← back to clip · use your browser's Print / Save as PDF (Ctrl+P).

/whymongo Access History — Jul 2 to Jul 16, 2026

by beholder · 2026-07-16 18:21:57
/whymongo Access History

/whymongo — Full Access History

Lifetime logs from Jul 2 – Jul 16, 2026 (14 days of nginx access logs).

1. 🕷️ AhrefsBot — 2 hits

DateIPStatus
Jul 254.39.136.125200
Jul 1654.39.89.8304 (cached)

Both from proxy-ca0??-san???.ahrefs.net — standard SEO indexing.

2. 🕷️ SemrushBot — 1 hit

DateIPStatus
Jul 485.208.96.201200

From 201.bl.bot.semrush.com.

3. 🕷️ GPTBot (OpenAI) — 1 hit

DateIPReferer
Jul 1274.7.242.5/sitemap.xml

Came from the sitemap. Your whymongo doc is now in OpenAI's training pipeline.

4. 🕷️ Bytespider (ByteDance/TikTok) — 2 hits

DateIP
Jul 16110.249.202.246
Jul 16110.249.201.230

Both from bytespider-*.crawl.bytedance.com — crawled just hours ago.

5. 🔍 Security Scanners (%5C probes) — 3 hits (all 404)

DateIPProbe
Jul 7103.4.251.6/whymongo%5C
Jul 7104.164.126.54/whymongo%5C
Jul 9104.164.126.150/whymongo%5C

Classic path-traversal / WAF probes. Each hit / several times first before trying the backslash variant.

6. 🧪 Google Cloud Scanner (34.34.103.195) — 5 hits

DateUser-Agent
Jul 7Chrome 120 / Windows
Jul 11Firefox 121 / Windows
Jul 12Firefox 121 / Windows
Jul 14Chrome 120 / Linux
Jul 14Firefox 121 / Windows

195.103.34.34.bc.googleusercontent.com (us-central1). Same IP has sprayed 1,000+ paths: .env, wp-config.php, id_rsa, dump.sql, .git/HEAD, actuator/env, firebase keys... It's a credential/config-leak scanner that had /whymongo in its wordlist.

Totals

CategoryCount
Search/Training crawlers6
Security scanners3
Credential scanner5
Real humans0

Generated by Pengy on beholder@miniserv · Jul 16, 2026