๐ซ๐ท
masterguru
2026-09-21 06:43:59
(9 hours ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 06:13:48
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.236.170.188 (188.170.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.170.188 (188.170.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:13:44.726866 2026] [security2:error] [pid 7408:tid 7408] [client 35.236.170.188:46322] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.chelseafootballprogrammes.com|F|2"] [data ".chelseafootballprogrammes.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.chelseafootballprogrammes.com"] [uri "/z9x8c7v6b5-debug-trigger-www.chelseafootballprogrammes.com"] [unique_id "arDLGGQ-U_HXgrTUkVEPZQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-09-21 04:41:38
(11 hours ago)
{"level":"info","ts":1789965692.8292625,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1789965692.8292625,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.236.170.188","remote_port":"59786","client_ip":"35.236.170.188","proto":"HTTP/2.0","method":"GET","host":"status.chatandconvert.com","uri":"/assets/manifest.json","headers":{"Accept":["*/*"],"X-Nextjs-Data":["1"],"Sec-Ch-Ua":["\"Not=A?Brand\";v=\"99\", \"Google Chrome\";v=\"151\", \"Chromium\";v=\"151\""],"Sec-Ch-Ua-Platform":["\"macOS\""],"Sec-Fetch-Dest":["script"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"Accept-Language":["en-US,en;q=0.9"],"Sec-Fetch-Mode":["no-cors"],"Sec-Ch-Ua-Mobile":["?0"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Sec-Fetch-Site":["same-origin"],"Priority":["u=1"],"User-Agent":["Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/5
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:36:33
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.170.188 (188.170.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.170.188 (188.170.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:36:28.900009 2026] [security2:error] [pid 3187:tid 3208] [client 35.236.170.188:42636] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.chelseyrae.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "arC0TEtJrWe6JJdwU9vwAAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:57:44
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.170.188 (188.170.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.170.188 (188.170.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:57:40.232772 2026] [security2:error] [pid 5026:tid 5026] [client 35.236.170.188:60850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.chyps.com"] [uri "/@fs/app/.env"] [unique_id "arCdJGrRnPIyWOgMaKgNDQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 02:06:09
(14 hours ago)
Trying to access config files
Web App Attack
๐ฉ๐ช
mravb
2026-09-21 01:05:17
(15 hours ago)
35.236.170.188 - - [21/Sep/2026:04:05:17 +0300] "GET /.aws/credentials HTTP/2.0" 401 172 "-" "Mozill ...
show more
35.236.170.188 - - [21/Sep/2026:04:05:17 +0300] "GET /.aws/credentials HTTP/2.0" 401 172 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
...
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 23:59:21
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.170.188 (188.170.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.170.188 (188.170.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:59:14.696326 2026] [security2:error] [pid 25618:tid 25618] [client 35.236.170.188:40040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.chrismcc.com"] [uri "/apps/.env"] [unique_id "arBzUmhhXJKMUoUjHIuY5gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
robotstxt
2026-09-20 23:38:16
(16 hours ago)
35.236.170.188 - - [20/Sep/2026:23:37:13 +0000] "POST / HTTP/2.0" 403 189 "-" "Mozilla/5.0 (compatib ...
show more
35.236.170.188 - - [20/Sep/2026:23:37:13 +0000] "POST / HTTP/2.0" 403 189 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" "-" edge="35.236.170.188"
35.236.170.188 - - [20/Sep/2026:23:37:13 +0000] "GET /api/config HTTP/2.0" 403 189 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" "-" edge="35.236.170.188"
35.236.170.188 - - [20/Sep/2026:23:37:13 +0000] "GET /config.js HTTP/2.0" 403 189 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "-" edge="35.236.170.188"
35.236.170.188 - - [20/Sep/2026:23:37:13 +0000] "GET /z9x8c7v6b5-debug-trigger-demo.cinemapackage.com HTTP/2.0" 403 197 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot" "-" edge="35.236.170.188"
35.236.170.188 - - [20/Sep/2026:23:37:14 +0000] "GET /api/settings HTTP/2.0" 403 189 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" "-"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:05:14
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.236.170.188 (188.170.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.170.188 (188.170.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:05:09.174442 2026] [security2:error] [pid 1156:tid 1156] [client 35.236.170.188:59542] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.cheapbats.liddlesports.com|F|2"] [data ".cheapbats.liddlesports.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.cheapbats.liddlesports.com"] [uri "/z9x8c7v6b5-debug-trigger-www.cheapbats.liddlesports.com"] [unique_id "arBmpTdY7KTgWRrI0J27TgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:35:53
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.170.188 (188.170.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.170.188 (188.170.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:35:48.051339 2026] [security2:error] [pid 6621:tid 6621] [client 35.236.170.188:39904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "christmasgreetingcardsonline.com"] [uri "/.env.example"] [unique_id "arBfxNxJ0YMWZV0AQD5K3gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
conrad10781
2026-09-20 22:18:29
(18 hours ago)
nginx-dot-env
Web App Attack
๐บ๐ธ
mnsf
2026-09-20 22:05:31
(18 hours ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 21:44:02
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.170.188 (188.170.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.170.188 (188.170.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:43:54.334635 2026] [security2:error] [pid 12791:tid 12791] [client 35.236.170.188:58306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.digifonics.com"] [uri "/.env.example"] [unique_id "arBTmg5zYNXrBjox8yPd1QAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-20 21:42:08
(18 hours ago)
Multiple WAF Violations
Web App Attack