π©πͺ
macrob
2026-09-17 17:28:58
(3 hours ago)
2026/09/17 17:28:57 [error] 3435309#3435309: *8912654 access forbidden by rule, client: 35.188.200.2 ...
show more
2026/09/17 17:28:57 [error] 3435309#3435309: *8912654 access forbidden by rule, client: 35.188.200.22, server: fn.binixo.es, request: "GET /.aws/config HTTP/2.0", host: "ai.fastcredit.net.ua"
2026/09/17 17:28:57 [error] 3435309#3435309: *8912658 access forbidden by rule, client: 35.188.200.22, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "ai.fastcredit.net.ua"
2026/09/17 17:28:57 [error] 3435311#3435311: *8912659 access forbidden by rule, client: 35.188.200.22, server: fn.binixo.es, request: "GET /.aws/credentials HTTP/2.0", host: "ai.fastcredit.net.ua"
...
show less
Web App Attack
π§πͺ
Ivo Vynckier
2026-09-17 15:03:00
(5 hours ago)
35.188.200.22 - - [17/Sep/2026:12:12:24 +0200] "GET /static//app/.env HTTP/2.0" 403 106 "-" "CCBot/2 ...
show more
35.188.200.22 - - [17/Sep/2026:12:12:24 +0200] "GET /static//app/.env HTTP/2.0" 403 106 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
35.188.200.22 - - [17/Sep/2026:12:12:24 +0200] "GET //.env HTTP/2.0" 403 106 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
35.188.200.22 - - [17/Sep/2026:12:12:24 +0200] "GET /api/.env/public/.env HTTP/2.0" 403 106 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
35.188.200.22 - - [17/Sep/2026:12:12:24 +0200] "GET /.//.env HTTP/2.0" 403 106 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
show less
Web App Attack
π©πͺ
raph
2026-09-17 13:32:32
(7 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
π©πͺ
Petros Stefanakis
2026-09-17 13:15:04
(7 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.188.200.22 (US/United States/22.200. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.188.200.22 (US/United States/22.200.188.35.bc.googleusercontent.com)
show less
SQL Injection
π©πͺ
TheDjRider
2026-09-17 12:29:05
(8 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-17T12:29:03.968285572Z. Context: http_status=404
show less
Web App Attack
π³π±
Savvii
2026-09-17 11:26:04
(9 hours ago)
20 attempts against mh-misbehave-ban on choy
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 11:24:40
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.188.200.22 (22.200.188.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.188.200.22 (22.200.188.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 07:24:37.352782 2026] [security2:error] [pid 19797:tid 19875] [client 35.188.200.22:49452] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tomithai.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tomithai.com"] [uri "/z9x8c7v6b5-debug-trigger-tomithai.com"] [unique_id "aqvN9YRAUmLGYW3tQDEkfQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-09-17 10:57:53
(10 hours ago)
20 attempts against mh-misbehave-ban on mensa
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-09-17 09:44:13
(11 hours ago)
20 attempts against mh-misbehave-ban on ceres
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Alt255
2026-09-17 09:25:34
(11 hours ago)
[cb-01al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-01al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.188.200.22 - - [17/Sep/2026:11:25:13 +0200] "GET /@fs/src/.env?raw?? HTTP/2.0" 404 1338 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
...
show less
Bad Web Bot
Web App Attack
π΅π±
nakordoni.eu
2026-09-17 07:00:14
(13 hours ago)
Blocked by nakordoni.eu automated security: nakordoni-probe-gate. Jail: nakordoni-probe-gate, 1 matc ...
show more
Blocked by nakordoni.eu automated security: nakordoni-probe-gate. Jail: nakordoni-probe-gate, 1 matches. ISP: Google LLC (US), Usage: Data Center/Web Hosting/Transit. Prior AbuseIPDB score at ban time: 100/100.
show less
Bad Web Bot
Web App Attack
πͺπΈ
robotstxt
2026-09-17 06:53:57
(14 hours ago)
35.188.200.22 - - [17/Sep/2026:06:53:36 +0000] "GET /config/env/aws_credentials.env HTTP/2.0" 403 18 ...
show more
35.188.200.22 - - [17/Sep/2026:06:53:36 +0000] "GET /config/env/aws_credentials.env HTTP/2.0" 403 189 "https://noudiari.es/config/env/aws_credentials.env" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "-" edge="35.188.200.22"
35.188.200.22 - - [17/Sep/2026:06:53:36 +0000] "GET /.vscode/launch.json HTTP/2.0" 403 189 "https://noudiari.es/.vscode/launch.json" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" "-" edge="35.188.200.22"
35.188.200.22 - - [17/Sep/2026:06:53:36 +0000] "GET /serverless.yaml HTTP/2.0" 403 189 "https://noudiari.es/serverless.yaml" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" "-" edge="35.188.200.22"
35.188.200.22 - - [17/Sep/2026:06:53:36 +0000] "GET /.idea/WebServers.xml HTTP/2.0" 403 189 "https://noudiari.es/.idea/WebServers.xml" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "-" edge="35.188.200.22"
...
show less
Web App Attack
π©πͺ
netclix.gr
2026-09-17 06:37:59
(14 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.188.200.22 (US/United States/22.200. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.188.200.22 (US/United States/22.200.188.35.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
πΉπ
MWA SOC
2026-09-17 06:25:29
(14 hours ago)
Hacking
π³π±
Savvii
2026-09-17 06:23:26
(14 hours ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack