🇨🇭
GAS
2026-09-06 19:55:10
(48 minutes ago)
Direct IP access.
35.189.15.175 - - [06/Sep/2026:21:55:08 +0200] "GET /dump.sql HTTP/1.1" 402 3987 " ...
show more
Direct IP access.
35.189.15.175 - - [06/Sep/2026:21:55:08 +0200] "GET /dump.sql HTTP/1.1" 402 3987 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36" "REDACTED" ""
35.189.15.175 - - [06/Sep/2026:21:55:08 +0200] "GET /dump.tar.gz HTTP/1.1" 402 3987 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36" "REDACTED" ""
...
show less
Port Scan
Web App Attack
Anonymous
2026-09-06 13:45:18
(6 hours ago)
Observed scanned 12 known-sensitive endpoint(s), e.g.: /, /%2eenv, /.ENV, /.env, /.env.bak, /.env.ol ...
show more
Observed scanned 12 known-sensitive endpoint(s), e.g.: /, /%2eenv, /.ENV, /.env, /.env.bak, /.env.old
show less
Bad Web Bot
Web App Attack
🇰🇷
windykc
2026-09-06 06:30:11
(14 hours ago)
Honeypot capture. HTTP: 12 attacks (sample URIs: ['/.env.prod', '/.env.local', '/.env.backup', '/.en ...
show more
Honeypot capture. HTTP: 12 attacks (sample URIs: ['/.env.prod', '/.env.local', '/.env.backup', '/.env.production', '/.env.bak']). Geo/ISP: AU/Google LLC. Last seen: 2026-09-06T15:14:23Z.
show less
Hacking
Web App Attack
🇬🇧
openstrike.co.uk
2026-09-06 05:13:23
(15 hours ago)
13 attacks on env grabbing URLs, PHP URLs:
GET /.env.old HTTP/1.1
GET /wp-config.php.bak HTTP/1.1
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:55:42
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.15.175 (175.15.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.15.175 (175.15.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:55:39.002498 2026] [security2:error] [pid 11165:tid 11190] [client 35.189.15.175:49366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.chronotar.com"] [uri "/.env.bak"] [unique_id "apzkO_1pRt8N7QnZBIkoUQAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
penjaga BRIN
2026-09-06 03:26:47
(17 hours ago)
Suspicious malicious activity
Hacking
🇺🇸
TPI-Abuse
2026-09-06 03:02:38
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.15.175 (175.15.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.15.175 (175.15.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:02:30.832994 2026] [security2:error] [pid 21071:tid 21071] [client 35.189.15.175:55212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wedemandabetterplan.empoweruohio.org"] [uri "/.env.prod"] [unique_id "apzXxicgheULN8APSQYWlAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Skyrider
2026-09-06 02:31:55
(18 hours ago)
crowdsecurity/http-sensitive-files
Web App Attack
Anonymous
2026-09-06 02:21:01
(18 hours ago)
Observed scanned 1 known-sensitive endpoint(s), e.g.: /.env.example
Bad Web Bot
Web App Attack
🇮🇩
Burayot
2026-09-06 01:45:21
(18 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 35.189.15.175 (AU/Australia/175.15. ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 35.189.15.175 (AU/Australia/175.15.189.35.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
Anonymous
2026-09-06 00:30:48
(20 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 23:53:29
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.15.175 (175.15.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.15.175 (175.15.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:53:21.906374 2026] [security2:error] [pid 22065:tid 22065] [client 35.189.15.175:44514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "okeetokee.org"] [uri "/.env"] [unique_id "apyrcW5-m4STnaUOuM1ARQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 23:28:48
(21 hours ago)
Web application attack detected.
Web App Attack
🇬🇧
consul.to
2026-09-05 23:02:57
(21 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:54:54
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.15.175 (175.15.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.15.175 (175.15.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:54:47.159292 2026] [security2:error] [pid 2952:tid 2959] [client 35.189.15.175:35990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.gbodtheatre.com"] [uri "/.env.old"] [unique_id "apydt6tA3Hhb7YIrmc4LbQAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack