๐ฌ๐ง
consul.to
2026-10-05 09:40:40
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 08:22:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.203.106.103 (103.106.203.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.106.103 (103.106.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 04:22:20.419575 2026] [security2:error] [pid 14588:tid 14588] [client 35.203.106.103:56050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.tubbesing.services"] [uri "/.htpasswd"] [unique_id "asNePBGnEWzJj0AAgO_nxwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-10-05 07:20:21
(2 days ago)
{"level":"info","ts":1791184818.0359383,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1791184818.0359383,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.203.106.103","remote_port":"35982","client_ip":"35.203.106.103","proto":"HTTP/2.0","method":"GET","host":"status.funnelcloud.services","uri":"/manifest.json","headers":{"Sec-Fetch-User":["?1"],"Sec-Fetch-Mode":["navigate"],"Sec-Ch-Ua":["\"Chromium\";v=\"153\", \"Google Chrome\";v=\"153\", \"Not_A Brand\";v=\"8\""],"Accept-Encoding":["gzip, deflate, br, zstd"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8"],"Accept-Language":["en-US,en;q=0.9"],"Sec-Fetch-Dest":["document"],"X-Nextjs-Data":["1"],"Sec-Ch-Ua-Mobile":["?1"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"Sec-Ch-Ua-Platform":["\"Android\""],"Sec-Fetch-Site":["none"],"Upgrade-Insecure-Requests":["1"],"User-Agent":[
...
show less
DDoS Attack
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-05 07:17:44
(2 days ago)
20 attempts against mh-misbehave-ban on staging
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-05 04:47:15
(2 days ago)
20 attempts against mh-misbehave-ban on munin-ec2
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 01:42:19
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.203.106.103 (103.106.203.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.106.103 (103.106.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 21:42:15.757049 2026] [security2:error] [pid 30366:tid 30366] [client 35.203.106.103:50260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ggaccounting.services"] [uri "/appearance/../../.env"] [unique_id "asMAd3gzRJeqlWh_PV9vlQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
MatStef132
2026-10-04 22:48:47
(2 days ago)
MatShield L7: blocked on api.klovy.chat (secret-path-probe)
DDoS Attack
๐ฉ๐ช
Marc
2026-10-04 22:34:05
(2 days ago)
35.203.106.103 - - [05/Oct/2026:00:34:04 +0200] "GET /t56bqg82lej21ua7o06j HTTP/2.0" 404 291 "-" "Mo ...
show more
35.203.106.103 - - [05/Oct/2026:00:34:04 +0200] "GET /t56bqg82lej21ua7o06j HTTP/2.0" 404 291 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" 35.203.106.103 - - [05/Oct/2026:00:34:04 +0200] "GET /account HTTP/2.0" 404 269 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" 35.203.106.103 - - [05/Oct/2026:00:34:04 +0200] "GET /forgot-password HTTP/2.0" 404 269 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
show less
Brute-Force
๐ฌ๐ง
gws-hostmaster
2026-10-04 22:30:51
(2 days ago)
ModSecurity OWASP CRS (Anomaly Score: 45): HTTP header is restricted by policy (/x-middleware-subreq ...
show more
ModSecurity OWASP CRS (Anomaly Score: 45): HTTP header is restricted by policy (/x-middleware-subrequest/);JavaScript Prototype Pollution;JSON-Based SQL Injection;Node.js Injection Attack 1/2;OS File Access Attempt;Remote Command Execution: Unix Shell Code Found;Restricted File Access Attempt;
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 20:40:09
(2 days ago)
(mod_security) mod_security (id:210580) triggered by 35.203.106.103 (103.106.203.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 35.203.106.103 (103.106.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 16:40:01.717670 2026] [security2:error] [pid 29333:tid 29333] [client 35.203.106.103:47172] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:apis. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||trailer.services|F|2"] [data "Matched Data: proc/self/environ found within ARGS:apis: ../../../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "trailer.services"] [uri "/api/console/api_server"] [unique_id "asK5oRp7ILqeCks84gzR1QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-10-04 19:45:03
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ธ๐ช
nekopavel
2026-10-04 19:44:19
(2 days ago)
35.203.106.103 - - [04/Oct/2026:21:44:16 +0200]"GET /files../.env HTTP/2.0" 444 0"-" neko.chat "Mozi ...
show more
35.203.106.103 - - [04/Oct/2026:21:44:16 +0200]"GET /files../.env HTTP/2.0" 444 0"-" neko.chat "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot""0.000" "-""Montreal" "CA"
35.203.106.103 - - [04/Oct/2026:21:44:16 +0200]"GET /static../.env HTTP/2.0" 444 0"-" neko.chat "CCBot/2.0 (https://commoncrawl.org/faq/)""0.000" "-""Montreal" "CA"
35.203.106.103 - - [04/Oct/2026:21:44:16 +0200]"GET /media../.env HTTP/2.0" 301 0"-" neko.chat "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)""0.010" "0.005""Montreal" "CA"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-10-04 19:34:01
(2 days ago)
163 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-10-04 19:13:01
(2 days ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2021-03-26 15:00:00
(5 years ago)
Brute force login
Brute-Force