๐ฉ๐ช
HoneyPot-FrPri
2026-08-28 20:44:28
(4 minutes ago)
35.229.18.104 - - fru.[redacted] [28/Aug/2026:22:44:27 +0200] "GET /.env.backup HTTP/1.1" 404 153 "- ...
show more
35.229.18.104 - - fru.[redacted] [28/Aug/2026:22:44:27 +0200] "GET /.env.backup HTTP/1.1" 404 153 "-" "crusader-worker/1.0" 0.000 - -
35.229.18.104 - - fru.[redacted] [28/Aug/2026:22:44:27 +0200] "GET /
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 20:07:14
(42 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.229.18.104 (104.18.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.18.104 (104.18.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:07:09.346234 2026] [security2:error] [pid 28476:tid 28476] [client 35.229.18.104:59846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gunningphysio.com"] [uri "/.env.example"] [unique_id "apHqbQ_cqO1AsejiXvRjbgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 19:51:34
(57 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.229.18.104 (104.18.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.18.104 (104.18.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:51:27.904024 2026] [security2:error] [pid 8079:tid 8079] [client 35.229.18.104:43102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chubat.com"] [uri "/.env"] [unique_id "apHmv4u5GsaD_zIuGPBvdwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:31:33
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.18.104 (104.18.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.18.104 (104.18.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:31:29.960304 2026] [security2:error] [pid 791:tid 791] [client 35.229.18.104:51144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "onlyincanada-eh.com"] [uri "/.env.bak"] [unique_id "apHUATt_QHqce_1UWGNn0QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 18:14:12
(2 hours ago)
Bot / seems abusive / Apache connections: 25
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 17:40:02
(3 hours ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
Dennis
2026-08-28 17:29:50
(3 hours ago)
35.229.18.104 has been banned for triggering http-sensitive-files (5 events over 7.220059ms).
Brute-Force
Web App Attack
Anonymous
2026-08-28 15:42:43
(5 hours ago)
[ssd5.kdns.gr] httpd-config-scan: sites=www.hparxo.gr; logs=/var/log/httpd/domains/hparxo.gr.log; sa ...
show more
[ssd5.kdns.gr] httpd-config-scan: sites=www.hparxo.gr; logs=/var/log/httpd/domains/hparxo.gr.log; samples=/.env.dev | /wp-config.php~ | /.env.prod
show less
Hacking
Web App Attack
Anonymous
2026-08-28 15:10:04
(5 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.save HTTP/1.1, GET /actuator/configprops HTTP/1.1, ...
show more
Bot / scanning and/or hacking attempts: GET /.env.save HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /actuator/env HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env HTTP/1.1, GET /.env.production HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /.env.bak HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /env HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.env.example HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /.env.local HTTP/1.1
show less
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-08-28 14:16:49
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-28 14:08:41
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
e.fierstra
2026-08-28 13:09:23
(7 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 12:50:07
(7 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 12:18:32
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.18.104 (104.18.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.18.104 (104.18.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:18:24.631007 2026] [security2:error] [pid 31222:tid 31222] [client 35.229.18.104:52782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.acraloc.com"] [uri "/.env.local"] [unique_id "apF8kNcKvkiZKURskPIQbAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-28 12:06:35
(8 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack