Anonymous
2026-09-09 15:07:12
(1 hour ago)
35.201.233.196 - - [09/Sep/2026:17:07:07 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 403 124 "-" "Mozilla/ ...
show more
35.201.233.196 - - [09/Sep/2026:17:07:07 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)"
35.201.233.196 - - [09/Sep/2026:17:07:07 +0200] "GET /@fs/root/rootkey.csv?raw?? HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.4; +https://openai.com/gptbot) Chrome/120.0.4431.41 Safari/537.36"
35.201.233.196 - - [09/Sep/2026:17:07:07 +0200] "GET /@fs/app/.env?raw?? HTTP/1.1" 403 183 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_4 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot) Chrome/122.0.7011.235 Mobile Safari/537.36"
35.201.233.196 - - [09/Sep/2026:17:07:07 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Bytespider; +ht
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 14:42:00
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.201.233.196 (196.233.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.233.196 (196.233.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 10:41:56.117139 2026] [security2:error] [pid 4429:tid 4429] [client 35.201.233.196:7660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.auditleverage.com"] [uri "/@fs/root/.env"] [unique_id "aqFwNA5K1Q8Cs8yn2nEr5gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
rubixstudios
2026-09-09 14:37:03
(1 hour ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇩🇪
v1nc
2026-09-09 13:23:04
(3 hours ago)
35.201.233.196 - - [09/Sep/2026:13:23:03 +0000] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 404 118 ...
show more
35.201.233.196 - - [09/Sep/2026:13:23:03 +0000] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 404 118 "-" "Mozilla/5.0 (compatible; facebookexternalhit/1.1; +http://www.facebook.com/externalhit_uatext.php)"
...
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-09 13:16:16
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.233.196 (196.233.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.233.196 (196.233.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:16:10.790533 2026] [security2:error] [pid 7171:tid 7171] [client 35.201.233.196:51594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fatjesus.com"] [uri "/@fs/src/.env"] [unique_id "aqFcGjkHMG8DiKk1YqvflgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
DEV-DNS
2026-09-09 12:59:43
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇺🇸
TPI-Abuse
2026-09-09 11:25:20
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.233.196 (196.233.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.233.196 (196.233.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:25:12.973171 2026] [security2:error] [pid 16436:tid 16517] [client 35.201.233.196:45280] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.love-spells-magic.com"] [uri "/@fs/../.env"] [unique_id "aqFCGO6Ee8pfLrfT0qkrDAAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 10:48:28
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.233.196 (196.233.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.233.196 (196.233.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 06:48:23.028190 2026] [security2:error] [pid 22905:tid 22905] [client 35.201.233.196:60092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dev.budgetguard.com"] [uri "/@fs/root/.env"] [unique_id "aqE5d_UtGhtSDfef8oUztwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-09 10:35:52
(5 hours ago)
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 (compatible; Ama ...
show more
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot) (+1 more) | path: /@fs/../../.env (+10 more) | 2026-09-09 10:35 UTC
show less
Bad Web Bot
🇫🇷
Stara
2026-09-09 10:35:40
(5 hours ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 10:22:30
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.233.196 (196.233.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.233.196 (196.233.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 06:22:22.397007 2026] [security2:error] [pid 6949:tid 6949] [client 35.201.233.196:11228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.camouflagebikinis.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqEzXn0tGY0SDGub-5lEygAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-09 10:18:00
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
NXTwoThou
2026-09-09 09:52:00
(6 hours ago)
/@fs/../../.env%3Fraw%3F%3F
Web App Attack
🇺🇸
dot.mg
2026-09-09 09:21:03
(7 hours ago)
Bad behaviour
Web Spam
🇳🇱
Site.eu
2026-09-09 09:16:22
(7 hours ago)
Excessive multi-domain requests
Brute-Force