Anonymous
2026-06-15 07:54:35
(6 hours ago)
[server.tmg.gr] httpd-suspicious-path: sites=cardioathena2025.gr; logs=/var/log/httpd/domains/cardio ...
show more
[server.tmg.gr] httpd-suspicious-path: sites=cardioathena2025.gr; logs=/var/log/httpd/domains/cardioathena2025.gr.log; samples=/.env.qa | /api/.env.staging | /app/.env.backup
show less
Hacking
Web App Attack
๐ฉ๐ช
updown.io
2026-06-15 07:06:44
(7 hours ago)
{"level":"info","ts":1781507203.8090193,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1781507203.8090193,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.222.161.219","remote_port":"55880","client_ip":"35.222.161.219","proto":"HTTP/1.1","method":"GET","host":"1update.dgnvuwww.www.www.www.status.quarks-erp.com","uri":"/.env.production.bak","headers":{"User-Agent":["Mozilla/5.0 (Linux; U; Android 4.1; en-us; sdk Build/MR1) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.1 Safari/534.30"],"Accept-Charset":["utf-8"],"Accept-Encoding":["gzip"],"Connection":["close"]}},"bytes_read":0,"user_id":"","duration":0.000078469,"size":0,"status":308,"resp_headers":{"Connection":["close"],"Location":["https://1update.dgnvuwww.www.www.www.status.quarks-erp.com/.env.production.bak"],"Content-Type":[],"Server":["Caddy"]}}
{"level":"info","ts":1781507203.841627,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.222.161.219","remote_port":"55908","client_ip":"35.222.161.219","proto":"HTTP/1.1","method":"
...
show less
DDoS Attack
Web App Attack
๐ณ๐ฑ
Cloud86 B.V.
2026-06-15 03:00:04
(11 hours ago)
categories: DDoS Attack
DDoS Attack
๐ฎ๐น
clamehost.it
2026-06-15 01:11:48
(13 hours ago)
Automatic report - Brute Force attack using this IP address
Brute-Force
๐ณ๐ฑ
Site.eu
2026-06-15 00:48:37
(14 hours ago)
Excessive multi-domain requests
Brute-Force
๐ฎ๐น
eliosbrocchi
2026-06-14 22:04:37
(16 hours ago)
35.222.161.219 - - [15/Jun/2026:00:04:34 +0200] "GET /production/.env HTTP/1.1" 404 3377 "-" "Mozill ...
show more
35.222.161.219 - - [15/Jun/2026:00:04:34 +0200] "GET /production/.env HTTP/1.1" 404 3377 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"
...
show less
VPN IP
๐บ๐ธ
TPI-Abuse
2026-06-14 21:03:06
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.222.161.219 (219.161.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.222.161.219 (219.161.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 17:03:00.645269 2026] [security2:error] [pid 2672:tid 2717] [client 35.222.161.219:40070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "honorac.com"] [uri "/backend/.env.bak"] [unique_id "ai8XBP3qJcz_w3fzmb15zwAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
mediarama.com
2026-06-14 17:25:56
(21 hours ago)
Banned by Fail2Ban
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-06-14 15:30:29
(23 hours ago)
20 attempts against mh-misbehave-ban on storm
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-06-14 12:32:42
(1 day ago)
Too many 404 requests [BY]
Web App Attack
๐บ๐ธ
alecj.com
2026-06-14 12:03:03
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ธ๐ช
nekopavel
2026-06-14 03:17:24
(1 day ago)
35.222.161.219 - - [14/Jun/2026:05:17:20 +0200]"GET /.env.sample HTTP/1.1" 404 118"-" autoconfig.nek ...
show more
35.222.161.219 - - [14/Jun/2026:05:17:20 +0200]"GET /.env.sample HTTP/1.1" 404 118"-" autoconfig.neko.chat "Mozilla/5.0 (SymbianOS/9.4; U; Series60/5.0 SonyEricssonP100/01; Profile/MIDP-2.1 Configuration/CLDC-1.1) AppleWebKit/525 (KHTML, like Gecko) Version/3.0 Safari/525""0.000" "0.001""Council Bluffs" "US"
35.222.161.219 - - [14/Jun/2026:05:17:20 +0200]"GET /.env.local.bak HTTP/1.1" 404 118"-" autoconfig.neko.chat "Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Firefox/38.0 Iceweasel/38.2.1""0.001" "0.000""Council Bluffs" "US"
35.222.161.219 - - [14/Jun/2026:05:17:20 +0200]"GET /.env.copy HTTP/1.1" 404 178"-" autoconfig.neko.chat "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.145 Safari/537.36 Vivaldi/2.6.1566.49""0.001" "0.000""Council Bluffs" "US"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-06-14 03:07:27
(1 day ago)
Web vulnerability probing: /.env.backup
Web App Attack
๐ง๐ท
dominioz
2026-06-14 02:49:15
(1 day ago)
2026-06-14 02:48:22 GET /api/v3/.env - - 35.222.161.219 HTTP/1.1 Mozilla/5.0+(X11;+Linux+i686)+Apple ...
show more
2026-06-14 02:48:22 GET /api/v3/.env - - 35.222.161.219 HTTP/1.1 Mozilla/5.0+(X11;+Linux+i686)+AppleWebKit/535.1+(KHTML,+like+Gecko)+Ubuntu/11.04+Chromium/14.0.825.0+Chrome/14.0.825.0+Safari/535.1 - 301 585
2026-06-14 02:48:22 GET /v2/.env - - 35.222.161.219 HTTP/1.1 Nokia6230i/2.0+(03.80)+Profile/MIDP-2.0+Configuration/CLDC-1.1 - 301 577
2026-06-14 02:48:22 GET /api/v2/.env - - 35.222.161.219 HTTP/1.1 Mozilla/5.0+(X11;+U;+Linux+i686;+pt-PT;+rv:1.9.2.3)+Gecko/20100402+Iceweasel/3.6.3+(like+Firefox/3.6.3)+GTB7.0 - 301 585
2026-06-14 02:48:22 GET /v1/.env - - 35.222.161.219 HTTP/1.1 Mozilla/5.0+(X11;+U;+Linux+x86_64;+en-gb)+AppleWebKit/534.35+(KHTML,+like+Gecko)+Chrome/11.0.696.65+Safari/534.35+Puffin/2.9174AP - 301 577
...
show less
Web App Attack
๐ฆ๐บ
afleventoffice.com.au
2026-06-13 09:30:28
(2 days ago)
\x16\x03\x01
Web App Attack