Anonymous
2026-09-06 06:31:55
(1 hour ago)
Too many successive quick attempts with error status 301, 404, 405, 444, 403 or 400
Bad Web Bot
🇬🇧
openstrike.co.uk
2026-09-06 05:13:04
(3 hours ago)
11 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php.bak HTTP/1.1
GET /.env.local HTTP/1.1
Web App Attack
Hacking
🇬🇧
Apache
2026-09-06 03:53:45
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.47.94 (US/United States/94.47.229.35.bc. ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.47.94 (US/United States/94.47.229.35.bc.googleusercontent.com): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:51:04
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.47.94 (94.47.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.47.94 (94.47.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:50:55.471169 2026] [security2:error] [pid 28361:tid 28361] [client 35.229.47.94:36784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.saratogaequity.com"] [uri "/.env"] [unique_id "apzjHxLt0biKFzwW3hfPgQAAAGY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
SkyDancer
2026-09-06 03:40:01
(4 hours ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
🇩🇪
itsolon
2026-09-06 03:04:59
(5 hours ago)
[06/Sep/2026:05:04:58 +0200] 17886638987.884739 35.229.47.94 40862 217.154.7.177 443
[06/Sep/2026:05 ...
show more
[06/Sep/2026:05:04:58 +0200] 17886638987.884739 35.229.47.94 40862 217.154.7.177 443
[06/Sep/2026:05:04:58 +0200] 178866389845.989545 35.229.47.94 40868 217.154.7.177 443
[06/Sep/2026:05:04:58 +0200] 178866389851.112861 35.229.47.94 40806 217.154.7.177 443
[06/Sep/2026:05:04:58 +0200] 178866389813.931554 35.229.47.94 40782 217.154.7.177 443
[06/Sep/2026:05:04:58 +0200] 178866389815.427394 35.229.47.94 40710 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:00:59
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.47.94 (94.47.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.47.94 (94.47.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:00:51.528575 2026] [security2:error] [pid 26204:tid 26213] [client 35.229.47.94:34184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.dermatologycoloradosprings.com"] [uri "/.env.example"] [unique_id "apzXY9BbnM4DZJ7oJiN2YgAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
todix
2026-09-06 02:59:40
(5 hours ago)
Web App Attack Exploid from 35.229.47.94
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:30:12
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.47.94 (94.47.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.47.94 (94.47.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:30:07.661696 2026] [security2:error] [pid 14059:tid 14059] [client 35.229.47.94:40546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fluff.thewaywework.com"] [uri "/wp-config.php.swp"] [unique_id "apzCHwfOuiV0fv0sIQnk5wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
paissangroup
2026-09-06 01:13:03
(7 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:02:01
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.47.94 (94.47.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.47.94 (94.47.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:01:53.051286 2026] [security2:error] [pid 17950:tid 17950] [client 35.229.47.94:48504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "email.semisysteme.com"] [uri "/.env.local"] [unique_id "apy7gTPsEEdCoyYCRGzvVgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:34:49
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.47.94 (94.47.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.47.94 (94.47.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:34:41.309255 2026] [security2:error] [pid 11512:tid 11512] [client 35.229.47.94:38286] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boat-registration-hong-kong.com"] [uri "/.env"] [unique_id "apy1IY8D-pIBnb0BlIssfgAAADw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-06 00:28:42
(7 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:09:25
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.47.94 (94.47.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.47.94 (94.47.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:09:19.976382 2026] [security2:error] [pid 3505653:tid 3505693] [client 35.229.47.94:47788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nopictures.org"] [uri "/.env.local"] [unique_id "apyvL5t-xs6dfcnCXm51aQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇷
Peregrine
2026-09-06 00:04:20
(8 hours ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 35.229.47.94 104.22.56.24 - - [05/Sep/2026:21:04:16 -0300 ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 35.229.47.94 104.22.56.24 - - [05/Sep/2026:21:04:16 -0300] "GET /.env HTTP/1.1" 404 414
35.229.47.94 104.22.24.154 - - [05/Sep/2026:21:04:16 -0300] "GET /.env.bak HTTP/1.1" 404 414
35.229.47.94 104.22.56.24 - - [05/Sep/2026:21:04:16 -0300] "GET /.env.save HTTP/1.1" 404 414
35.229.47.94 172.71.23.39 - - [05/Sep/2026:21:04:16 -0300] "GET /.env.dev HTTP/1.1" 404 414
35.229.47.94 104.22.56.24 - - [05/Sep/2026:21:04:16 -0300] "GET /.env.backup HTTP/1.1" 404 414
35.229.47.94 172.71.31.154 - - [05/Sep/2026:21:04:16 -0300] "GET /.env.local HTTP/1.1" 404 414
35.229.47.94 104.22.56.25 - - [05/Sep/2026:21:04:16 -0300] "GET /.env.prod HTTP/1.1" 404 414
35.229.47.94 104.23.245.195 - - [05/Sep/2026:21:04:16 -0300] "GET /.env.old HTTP/1.1" 404 414
35.229.47.94 172.71.23.39 - - [05/Sep/2026:21:04:16 -0300] "GET /.env.example HTTP/1.1" 404 414
35.229.47.94 172.71.23.39 - - [05/Sep/2026:21:04:16 -0300] "GET /.env.production HTTP/1.1" 404 414
show less
Bad Web Bot