๐ซ๐ท
guillaume illien
2026-10-05 18:06:08
(1 hour ago)
35.199.64.152 - - [05/Oct/2026:18:06:00 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2 ...
show more
35.199.64.152 - - [05/Oct/2026:18:06:00 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 166 "-" "-"
35.199.64.152 - - [05/Oct/2026:18:06:06 +0000] "GET /..%2f.env HTTP/1.1" 400 166 "-" "-"
35.199.64.152 - - [05/Oct/2026:18:06:06 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 166 "-" "-"
35.199.64.152 - - [05/Oct/2026:18:06:06 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 166 "-" "-"
35.199.64.152 - - [05/Oct/2026:18:06:06 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 166 "-" "-"
35.199.64.152 - - [05/Oct/2026:18:06:07 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 166 "-" "-"
35.199.64.152 - - [05/Oct/2026:18:06:08 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 166 "-" "-"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
๐ฉ๐ช
webanyone
2026-10-05 18:05:42
(1 hour ago)
Secret file probe | method: GET | path: //.env | ua: Mozilla/5.0 (compatible; Hunyuan/1.0; +https:// ...
show more
Secret file probe | method: GET | path: //.env | ua: Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)
show less
Hacking
Web App Attack
๐ซ๐ท
guillaume illien
2026-10-05 12:36:21
(6 hours ago)
35.199.64.152 - - [05/Oct/2026:12:36:08 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2 ...
show more
35.199.64.152 - - [05/Oct/2026:12:36:08 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 166 "-" "-"
35.199.64.152 - - [05/Oct/2026:12:36:10 +0000] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
35.199.64.152 - - [05/Oct/2026:12:36:18 +0000] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/proc/self/environ HTTP/1.1" 400 166 "-" "-"
35.199.64.152 - - [05/Oct/2026:12:36:18 +0000] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env HTTP/1.1" 400 166 "-" "-"
35.199.64.152 - - [05/Oct/2026:12:36:19 +0000] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
35.199.64.152 - - [05/Oct/2026:12:36:20 +0000] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
35.199.64.152 - - [05/Oct/2026:12:36:21 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 166 "-" "-"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
๐ฉ๐ช
raph
2026-10-05 08:37:43
(10 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ซ๐ท
Entalpi.net
2026-10-05 07:10:21
(12 hours ago)
Repeated requests against sensitive web endpoints
Web App Attack
๐ช๐ธ
robotstxt
2026-10-05 06:35:39
(12 hours ago)
35.199.64.152 - - [05/Oct/2026:06:35:34 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 193 "-" "-" "-" ed ...
show more
35.199.64.152 - - [05/Oct/2026:06:35:34 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.199.64.152"
35.199.64.152 - - [05/Oct/2026:06:35:35 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="35.199.64.152"
35.199.64.152 - - [05/Oct/2026:06:35:35 +0000] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="35.199.64.152"
35.199.64.152 - - [05/Oct/2026:06:35:35 +0000] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.199.64.152"
35.199.64.152 - - [05/Oct/2026:06:35:35 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="35.199.64.152"
...
show less
Web Spam
Web App Attack
๐ฉ๐ช
Michel Wijnberg
2026-10-05 06:30:09
(12 hours ago)
35.199.64.152 - - [05/Oct/2026:06:30:08 +0000] "GET /phpinfo.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 ...
show more
35.199.64.152 - - [05/Oct/2026:06:30:08 +0000] "GET /phpinfo.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-10-05 06:24:50
(12 hours ago)
Not following 301 redirects โ wasted requests | method: GET | path: / | ua: Mozilla/5.0 (Windows NT ...
show more
Not following 301 redirects โ wasted requests | method: GET | path: / | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
[email protected]
2026-10-05 06:09:58
(13 hours ago)
CrowdSec ban: crowdsecurity/http-crawl-non_statics (duration: 71h59m59s)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 06:07:24
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.64.152 (152.64.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.64.152 (152.64.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 02:07:16.601504 2026] [security2:error] [pid 20993:tid 20993] [client 35.199.64.152:44064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "utilis.net"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "asM-lPjGEo0P5OD5-CHRHAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
NotCool
2026-10-05 06:02:03
(13 hours ago)
(CRAWLDELAY) Generic Bot Crawl-delay Violation 35.199.64.152 (BR/Brazil/152.64.199.35.bc.googleuserc ...
show more
(CRAWLDELAY) Generic Bot Crawl-delay Violation 35.199.64.152 (BR/Brazil/152.64.199.35.bc.googleusercontent.com): 50 in the last 3600 secs
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-05 05:50:46
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.64.152 (152.64.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.64.152 (152.64.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 01:50:43.894137 2026] [security2:error] [pid 758:tid 758] [client 35.199.64.152:50652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tracybur.net"] [uri "/.htpasswd"] [unique_id "asM6s-INI0h4MXwlNbttxwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-10-05 05:27:31
(13 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
entangled_mongoose
2026-10-05 05:24:41
(13 hours ago)
Probed /wp-json.
Web App Attack
๐ฉ๐ช
firestorm
2026-10-05 05:11:06
(14 hours ago)
35.199.64.152 - - [05/Oct/2026:07:11:03 +0200] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/e ...
show more
35.199.64.152 - - [05/Oct/2026:07:11:03 +0200] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 150 "-" "-"
35.199.64.152 - - [05/Oct/2026:07:11:04 +0200] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 150 "-" "-"
35.199.64.152 - - [05/Oct/2026:07:11:05 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 150 "-" "-"
...
show less
Brute-Force
Web App Attack