๐บ๐ธ
helios.live
2026-09-19 04:10:03
(1 day ago)
2026/09/19 04:10:01 [error] 1393912#1393912: *3754013 access forbidden by rule, client: 35.221.212.2 ...
show more
2026/09/19 04:10:01 [error] 1393912#1393912: *3754013 access forbidden by rule, client: 35.221.212.205, server: kocerroxy.com, request: "GET /dist/.vite/manifest.json HTTP/1.1", host: "app.kocerroxy.com"
2026/09/19 04:10:01 [error] 1393912#1393912: *3754013 access forbidden by rule, client: 35.221.212.205, server: kocerroxy.com, request: "GET /.vite/manifest.json HTTP/1.1", host: "app.kocerroxy.com"
2026/09/19 04:10:01 [error] 1393912#1393912: *3754010 access forbidden by rule, client: 35.221.212.205, server: kocerroxy.com, request: "GET /.zshrc HTTP/1.1", host: "app.kocerroxy.com"
2026/09/19 04:10:03 [error] 1393912#1393912: *3754007 access forbidden by rule, client: 35.221.212.205, server: kocerroxy.com, request: "GET /.bash_profile HTTP/1.1", host: "app.kocerroxy.com"
2026/09/19 04:10:03 [error] 1393912#1393912: *3753903 access forbidden by rule, client: 35.221.212.205, server: kocerroxy.com, request: "GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/1.1", ho
...
show less
Web App Attack
๐บ๐ธ
deskpass.com
2026-09-19 03:55:20
(1 day ago)
POST /lib/terminal-xhr.php
Web App Attack
๐ฉ๐ช
Skyrider
2026-09-19 00:34:46
(1 day ago)
crowdsecurity/http-probing
Web App Attack
๐ซ๐ฎ
albionfreemarket.com
2026-09-18 23:10:13
(1 day ago)
35.221.212.205 - - [18/Sep/2026:23:10:12 +0000] "POST /graphql HTTP/2.0" 403 555 "https://api.albion ...
show more
35.221.212.205 - - [18/Sep/2026:23:10:12 +0000] "POST /graphql HTTP/2.0" 403 555 "https://api.albionfreemarket.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" 0.000 "-" "TW"
35.221.212.205 - - [18/Sep/2026:23:10:12 +0000] "POST /api/graphql HTTP/2.0" 403 555 "https://api.albionfreemarket.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" 0.000 "-" "TW"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-18 13:55:48
(2 days ago)
20 attempts against mh-misbehave-ban on lunar
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-18 13:48:56
(2 days ago)
35.221.212.205 - - [18/Sep/2026:08:48:53 -0500] "GET /.env.live HTTP/1.1" 403 199 "-" "Mozilla/5.0 A ...
show more
35.221.212.205 - - [18/Sep/2026:08:48:53 -0500] "GET /.env.live HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" 35.221.212.205
35.221.212.205 - - [18/Sep/2026:08:48:53 -0500] "GET /.env.stage HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" 35.221.212.205
35.221.212.205 - - [18/Sep/2026:08:48:53 -0500] "GET /.env.js HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 35.221.212.205
35.221.212.205 - - [18/Sep/2026:08:48:54 -0500] "GET /.env.www HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" 35.221.212.205
35.221.212.205 - - [18/Sep/2026:08:48:54 -0500] "GET /.env.prod HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" 35.221.212.205
35.221.212.205 - - [18/Sep/2026:08:48:54 -0500] "GET /.env_1
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
noise.agency
2026-09-18 11:52:51
(2 days ago)
35.221.212.205 (TW/Taiwan/205.212.221.35.bc.googleusercontent.com), more than 10 Apache 403 hits
Hacking
๐ง๐ท
dermatovirtual
2026-09-18 11:39:44
(2 days ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 35 unauthorized requests recorded between 2026-09-17 11:37:23 UTC and 2026-09-17 11:37:34 UTC (rate: ~35 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-17 11:37:34 UTC] IP: 35.221.212.205 - W3C IIS (Port 443): GET /.git/config -> HTTP 404 [CLIENT: 35.221.212.205]
[2026-09-17 11:37:34 UTC] IP: 35.221.212.205 - W3C IIS (Port 443): GET /static/app/.env -> HTTP 404 [CLIENT: 35.221.212.205]
[2026-09-17 11:37:34 UTC] IP: 35.221.212.205 - W3C IIS (Port 443): GET /admin/.env -> HTTP 404 [CLIENT: 35.221.212.205]
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-18 09:44:19
(2 days ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.221.212.205 - - [18/Sep/2026:11:44:00 +0200] "GET /backend/.env HTTP/2.0" 404 1855 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-18 07:11:32
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐ฌ๐ง
Apache
2026-09-18 04:23:36
(2 days ago)
(mod_security) mod_security (id:930100) triggered by 35.221.212.205 (TW/Taiwan/205.212.221.35.bc.goo ...
show more
(mod_security) mod_security (id:930100) triggered by 35.221.212.205 (TW/Taiwan/205.212.221.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
SSH
Web App Attack
Anonymous
2026-09-17 23:00:00
(2 days ago)
Blocked by ModSec and CSF
Port Scan
๐ฎ๐น
VHosting
2026-09-17 22:55:04
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
zcampbell
2026-09-17 22:02:33
(2 days ago)
Web vulnerability scanning: probing for exposed sensitive files (.aws). Detected and blocked automat ...
show more
Web vulnerability scanning: probing for exposed sensitive files (.aws). Detected and blocked automatically.
show less
Web App Attack
Bad Web Bot
Anonymous
2026-09-17 19:30:00
(3 days ago)
Vercel.Next.js.x-middleware-subrequest.Authentication.Bypass
Hacking