /env HTTP/1.1" 404
"GET /.env HTTP/1.1" 404
"GET /.env.production HTTP/1.1" 404
"GET /.env.loca ...
show more
"GET /env HTTP/1.1" 404
"GET /.env HTTP/1.1" 404
"GET /.env.production HTTP/1.1" 404
"GET /.env.local HTTP/1.1" 404
"GET /.env.prod HTTP/1.1" 404
"GET /.env.backup HTTP/1.1" 404
"GET /.env.bak HTTP/1.1" 404
"GET /.env.old HTTP/1.1" 404
"GET /.env.save HTTP/1.1" 404
"GET /.env.example HTTP/1.1" 404
"GET /.env.dev HTTP/1.1" 404
"GET /actuator/env HTTP/1.1" 404
"GET /actuator/configprops HTTP/1.1" 404
"GET /_ignition/health-check HTTP/1.1" 404
"GET /crusader-404-probe HTTP/1.1" 404
"GET /wp-config.php.bak HTTP/1.1" 404
"GET /wp-config.php~ HTTP/1.1" 404
"GET /wp-config.php.swp HTTP/1.1" 404
"GET /storage/logs/laravel.log HTTP/1.1" 404
show less
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-27 15:42:01
(17 hours ago)
35.231.15.145 - - [27/Aug/2026:17:41:58 +0200] "GET /wp-config.php~ HTTP/1.1" 403 4650 "-" "crusader ...
show more
35.231.15.145 - - [27/Aug/2026:17:41:58 +0200] "GET /wp-config.php~ HTTP/1.1" 403 4650 "-" "crusader-worker/1.0"
35.231.15.145 - - [27/Aug/2026:17:41:58 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 4651 "-" "crusader-worker/1.0"
35.231.15.145 - - [27/Aug/2026:17:41:58 +0200] "GET /actuator/configprops HTTP/1.1" 403 4651 "-" "crusader-worker/1.0"
35.231.15.145 - - [27/Aug/2026:17:41:58 +0200] "GET /wp-config.php.swp HTTP/1.1" 403 4651 "-" "crusader-worker/1.0"
35.231.15.145 - - [27/Aug/2026:17:41:58 +0200] "GET /.env.dev HTTP/1.1" 403 4651 "-" "crusader-worker/1.0"
35.231.15.145 - - [27/Aug/2026:17:41:58 +0200] "GET /.env.prod HTTP/1.1" 403 4651 "-" "crusader-worker/1.0"
35.231.15.145 - - [27/Aug/2026:17:41:58 +0200] "GET /.env.backup HTTP/1.1" 403 4652 "-" "crusader-worker/1.0"
35.231.15.145 - - [27/Aug/2026:17:41:58 +0200] "GET /crusader-404-probe HTTP/1.1" 403 4652 "-" "crusader-worker/1.0"
35.231.15.145 - - [27/Aug/2026:17:41:58 +0200] "GET /.env HTTP/1.1" 403 4652 "-" "crusader-wor
show less
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-27 15:09:51
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.231.15.145 (145.15.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.15.145 (145.15.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:09:46.310561 2026] [security2:error] [pid 16378:tid 16378] [client 35.231.15.145:44728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.solarshop.aguasolar.com"] [uri "/wp-config.php~"] [unique_id "apBTOgnqdth0-ukB-lrDsgAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-27 14:37:48
(18 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-08-27 14:35:26
(18 hours ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 14:31:51
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.231.15.145 (145.15.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.15.145 (145.15.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:31:48.055389 2026] [security2:error] [pid 24837:tid 24837] [client 35.231.15.145:36336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whitelabelcasinoportal.net.crazycoin.net"] [uri "/.env"] [unique_id "apBKVCldMJlHiXDYIb6AUAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-08-27 14:21:20
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.231.15.145 (US/United States/145.15.231.35.b ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.15.145 (US/United States/145.15.231.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-08-27 14:02:37
(18 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-27 14:02:05
(18 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.231.15.145 (US/United States/145. ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.231.15.145 (US/United States/145.15.231.35.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack