๐ฉ๐ช
macrob
2026-10-02 10:51:34
(25 minutes ago)
2026/10/02 10:51:31 [error] 2231817#2231817: *8262494 access forbidden by rule, client: 35.201.224.4 ...
show more
2026/10/02 10:51:31 [error] 2231817#2231817: *8262494 access forbidden by rule, client: 35.201.224.44, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "stage.smoozy.org"
2026/10/02 10:51:32 [error] 2231816#2231816: *8262493 access forbidden by rule, client: 35.201.224.44, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "stage.smoozy.org"
2026/10/02 10:51:32 [error] 2231816#2231816: *8262529 access forbidden by rule, client: 35.201.224.44, server: fn.binixo.es, request: "GET /cache/original/%2e%2e/.env HTTP/2.0", host: "stage.smoozy.org"
...
show less
Web App Attack
Anonymous
2026-10-02 10:31:11
(45 minutes ago)
2026/10/02 10:31:07 [error] 2479716#2479716: *532392 [client 35.201.224.44] ModSecurity: Access deni ...
show more
2026/10/02 10:31:07 [error] 2479716#2479716: *532392 [client 35.201.224.44] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "sakaman.idealcollegeonline.org"] [uri "/z9x8c7v6b5-debug-trigger-sakaman.idealcollegeonline.org"] [unique_id "179093706799.910236"] [ref ""], client: 35.201.224.44, server: srv.ingeltechgh.com, request: "GET /z9x8c7v6b5-debug-trigger-sakaman.idealcollegeonline.org HTTP/2.0", host: "sakaman.idealcollegeonline.org"
2026/10/02 10:31:07 [error] 2479716#2479716: *532392 [client 35.201.224.44] ModSecurity: Access denied with code 403 (phase 2). Matche
...
show less
Brute-Force
Anonymous
2026-10-02 10:26:02
(50 minutes ago)
Sensitive file access attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-02 10:17:22
(59 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.201.224.44 (44.224.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.224.44 (44.224.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 06:17:15.562754 2026] [security2:error] [pid 18506:tid 18506] [client 35.201.224.44:36112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.thenewplace.org"] [uri "/static../.env"] [unique_id "ar-EqxOBhNIL9kzbPhWgKgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-10-02 10:02:02
(1 hour ago)
Bad behaviour
Web Spam
๐ฉ๐ช
yitzhaq
2026-10-02 09:14:19
(2 hours ago)
35.201.224.44 - - [02/Oct/2026:11:14:17 +0200] "GET /graphql/console HTTP/2.0" 404 294 "-" "Mozilla/ ...
show more
35.201.224.44 - - [02/Oct/2026:11:14:17 +0200] "GET /graphql/console HTTP/2.0" 404 294 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
35.201.224.44 - - [02/Oct/2026:11:14:17 +0200] "GET /v1/graphql HTTP/2.0" 403 297 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
35.201.224.44 - - [02/Oct/2026:11:14:17 +0200] "GET /telescope/requests HTTP/2.0" 404 294 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
35.201.224.44 - - [02/Oct/2026:11:14:17 +0200] "GET /_debugbar/open HTTP/2.0" 403 297 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
35.201.224.44 - - [02/Oct/2026:11:14:17 +0200] "GET /_ignition/health-check HTTP/2.0" 403 297 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-02 08:45:23
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.224.44 (44.224.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.224.44 (44.224.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 04:45:16.784360 2026] [security2:error] [pid 21515:tid 21515] [client 35.201.224.44:55534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.salvoni.org"] [uri "/static../.env"] [unique_id "ar9vHIBp5WVD9NJbb5k-GAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
melroy89
2026-10-02 08:01:45
(3 hours ago)
35.201.224.44 - - [02/Oct/2026:10:01:29 +0200] "GET / HTTP/1.1" 403 9 "-" "Mozilla/5.0 (Windows NT ...
show more
35.201.224.44 - - [02/Oct/2026:10:01:29 +0200] "GET / HTTP/1.1" 403 9 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0" "internal.melroy.org" 0.000
35.201.224.44 - - [02/Oct/2026:10:01:29 +0200] "GET /tvnuobqh6whby807ovwv HTTP/1.1" 403 9 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" "internal.melroy.org" 0.000
35.201.224.44 - - [02/Oct/2026:10:01:30 +0200] "GET /model/info HTTP/1.1" 403 9 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" "internal.melroy.org" 0.000
35.201.224.44 - - [02/Oct/2026:10:01:30 +0200] "GET /6jthu9xc1aaascuuj4ag HTTP/1.1" 403 9 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" "internal.melroy.org" 0.000
35.201.224.44 - - [02/Oct/2026:10:01:30 +0200] "POST / HTTP/1.1" 403 9 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" "internal.melroy.org" 0.0
...
show less
Web App Attack
๐ฉ๐ช
updown.io
2026-10-02 07:59:35
(3 hours ago)
{"level":"info","ts":1790927969.5255327,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790927969.5255327,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.201.224.44","remote_port":"41220","client_ip":"35.201.224.44","proto":"HTTP/2.0","method":"GET","host":"status.korni22.org","uri":"/dist/manifest.json","headers":{"Upgrade-Insecure-Requests":["1"],"Sec-Fetch-Dest":["document"],"Sec-Ch-Ua":["\"Chromium\";v=\"152\", \"Not?A_Brand\";v=\"24\", \"Microsoft Edge\";v=\"152\""],"Sec-Fetch-Mode":["navigate"],"Priority":["u=0, i"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Sec-Fetch-User":["?1"],"Accept-Language":["en-US,en;q=0.9"],"X-Nextjs-Data":["1"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8"],"Sec-Ch-Ua-Mobile":["?0"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"],"Accept-Encoding":["gzip, deflate, br, zstd"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/m
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 07:15:26
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.224.44 (44.224.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.224.44 (44.224.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 03:15:23.053507 2026] [security2:error] [pid 1421:tid 1421] [client 35.201.224.44:52008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sandboxspeech.org"] [uri "/.env.js"] [unique_id "ar9aC6PA50fkKS_Eb-5y6gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-10-02 06:52:11
(4 hours ago)
2026/10/02 06:52:01 [error] 2173941#2173941: *7525763 access forbidden by rule, client: 35.201.224.4 ...
show more
2026/10/02 06:52:01 [error] 2173941#2173941: *7525763 access forbidden by rule, client: 35.201.224.44, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "api.smoozy.org"
2026/10/02 06:52:01 [error] 2173941#2173941: *7525768 access forbidden by rule, client: 35.201.224.44, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "api.smoozy.org"
2026/10/02 06:52:01 [error] 2173941#2173941: *7525763 access forbidden by rule, client: 35.201.224.44, server: fn.binixo.es, request: "GET /config/env/aws_credentials.env HTTP/2.0", host: "api.smoozy.org"
...
show less
Web App Attack
๐ฆ๐บ
aranguren.org
2026-10-02 06:26:41
(4 hours ago)
35.201.224.44 - - [02/Oct/2026:16:26:41 +1000] "GET /asset-manifest.json HTTP/2.0" 404 1160 "https:/ ...
show more
35.201.224.44 - - [02/Oct/2026:16:26:41 +1000] "GET /asset-manifest.json HTTP/2.0" 404 1160 "https://www.aranguren.org/asset-manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36"
35.201.224.44 - - [02/Oct/2026:16:26:41 +1000] "GET /model/info HTTP/2.0" 404 1142 "https://www.aranguren.org/model/info" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
35.201.224.44 - - [02/Oct/2026:16:26:41 +1000] "GET /y909nabah6nz7xajolbw HTTP/2.0" 404 1162 "https://www.aranguren.org/y909nabah6nz7xajolbw" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
35.201.224.44 - - [02/Oct/2026:16:26:41 +1000] "GET /webpack-stats.json HTTP/2.0" 404 1158 "https://www.aranguren.org/webpack-stats.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36"
35.201.224.44 - - [02/Oct/2026:16:26:41 +1000] "GET /asset
...
show less
Bad Web Bot
๐ซ๐ฎ
Kotisivu.org
2026-10-02 05:33:43
(5 hours ago)
Automated web scanner probe: GET /api/console/api_server?<redacted> on internal.kotisivu.org.
Brute-Force
Web App Attack
๐บ๐ธ
creechy
2026-10-02 05:33:22
(5 hours ago)
35.201.224.44 - - [01/Oct/2026:22:33:13 -0700] "GET /wp-json HTTP/1.1" 404 759 "-" "Mozilla/5.0 Appl ...
show more
35.201.224.44 - - [01/Oct/2026:22:33:13 -0700] "GET /wp-json HTTP/1.1" 404 759 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Hacking
Bad Web Bot
Anonymous
2026-10-02 05:20:57
(5 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking