Anonymous
2026-09-21 05:50:01
(1 day ago)
35.221.222.53 - - [20/Sep/2026:07:23:38 -0500] "GET /.env.old HTTP/1.1" 301 247 "-" "Mozilla/5.0 (co ...
show more
35.221.222.53 - - [20/Sep/2026:07:23:38 -0500] "GET /.env.old HTTP/1.1" 301 247 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" 172.68.87.62
35.221.222.53 - - [20/Sep/2026:07:23:39 -0500] "GET /.env.old HTTP/1.1" 403 199 "http://synapseresults.com/.env.old" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" 162.158.193.168
35.221.222.53 - - [20/Sep/2026:07:23:42 -0500] "GET /.env.live HTTP/1.1" 301 248 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" 172.68.87.62
35.221.222.53 - - [20/Sep/2026:07:23:42 -0500] "GET /.env.www HTTP/1.1" 301 247 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 172.68.87.63
35.221.222.53 - - [20/Sep/2026:07:23:42 -0500] "GET /.env.live HTTP/1.1" 403 199 "http://synapseresults.com/.env.live" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" 162.158.193.169
35.221.222.53 - - [20/Sep/2026:07:23:42 -0500] "GET /.env.prod HTTP/1.1" 301 248 "-
...
show less
Brute-Force
Bad Web Bot
Web App Attack
π²π½
octageeks.com
2026-09-21 04:15:47
(1 day ago)
Wordpress malicious attack:[octablocked]
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 15:10:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.221.222.53 (53.222.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.222.53 (53.222.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:10:28.209391 2026] [security2:error] [pid 30039:tid 30039] [client 35.221.222.53:49690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theradarshop.com"] [uri "/deploy/.env"] [unique_id "aq_3ZMQtUfrdDywGFlxzWQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 14:01:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.221.222.53 (53.222.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.222.53 (53.222.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:01:50.133492 2026] [security2:error] [pid 32234:tid 32234] [client 35.221.222.53:41464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thepinelandclub.com"] [uri "/.env.local"] [unique_id "aq_nTqipcJvCtUH4XUau9AAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
NotCool
2026-09-20 13:37:06
(1 day ago)
(CRAWLDELAY) Generic Bot Crawl-delay Violation 35.221.222.53 (TW/Taiwan/53.222.221.35.bc.googleuserc ...
show more
(CRAWLDELAY) Generic Bot Crawl-delay Violation 35.221.222.53 (TW/Taiwan/53.222.221.35.bc.googleusercontent.com): 50 in the last 3600 secs
show less
Bad Web Bot
π«π·
dynamix
2026-09-20 13:34:22
(1 day ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 12:53:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.221.222.53 (53.222.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.222.53 (53.222.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:53:16.778147 2026] [security2:error] [pid 12626:tid 12626] [client 35.221.222.53:32964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thenotarymobile.com"] [uri "/.git/HEAD"] [unique_id "aq_XPNiKn2MhFfvcdejsHwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-09-20 12:43:49
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-09-20 12:22:59
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.221.222.53 (53.222.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.222.53 (53.222.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:22:54.663812 2026] [security2:error] [pid 30661:tid 30704] [client 35.221.222.53:38762] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stratifiedstudios.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stratifiedstudios.com"] [uri "/z9x8c7v6b5-debug-trigger-stratifiedstudios.com"] [unique_id "aq_QHp4BAY53048uloiCzAAAAMM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 11:59:23
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.221.222.53 (53.222.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.222.53 (53.222.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 07:59:18.963939 2026] [security2:error] [pid 22246:tid 22246] [client 35.221.222.53:42996] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kevinfranz.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kevinfranz.com"] [uri "/z9x8c7v6b5-debug-trigger-kevinfranz.com"] [unique_id "aq_Kll29AMac2wJzh4R69AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
bazter.pro
2026-09-20 11:45:54
(1 day ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 11:39:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.221.222.53 (53.222.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.222.53 (53.222.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 07:39:13.396422 2026] [security2:error] [pid 10437:tid 10437] [client 35.221.222.53:44904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drxcontent.com"] [uri "/.env.bak"] [unique_id "aq_F4bd5N8yQj0hEyg2TKgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
demomodule
2026-09-20 11:37:21
(1 day ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
πΊπΈ
factor1
2026-09-20 11:37:16
(1 day ago)
CrowdSec at apollo Reports Abuse
Web App Attack
Anonymous
2026-09-20 11:29:13
(1 day ago)
git/env leak probe
Web App Attack