🇫🇷
masterguru
2026-09-04 11:21:24
(1 hour ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
🇫🇷
Baking333
2026-09-04 10:35:35
(1 hour ago)
[redacted] 35.221.82.244 - - [04/Sep/2026:11:35:33 +0100] "GET /@fs/app/.aws/credentials?raw?? HTTP/ ...
show more
[redacted] 35.221.82.244 - - [04/Sep/2026:11:35:33 +0100] "GET /@fs/app/.aws/credentials?raw?? HTTP/1.1" 302 6773 0/70020 "-" "Mozilla/5.0 (compatible; Claude-SearchBot/1.0; +https://[redacted]/claude-searchbot)" [redacted] 35.221.82.244 - - [04/Sep/2026:11:35:33 +0100] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.1" 302 6773 0/86264 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://[redacted]/grokbot)" [redacted] 35.221.82.244 - - [04/Sep/2026:11:35:33 +0100] "GET /@fs/home/node/.aws/config?raw?? HTTP/1.1" 302 6773 0/82747 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.4681.28 Safari/537.36; compatible; Perplexity-User/1.0; +https://[redacted]/perplexity-user"
show less
Bad Web Bot
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-04 10:18:24
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.221.82.244 (JP/Japan/244.82.221.35.b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.221.82.244 (JP/Japan/244.82.221.35.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-04 09:29:21
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.82.244 (244.82.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.82.244 (244.82.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:29:16.177234 2026] [security2:error] [pid 22684:tid 22684] [client 35.221.82.244:22156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.desertdwellings.com"] [uri "/@fs/src/.env"] [unique_id "apqPbJ8hbHKgsg6BYOySkQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:57:03
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.82.244 (244.82.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.82.244 (244.82.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:56:58.512252 2026] [security2:error] [pid 408086:tid 408086] [client 35.221.82.244:12602] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cor-ex.com"] [uri "/@fs/.env"] [unique_id "apqH2vBUP1lZgrOEnTt_GQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:37:08
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.82.244 (244.82.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.82.244 (244.82.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:37:03.376103 2026] [security2:error] [pid 6491:tid 6491] [client 35.221.82.244:30678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "billfried.net"] [uri "/@fs/.env"] [unique_id "apqDL5vTdLkBHK5LXczL2QAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
palzer.IT
2026-09-04 08:29:04
(3 hours ago)
Fail2ban automatic report for plesk-apache-badbot: 35.221.82.244 - - [04/Sep/2026:10:28:50 +0200] GE ...
show more
Fail2ban automatic report for plesk-apache-badbot: 35.221.82.244 - - [04/Sep/2026:10:28:50 +0200] GET /@fs/home/debian/.aws/credentials?raw?? [DOMAIN_REMOVED] 404 6335 [DOMAIN_REMOVED] Mozilla/5.0 (compatible; PerplexityBot/1.0; +[DOMAIN_REMOVED]
show less
Bad Web Bot
Anonymous
2026-09-04 08:05:03
(4 hours ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
🇩🇪
4server
2026-09-04 07:51:18
(4 hours ago)
[FriSep0409:51:15.1376692026][security2:error][pid4053276:tid4053400][client35.221.82.244:0]ModSecur ...
show more
[FriSep0409:51:15.1376692026][security2:error][pid4053276:tid4053400][client35.221.82.244:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"/etc/passwd\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"141\"][id\"347009\"][rev\"1\"][msg\"Atomicorp.comWAFRules:ProtectedFileaccessdenied\"][severity\"CRITICAL\"][hostname\"webmail.dsfiduciaria.ch\"][uri\"/@fs/etc/passwd\"][unique_id\"app4c1rAJ66ScCUu4G8SSwAAAUU\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:47:20
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.82.244 (244.82.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.82.244 (244.82.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:47:12.914327 2026] [security2:error] [pid 8573:tid 8573] [client 35.221.82.244:12522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.templegardens.org"] [uri "/@fs/root/.env"] [unique_id "app3gBs5ZFg4pZrMEwFDpQAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:21:15
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.82.244 (244.82.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.82.244 (244.82.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:21:09.707509 2026] [security2:error] [pid 25509:tid 25509] [client 35.221.82.244:29028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.myduraluxepanel.ipostsocialmedia.com"] [uri "/@fs/root/.env"] [unique_id "appxZS_G7g-vNOkF1p2dNQAAAGM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
user-01
2026-09-04 07:14:06
(5 hours ago)
Multiple WAF violations
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 05:50:03
(6 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:47:07
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.82.244 (244.82.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.82.244 (244.82.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:46:59.089396 2026] [security2:error] [pid 19570:tid 19590] [client 35.221.82.244:3376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.djkirby.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "appbU4ATf_ZZpZvaRJmirwAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 04:36:25
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.82.244 (244.82.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.82.244 (244.82.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:36:19.388257 2026] [security2:error] [pid 30266:tid 30266] [client 35.221.82.244:33060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jfhglobal.net"] [uri "/@fs/.env"] [unique_id "appKw9T30ESgIgLQS5PwWgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack