π§πͺ
cmbplf
2026-09-22 02:41:44
(12 hours ago)
100 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
πͺπΈ
robotstxt
2026-09-22 00:44:22
(14 hours ago)
35.237.210.174 - - [22/Sep/2026:00:43:20 +0000] "GET / HTTP/2.0" 403 39499 "https://leydeciberresili ...
show more
35.237.210.174 - - [22/Sep/2026:00:43:20 +0000] "GET / HTTP/2.0" 403 39499 "https://leydeciberresiliencia.com/" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" "-" edge="35.237.210.174"
35.237.210.174 - - [22/Sep/2026:00:43:20 +0000] "GET /__/firebase/init.json HTTP/2.0" 403 12651 "https://leydeciberresiliencia.com/__/firebase/init.json" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" "-" edge="35.237.210.174"
35.237.210.174 - - [22/Sep/2026:00:43:20 +0000] "GET /z9x8c7v6b5-debug-trigger-leydeciberresiliencia.com HTTP/2.0" 403 12675 "https://leydeciberresiliencia.com/z9x8c7v6b5-debug-trigger-leydeciberresiliencia.com" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" "-" edge="35.237.210.174"
35.237.210.174 - - [22/Sep/2026:00:43:20 +0000] "GET /.gitlab-ci.yml HTTP/2.0" 403 12651 "https://leydeciberresiliencia.com/.gitlab-ci.yml" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https:
...
show less
Web App Attack
π©πͺ
LRob
2026-09-22 00:22:02
(15 hours ago)
This address declares itself a crawler and keeps requesting pages after being refused (HTTP 403/429) ...
show more
This address declares itself a crawler and keeps requesting pages after being refused (HTTP 403/429) and told to stop by robots.txt. A crawler that ignores refusals costs our servers capacity for nothing and is treated as abusive; blocked. Please make it honour robots.txt and the refusals it is given. | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] ) (+2 more) | path: /admin/.env (+2 more) | 2026-09-22 00:22 UTC
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-22 00:04:32
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.237.210.174 (174.210.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.210.174 (174.210.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:04:00.300735 2026] [security2:error] [pid 29848:tid 29848] [client 35.237.210.174:60836] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.flashbackmusicmemories.com|F|2"] [data ".flashbackmusicmemories.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.flashbackmusicmemories.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.flashbackmusicmemories.com"] [unique_id "arHF8B8GFHB-vp4aiwN_AQAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 22:46:01
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.210.174 (174.210.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.210.174 (174.210.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:45:56.614272 2026] [security2:error] [pid 15179:tid 15179] [client 35.237.210.174:53378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.royal-barbershop.com"] [uri "/.env.backup"] [unique_id "arGzpE5j3dV8mVun3mH6RQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 22:26:32
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.237.210.174 (174.210.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.210.174 (174.210.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:26:25.564794 2026] [security2:error] [pid 29753:tid 29753] [client 35.237.210.174:49138] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.llewlife.78cardsofthetarot-tarotmancy-tarot-cards-and-tarot-readings.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.llewlife.78cardsofthetarot-tarotmancy-tarot-cards-and-tarot-readings.com"] [uri "/rclone.conf"] [unique_id "arGvEfOnDBUSTv3C9C5D8QAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 21:11:23
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.237.210.174 (174.210.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.210.174 (174.210.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:11:18.065127 2026] [security2:error] [pid 32689:tid 32689] [client 35.237.210.174:37302] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lollytalk.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lollytalk.com"] [uri "/z9x8c7v6b5-debug-trigger-lollytalk.com"] [unique_id "arGddhJa7BqyfST8nKvX5gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 20:36:34
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.210.174 (174.210.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.210.174 (174.210.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:36:30.727348 2026] [security2:error] [pid 18379:tid 18379] [client 35.237.210.174:36600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.oshadega.com"] [uri "/images../.env"] [unique_id "arGVTpZ7S_fPQJxPAzKyfAAAAGs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 19:31:40
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.237.210.174 (174.210.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.210.174 (174.210.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:31:31.778773 2026] [security2:error] [pid 24420:tid 24420] [client 35.237.210.174:53288] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.liyatalton.com|F|2"] [data ".liyatalton.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.liyatalton.com"] [uri "/z9x8c7v6b5-debug-trigger-www.liyatalton.com"] [unique_id "arGGE3kBJlCO7ngLcNW0hQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
lnklnx
2026-09-21 18:51:56
(20 hours ago)
www.lnklnx.com:443 35.237.210.174 - - [21/Sep/2026:13:51:52 -0500] "GET /.env.backup HTTP/1.1" 403 5 ...
show more
www.lnklnx.com:443 35.237.210.174 - - [21/Sep/2026:13:51:52 -0500] "GET /.env.backup HTTP/1.1" 403 503 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 18:27:41
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.210.174 (174.210.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.210.174 (174.210.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:27:35.675668 2026] [security2:error] [pid 15188:tid 15188] [client 35.237.210.174:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.local639.com"] [uri "/admin/.env"] [unique_id "arF3F2HqEAsLfwwY01f96gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-09-21 18:05:34
(21 hours ago)
Too many Status 40X (17)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 17:56:14
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.210.174 (174.210.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.210.174 (174.210.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:56:09.415792 2026] [security2:error] [pid 507662:tid 507662] [client 35.237.210.174:49428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lloydprins.com"] [uri "/api/.env"] [unique_id "arFvuSUrUkaY-gEqlZ7ZswAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 16:45:21
(22 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-09-21 16:31:47
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.210.174 (174.210.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.210.174 (174.210.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:31:40.956806 2026] [security2:error] [pid 28410:tid 28410] [client 35.237.210.174:41106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.lemontreefoods.com"] [uri "/.env.production"] [unique_id "arFb7LGWKC84J_CsFYy9UQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack