🇩🇪
HoneyPot-FrPri
2026-09-07 12:28:23
(14 hours ago)
35.220.232.253 - - 181.214.99.65 [07/Sep/2026:14:28:23 +0200] "GET /.env.local HTTP/1.1" 404 153 "-" ...
show more
35.220.232.253 - - 181.214.99.65 [07/Sep/2026:14:28:23 +0200] "GET /.env.local HTTP/1.1" 404 153 "-" "crusader-worker/1.0" 0.000 - -
35.220.232.253 - - 181.214.99.65 [07/Sep/2026:14:28:23 +0200] "GET
...
show less
Bad Web Bot
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-06 13:34:27
(1 day ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-stl2-13)
show less
Hacking
🇦🇺
Starburst SysOp Team
2026-09-06 06:13:08
(1 day ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-syd2-4)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-06 03:53:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.220.232.253 (253.232.220.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.232.253 (253.232.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:53:31.117695 2026] [security2:error] [pid 29487:tid 29487] [client 35.220.232.253:52616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.richmondrents.com"] [uri "/.env.prod"] [unique_id "apzju50GWZeQXMrt3laCVgAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 03:38:04
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:35:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.220.232.253 (253.232.220.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.232.253 (253.232.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:35:27.371315 2026] [security2:error] [pid 28938:tid 28938] [client 35.220.232.253:43478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pr-professional.com"] [uri "/.env.save"] [unique_id "apzff0lkMEY5SkwV8oqE6wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Lee Daniel
2026-09-06 03:27:41
(1 day ago)
35.220.232.253 - - [05/Sep/2026:23:27:40 -0400] "GET /.env HTTP/1.1" 403 6302 "-" "crusader-worker/1 ...
show more
35.220.232.253 - - [05/Sep/2026:23:27:40 -0400] "GET /.env HTTP/1.1" 403 6302 "-" "crusader-worker/1.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:56:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.220.232.253 (253.232.220.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.232.253 (253.232.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:56:46.025848 2026] [security2:error] [pid 13481:tid 13481] [client 35.220.232.253:47362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.pinebrookdesign.com"] [uri "/wp-config.php.swp"] [unique_id "apzWbgHd733z3beqZZ7IQgAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-06 02:01:17
(2 days ago)
[05/Sep/2026:22:01:17.110008 --0400] apzJbR3ViE1vjLY9Afo0bgAAA5Q 35.220.232.253 59708 205.233.18.17 ...
show more
[05/Sep/2026:22:01:17.110008 --0400] apzJbR3ViE1vjLY9Afo0bgAAA5Q 35.220.232.253 59708 205.233.18.17 7081
[05/Sep/2026:22:01:17.110823 --0400] apzJbenkF3EQX2VX6UlrwQAAAIc 35.220.232.253 59712 205.233.18.17 7081
[05/Sep/2026:22:01:17.114090 --0400] apzJbZrbzrMb5qC8DBndEwAAARc 35.220.232.253 59738 205.233.18.17 7081
[05/Sep/2026:22:01:17.115015 --0400] apzJbenkF3EQX2VX6UlrwgAAAJg 35.220.232.253 59754 205.233.18.17 7081
[05/Sep/2026:22:01:17.125130 --0400] apzJbenkF3EQX2VX6UlrwwAAAJE 35.220.232.253 59798 205.233.18.17 7081
...
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-06 01:56:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.220.232.253 (253.232.220.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.232.253 (253.232.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:56:48.070471 2026] [security2:error] [pid 14511:tid 14511] [client 35.220.232.253:41796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ashotofcoffee.com"] [uri "/.env.production"] [unique_id "apzIYHgOqEBgYTOwXMKpDwAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
✨
2026-09-06 01:12:12
(2 days ago)
Domain : coventryboysclub.com
Rule : env
2026-09-06 01:10:40 W3SVC317 PLESK72 79.171.39.6 GET /.env. ...
show more
Domain : coventryboysclub.com
Rule : env
2026-09-06 01:10:40 W3SVC317 PLESK72 79.171.39.6 GET /.env.production - 80 - 35.220.232.253 HTTP/1.1 crusader-worker/1.0 - - coventryboysclub.com 404 0 2 393 107 257 - -
show less
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 00:47:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.220.232.253 (253.232.220.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.232.253 (253.232.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:47:44.854255 2026] [security2:error] [pid 15462:tid 15462] [client 35.220.232.253:43028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.glslightingandcontrols.com"] [uri "/.env.local"] [unique_id "apy4MHV3fGA2KdcqsVPmEwAAAHs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:56:55
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.220.232.253 (253.232.220.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.232.253 (253.232.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:56:49.543860 2026] [security2:error] [pid 21242:tid 21242] [client 35.220.232.253:44000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.leonardodecaprio.com"] [uri "/.env.backup"] [unique_id "apysQU8OrvZqnVsyX9EHJwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:26:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.220.232.253 (253.232.220.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.232.253 (253.232.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:26:10.299948 2026] [security2:error] [pid 22046:tid 22075] [client 35.220.232.253:41646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.mailme.name"] [uri "/.htaccess"] [unique_id "apylEmjU7nGdeZkaUZX7DAAAAM8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 22:57:20
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking