🇫🇷
Zundapper
2026-09-08 12:59:42
(3 hours ago)
35.221.104.172 - - [08/Sep/2026:14:58:48 +0200] "GET /@fs/var/www/html/wp-config.php?raw?? HTTP/1.1" ...
show more
35.221.104.172 - - [08/Sep/2026:14:58:48 +0200] "GET /@fs/var/www/html/wp-config.php?raw?? HTTP/1.1" 404 27 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko; compatible; LinkedInBot/1.0; +http://www.linkedin.com) Version/19.0 Safari/605.1.15"
35.221.104.172 - - [08/Sep/2026:14:59:07 +0200] "GET /config/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.979.151 Safari/537.36; compatible; ClaudeBot/1.0; [email protected] "
35.221.104.172 - - [08/Sep/2026:14:59:35 +0200] "GET /wp-config.php HTTP/1.1" 404 27 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)"
35.221.104.172 - - [08/Sep/2026:14:59:42 +0200] "GET /config/database.yml HTTP/1.1" 404 146 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
35.221.104.172 - - [08/Sep/2026:14:59:42
...
show less
Web App Attack
Port Scan
🇺🇸
TPI-Abuse
2026-09-08 11:44:43
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.104.172 (172.104.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.104.172 (172.104.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:44:39.575829 2026] [security2:error] [pid 32331:tid 32331] [client 35.221.104.172:16058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.cartiologyfilms.com"] [uri "/@fs/.env"] [unique_id "ap_1J9sXfYxhA-SHd87uHQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:29:02
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.104.172 (172.104.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.104.172 (172.104.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:28:56.851468 2026] [security2:error] [pid 23744:tid 23744] [client 35.221.104.172:16416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.informant-systems.com"] [uri "/@fs/.env"] [unique_id "ap_xeOIV2gtYapK8Jf8J4wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
taivas.nl
2026-09-08 11:02:11
(5 hours ago)
Bad_requests
Bad Web Bot
🇪🇸
librebit
2026-09-08 10:59:40
(5 hours ago)
Bad guys doing bad things, bad crawling
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 10:36:18
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.104.172 (172.104.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.104.172 (172.104.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:36:12.458676 2026] [security2:error] [pid 7407:tid 7407] [client 35.221.104.172:40506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.diamondtrailerserv.com"] [uri "/@fs/../../.env"] [unique_id "ap_lHPyq0lU-xFLNtobRuQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇬
Cloudkul Cloudkul
2026-09-08 10:24:29
(5 hours ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
🇵🇱
Budyn
2026-09-08 10:24:23
(5 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: test.budyn.ovh | URI: /@fs/root/.aws/credentials.bak?raw?? | UA: Mozilla/5.0 (compatible; Slackbot-LinkExpanding/1.0; +https://api.slack.com/robots) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:17:00
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.104.172 (172.104.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.104.172 (172.104.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:16:54.335601 2026] [security2:error] [pid 30415:tid 30415] [client 35.221.104.172:21190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "axiomcommercial.com"] [uri "/@fs/root/.env"] [unique_id "ap_glufPR-FDjLX1oY-OTgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:38:13
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.104.172 (172.104.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.104.172 (172.104.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:38:10.520399 2026] [security2:error] [pid 29396:tid 29396] [client 35.221.104.172:20728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.montebiancoltd.com"] [uri "/@fs/src/.env"] [unique_id "ap_Xgj-q1kGRm1PT9uEC0QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-08 09:26:16
(6 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-08 09:17:23
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:09:38
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.104.172 (172.104.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.104.172 (172.104.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:09:30.471044 2026] [security2:error] [pid 1714852:tid 1715251] [client 35.221.104.172:43418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.plumberw9.com"] [uri "/@fs/.env"] [unique_id "ap_QyhOHGUIw6XcWdwopVgAAAUA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-08 08:43:55
(7 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:44:11
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.104.172 (172.104.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.104.172 (172.104.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:44:06.512193 2026] [security2:error] [pid 1496:tid 1496] [client 35.221.104.172:4790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.podbillspec.com"] [uri "/@fs/app/.env"] [unique_id "ap-8xtLZ7c50n6QGFHy5UwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack