๐ช๐ธ
robotstxt
2026-09-30 19:11:06
(4 days ago)
35.189.162.132 - - [30/Sep/2026:19:10:49 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 81383 "https ...
show more
35.189.162.132 - - [30/Sep/2026:19:10:49 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 81383 "https://cool-dreams.com/.vite/manifest.json" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.189.162.132"
35.189.162.132 - - [30/Sep/2026:19:10:50 +0000] "GET /.ssh/config HTTP/2.0" 403 82828 "https://cool-dreams.com/.ssh/config" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot" "-" edge="35.189.162.132"
35.189.162.132 - - [30/Sep/2026:19:10:50 +0000] "GET /.ssh/id_ed25519 HTTP/2.0" 403 82835 "https://cool-dreams.com/.ssh/id_ed25519" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" "-" edge="35.189.162.132"
35.189.162.132 - - [30/Sep/2026:19:10:52 +0000] "GET /.zshrc HTTP/2.0" 403 82834 "https://cool-dreams.com/.zshrc" "M
...
show less
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-30 17:47:56
(4 days ago)
[cb-13al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-13al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.189.162.132 - - [30/Sep/2026:19:47:42 +0200] "GET /.htpasswd HTTP/2.0" 403 1862 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-30 17:42:02
(4 days ago)
20 attempts against mh-misbehave-ban on mensa
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 17:04:39
(4 days ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 16:13:29
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 35.189.162.132 (132.162.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.189.162.132 (132.162.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 12:13:20.680812 2026] [security2:error] [pid 5391:tid 5391] [client 35.189.162.132:47328] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||terrybeachmusic.danged.com|F|2"] [data ".danged.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "terrybeachmusic.danged.com"] [uri "/z9x8c7v6b5-debug-trigger-terrybeachmusic.danged.com"] [unique_id "ar01IHQM0yn8jTQSG0dZGgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:30:11
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.189.162.132 (132.162.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.162.132 (132.162.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:30:04.406063 2026] [security2:error] [pid 28298:tid 28298] [client 35.189.162.132:56070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "altruaglobalsolutions.com"] [uri "/.env.js"] [unique_id "ar0c7N8PRP5Y6NcmmXu1HwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Mediashaker
2026-09-30 14:17:47
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted] 35.189.162.132 (TW/Taiwan/132.162.189.3 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.189.162.132 (TW/Taiwan/132.162.189.35.bc.googleusercontent.com)
show less
SQL Injection
๐ซ๐ท
masterguru
2026-09-30 13:58:37
(4 days ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-201)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-30 13:38:30
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 35.189.162.132 (132.162.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.189.162.132 (132.162.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:38:27.923993 2026] [security2:error] [pid 25511:tid 25525] [client 35.189.162.132:43752] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||teanaunz.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "teanaunz.com"] [uri "/z9x8c7v6b5-debug-trigger-teanaunz.com"] [unique_id "ar0Q090c_B2kDkayPQVYaAAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:21:17
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 35.189.162.132 (132.162.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.189.162.132 (132.162.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:21:13.509268 2026] [security2:error] [pid 17214:tid 17214] [client 35.189.162.132:45100] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||technicallydental.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "technicallydental.com"] [uri "/z9x8c7v6b5-debug-trigger-technicallydental.com"] [unique_id "ar0MyXNF9TPxHiflgzeBogAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:52:21
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.189.162.132 (132.162.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.162.132 (132.162.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:52:16.616070 2026] [security2:error] [pid 885:tid 885] [client 35.189.162.132:42228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.televisonic.com"] [uri "/api/.env/public/.env"] [unique_id "ar0GAKGwX9FkqFwqqY4HXwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:08:35
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.189.162.132 (132.162.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.162.132 (132.162.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:08:31.452307 2026] [security2:error] [pid 2324:tid 2324] [client 35.189.162.132:55512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.needtoorder.com"] [uri "/.git/HEAD"] [unique_id "arz7v5Mx7C5c-06LXuIDWgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-30 11:50:08
(4 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:44:56
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 35.189.162.132 (132.162.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.189.162.132 (132.162.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:44:53.498297 2026] [security2:error] [pid 3930:tid 3930] [client 35.189.162.132:32886] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||tenderloinbeautiful.sfgardening.com|F|2"] [data ".sfgardening.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tenderloinbeautiful.sfgardening.com"] [uri "/z9x8c7v6b5-debug-trigger-tenderloinbeautiful.sfgardening.com"] [unique_id "arz2NSqqcC6RwA4j6m57gAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 10:55:49
(4 days ago)
malicious scanning tool activity
Web App Attack