π©πͺ
updown.io
2026-09-21 06:24:47
(3 days ago)
{"level":"info","ts":1789971884.1681378,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1789971884.1681378,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.229.97.177","remote_port":"45644","client_ip":"35.229.97.177","proto":"HTTP/2.0","method":"GET","host":"status.beeceptor.com","uri":"/asset-manifest.json","headers":{"Priority":["u=0, i"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"Sec-Ch-Ua-Mobile":["?0"],"Accept-Language":["en-US,en;q=0.9"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8"],"Sec-Ch-Ua":["\"Chromium\";v=\"153\", \"Brave\";v=\"153\", \"Not_A Brand\";v=\"8\""],"Sec-Ch-Ua-Platform":["\"Windows\""],"Sec-Fetch-Dest":["document"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"],"Sec-Fetch-Mode":["navigate"],"Upg
...
show less
DDoS Attack
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 06:23:15
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.97.177 (177.97.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.97.177 (177.97.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:23:11.393601 2026] [security2:error] [pid 17605:tid 17605] [client 35.229.97.177:53760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.whaletailpuckerbutt.com"] [uri "/media../.env"] [unique_id "arDNTyEkncu_KWOVDPjBuwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 05:46:20
(3 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-09-21 05:44:16
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.97.177 (177.97.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.97.177 (177.97.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:44:11.233148 2026] [security2:error] [pid 21595:tid 21595] [client 35.229.97.177:48462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.vicchorus.com"] [uri "/@fs/app/.env"] [unique_id "arDEK_SgTxIMhuHo9VEAxgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 04:54:06
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.97.177 (177.97.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.97.177 (177.97.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:54:03.272310 2026] [security2:error] [pid 11052:tid 11052] [client 35.229.97.177:35928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.willowbrookins.com"] [uri "/@fs/app/.env"] [unique_id "arC4a4NTf9gw6nmVaGj3BQAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 03:32:56
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.229.97.177 (177.97.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.97.177 (177.97.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:32:48.797340 2026] [security2:error] [pid 28558:tid 28558] [client 35.229.97.177:46038] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stefaneder.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stefaneder.com"] [uri "/z9x8c7v6b5-debug-trigger-stefaneder.com"] [unique_id "arClYEHI6EUGw5z9YacPkQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 03:10:41
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.97.177 (177.97.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.97.177 (177.97.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:10:36.150924 2026] [security2:error] [pid 23691:tid 23691] [client 35.229.97.177:37134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sekelconsulting.com"] [uri "/web/.env"] [unique_id "arCgLMBhi9vIhFEPr6aWGQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 02:22:13
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.97.177 (177.97.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.97.177 (177.97.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:22:07.625373 2026] [security2:error] [pid 9908:tid 9908] [client 35.229.97.177:50878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "starcrestsales.com"] [uri "/.git/HEAD"] [unique_id "arCUz-s7hdtx9fHyfOXMYwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 02:01:30
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.229.97.177 (177.97.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.97.177 (177.97.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:01:22.770789 2026] [security2:error] [pid 6208:tid 6208] [client 35.229.97.177:47356] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tecnoconce.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tecnoconce.com"] [uri "/host.key"] [unique_id "arCP8hy_8_9R4o4wxPXqtgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π²πΎ
Rizzy
2026-09-21 01:41:31
(3 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-09-21 01:40:08
(3 days ago)
Blocked by ModSec and CSF
Port Scan
πΊπΈ
TPI-Abuse
2026-09-21 01:16:50
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.97.177 (177.97.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.97.177 (177.97.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:16:45.080232 2026] [security2:error] [pid 21937:tid 21937] [client 35.229.97.177:56304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.thewhispertwins.com"] [uri "/deploy/.env"] [unique_id "arCFfYTUbX1rc3ieuQ6VVgAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 00:54:16
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.97.177 (177.97.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.97.177 (177.97.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:54:09.405953 2026] [security2:error] [pid 2129:tid 2129] [client 35.229.97.177:41370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sykesclan.com"] [uri "/infra/.env"] [unique_id "arCAMflrqnfak9RXtywPcQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 00:48:01
(3 days ago)
Malicious activity detected
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 00:31:48
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.97.177 (177.97.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.97.177 (177.97.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:31:43.191480 2026] [security2:error] [pid 6420:tid 6420] [client 35.229.97.177:42314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.truecontrarian.com"] [uri "/config/.env"] [unique_id "arB679qMK_K6mSzR_eHxjgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack