🇸🇪
vaia.cloud
2026-09-10 20:55:03
(6 minutes ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇩🇪
LRob
2026-09-10 20:23:18
(37 minutes ago)
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 AppleWebKit/537. ...
show more
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] ) | path: /.env (+3 more) | 2026-09-10 20:23 UTC
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-10 20:02:56
(58 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.221.189.88 (88.189.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.189.88 (88.189.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 16:02:47.619860 2026] [security2:error] [pid 28906:tid 28906] [client 35.221.189.88:45216] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||4lazy.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "4lazy.com"] [uri "/rclone.conf"] [unique_id "aqMM5wNBfefHRwunAU4MEAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
COMAITE
2026-09-10 19:58:38
(1 hour ago)
Suspicious URL access.
Web App Attack
🇷🇴
clauss
2026-09-10 19:57:27
(1 hour ago)
35.221.189.88 - - [10/Sep/2026:22:57:23 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "DuckAssistBo ...
show more
35.221.189.88 - - [10/Sep/2026:22:57:23 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
35.221.189.88 - - [10/Sep/2026:22:57:27 +0300] "GET /secrets.yml HTTP/2.0" 301 0 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
...
show less
Web App Attack
🇩🇪
macrob
2026-09-10 19:52:41
(1 hour ago)
2026/09/10 19:52:40 [error] 17624#17624: *200315 access forbidden by rule, client: 35.221.189.88, se ...
show more
2026/09/10 19:52:40 [error] 17624#17624: *200315 access forbidden by rule, client: 35.221.189.88, server: 100fs.org, request: "GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/1.1", host: "100fs.org"
2026/09/10 19:52:40 [error] 17624#17624: *200640 access forbidden by rule, client: 35.221.189.88, server: 100fs.org, request: "GET /_nuxt/../.env HTTP/1.1", host: "100fs.org"
2026/09/10 19:52:40 [error] 17624#17624: *200643 access forbidden by rule, client: 35.221.189.88, server: 100fs.org, request: "GET /media../.env HTTP/1.1", host: "100fs.org"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2025-11-14 20:21:33
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 35.221.189.88 (88.189.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.189.88 (88.189.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 14 15:21:27.139731 2025] [security2:error] [pid 11813:tid 11813] [client 35.221.189.88:50350] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.weathercarib.com|F|2"] [data ".weathercarib.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.weathercarib.com"] [uri "/www.weathercarib.com"] [unique_id "aRePR05n0VSMXHHzaSr_LwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-14 20:02:21
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 35.221.189.88 (88.189.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.189.88 (88.189.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 14 15:02:15.568859 2025] [security2:error] [pid 14680:tid 14680] [client 35.221.189.88:34930] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.lockdownclaim.com|F|2"] [data ".lockdownclaim.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.lockdownclaim.com"] [uri "/www.lockdownclaim.com"] [unique_id "aReKx8PLI4SaQQFyh6uYCAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-14 15:37:02
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 35.221.189.88 (88.189.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.189.88 (88.189.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 14 10:36:56.600507 2025] [security2:error] [pid 11239:tid 11239] [client 35.221.189.88:39780] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.expertprofessionalcleaners.com|F|2"] [data ".expertprofessionalcleaners.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.expertprofessionalcleaners.com"] [uri "/www.expertprofessionalcleaners.com"] [unique_id "aRdMmBnXCo6CxzCNXfAPJAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack