🇬🇧
openstrike.co.uk
2026-09-05 05:13:47
(17 hours ago)
13 attacks on env grabbing URLs, PHP URLs:
GET /.env.bak HTTP/1.1
GET /wp-config.php~ HTTP/1.1
Hacking
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 22:02:55
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 15:22:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.236.49.89 (89.49.236.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.49.89 (89.49.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:22:19.143063 2026] [security2:error] [pid 6744:tid 6744] [client 35.236.49.89:53610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.goldenstatealliance.com"] [uri "/wp-config.php~"] [unique_id "apriK4eCPhutURvPXIImKwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 14:56:04
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 35.236.49.89 (US/United States/89.49.236.35.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 35.236.49.89 (US/United States/89.49.236.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇫🇷
dynamix
2026-09-04 14:36:46
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:06:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.236.49.89 (89.49.236.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.49.89 (89.49.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:06:06.901559 2026] [security2:error] [pid 20478:tid 20478] [client 35.236.49.89:37480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.allnoneok.com"] [uri "/.env.old"] [unique_id "aprQTqYSLi_K7FqrQw0NngAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-04 14:04:49
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php~ (+12 more) | 2026-09-04 14:04 UTC
show less
Hacking
Web App Attack
🇧🇪
FrankNeirynck
2026-09-04 13:48:11
(1 day ago)
[2026-09-04 15:48:10 +0200] [1427] [WARNING] ⚠️ 🌐 35.236.49.89 "GET /wp-config.php~ HTTP/1.1" 404 13 ...
show more
[2026-09-04 15:48:10 +0200] [1427] [WARNING] ⚠️ 🌐 35.236.49.89 "GET /wp-config.php~ HTTP/1.1" 404 1317 "-" "crusader-worker/1.0"
[2026-09-04 15:48:10 +0200] [1427] [WARNING] ⚠️ 🌐 35.236.49.89 "GET /wp-config.php.swp HTTP/1.1" 404 1317 "-" "crusader-worker/1.0"
[2026-09-04 15:48:10 +0200] [1427] [WARNING] ⚠️ 🌐 35.236.49.89 "GET /wp-config.php.bak HTTP/1.1" 404 1317 "-" "crusader-worker/1.0"
...
show less
Hacking
Web App Attack
🇩🇪
filstal.org
2026-09-04 13:42:26
(1 day ago)
Web exploit or injection attempt blocked by ModSecurity WAF.
SQL Injection
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:48:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.236.49.89 (89.49.236.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.49.89 (89.49.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:48:26.875334 2026] [security2:error] [pid 24059:tid 24059] [client 35.236.49.89:55126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atlantahome.rehab"] [uri "/.env.save"] [unique_id "apq-GlqhymxJh43yXWJdnQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:30:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.236.49.89 (89.49.236.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.49.89 (89.49.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:30:48.118171 2026] [security2:error] [pid 31157:tid 31210] [client 35.236.49.89:43084] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "forestancestry.com"] [uri "/.env.production"] [unique_id "apq5-A3ftUW3UjUe0T628QAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ruusvuu
2026-09-04 12:18:47
(1 day ago)
Automated abuse report: 15 attack/probe requests from Google LLC / US.
Targeted paths: /_ignition/he ...
show more
Automated abuse report: 15 attack/probe requests from Google LLC / US.
Targeted paths: /_ignition/health-check, /.env.production, /.env.old, /.env.local, /wp-config.php.swp.
Sample log lines:
[mirresolve] 2026-09-04 05:18:47: 35.236.49.89 - GET /.env.dev HTTP/1.1 404 21 - 0.417 ms
[mirresolve] 2026-09-04 05:18:47: 35.236.49.89 - GET /.env.example HTTP/1.1 404 21 - 0.368 ms
[mirresolve] 2026-09-04 05:18:47: 35.236.49.89 - GET /.env.prod HTTP/1.1 404 21 - 0.366 ms
Detected by an automated web-server log monitor.
show less
Web App Attack
🇩🇪
Hazzard
2026-09-04 12:18:43
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇺🇸
TPI-Abuse
2026-09-04 11:54:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.236.49.89 (89.49.236.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.49.89 (89.49.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:54:14.291871 2026] [security2:error] [pid 19811:tid 19811] [client 35.236.49.89:34212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "starrmail.net"] [uri "/.env.local"] [unique_id "apqxZkSZ7_jYc5i8S8WJzgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 11:08:49
(1 day ago)
35.236.49.89 - - [04/Sep/2026:13:08:49 +0200] "GET /.env.production HTTP/1.1" 403 2363 "-" "crusader ...
show more
35.236.49.89 - - [04/Sep/2026:13:08:49 +0200] "GET /.env.production HTTP/1.1" 403 2363 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Web App Attack