๐ฉ๐ช
thesimonmanuel
2026-09-21 06:05:44
(17 hours ago)
35.194.202.202 - - [21/Sep/2026:11:35:44 +0530] "GET /.aws/config HTTP/2.0" 404 548 "-" "Mozilla/5.0 ...
show more
35.194.202.202 - - [21/Sep/2026:11:35:44 +0530] "GET /.aws/config HTTP/2.0" 404 548 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" "-"
show less
Web App Attack
๐ซ๐ท
masterguru
2026-09-21 04:55:48
(18 hours ago)
Restricted File Access Attempt. Matched phrase "config.json" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-09-21 03:21:11
(19 hours ago)
OS File Access Attempt. Matched phrase "proc/self" at ARGS:0. (930120-195)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 03:16:57
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.194.202.202 (202.202.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.202.202 (202.202.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:16:53.918493 2026] [security2:error] [pid 14206:tid 14308] [client 35.194.202.202:58010] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.petsentiments.com|F|2"] [data ".petsentiments.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.petsentiments.com"] [uri "/z9x8c7v6b5-debug-trigger-www.petsentiments.com"] [unique_id "arChpVM7tXT2LoZ3Yl4Q9gAAAc0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-09-21 03:09:01
(20 hours ago)
35.194.202.202 - - [21/Sep/2026:11:08:59 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 301 471 "-" "Mozil ...
show more
35.194.202.202 - - [21/Sep/2026:11:08:59 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 301 471 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
35.194.202.202 - - [21/Sep/2026:11:08:59 +0800] "GET /_nuxt/../.env HTTP/1.1" 301 459 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
35.194.202.202 - - [21/Sep/2026:11:08:59 +0800] "GET /static../.env HTTP/1.1" 301 459 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
35.194.202.202 - - [21/Sep/2026:11:08:59 +0800] "GET /media../.env HTTP/1.1" 301 459 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
35.194.202.202 - - [21/Sep/2026:11:08:59 +0800] "GET /files../.env HTTP/1.1" 301 459 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
35.194.202.202 - - [21/Sep/2026:11:09:00 +0800] "GET /assets
...
show less
Brute-Force
๐บ๐ธ
cwytech
2026-09-21 02:59:19
(20 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: crowdsecurity/http-probing.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:31:35
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.194.202.202 (202.202.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.202.202 (202.202.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:31:27.648810 2026] [security2:error] [pid 14525:tid 14525] [client 35.194.202.202:43480] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||lindamsweeney.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lindamsweeney.com"] [uri "/rclone.conf"] [unique_id "arCW_wwekvF3MNt84K621QAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 01:16:26
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.202.202 (202.202.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.202.202 (202.202.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:16:20.986209 2026] [security2:error] [pid 26037:tid 26037] [client 35.194.202.202:50224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cygnetsilks.com"] [uri "/model/.env"] [unique_id "arCFZPWi8MymAa9YZbCMsQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:52:36
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.202.202 (202.202.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.202.202 (202.202.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:52:31.145561 2026] [security2:error] [pid 11173:tid 11173] [client 35.194.202.202:45344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.liyatalton.com"] [uri "/.git/config"] [unique_id "arB_z-FlLtY49lVFyqpFiwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 23:39:26
(23 hours ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:23:04
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.202.202 (202.202.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.202.202 (202.202.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:22:59.679146 2026] [security2:error] [pid 15190:tid 15203] [client 35.194.202.202:44736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.safeco-ins.com"] [uri "/frontend/.env"] [unique_id "arBq0_ZwOhW-Odp13o1gKQAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-09-20 23:12:49
(1 day ago)
{"level":"info","ts":1789945961.7182508,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1789945961.7182508,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.194.202.202","remote_port":"54058","client_ip":"35.194.202.202","proto":"HTTP/2.0","method":"GET","host":"status.gpltimes.com","uri":"/env.json","headers":{"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"],"Accept":["*/*"],"Accept-Encoding":["gzip"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.gpltimes.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000187477,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1789945961.725251,"logger":"http.log.access.log1","msg":"handled reques
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:42:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.194.202.202 (202.202.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.202.202 (202.202.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:42:42.767181 2026] [security2:error] [pid 5645:tid 5645] [client 35.194.202.202:60364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.linnardfinancial.com"] [uri "/.env.bak"] [unique_id "arBhYujRcehXX5QnA1hDeAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 22:33:44
(1 day ago)
XSS Attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 22:25:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.194.202.202 (202.202.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.202.202 (202.202.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:25:20.749736 2026] [security2:error] [pid 4452:tid 4452] [client 35.194.202.202:43930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.liddlesports.com"] [uri "/.env.example"] [unique_id "arBdUCpcLAKmJb8suGMe_wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack