Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-15.
show less
150 attacks on password grabbing URLs, VC URLs, deployment descriptor URLs, config grabbing URLs (ty ...
show more150 attacks on password grabbing URLs, VC URLs, deployment descriptor URLs, config grabbing URLs (type 2), site downloads, PHP URLs, env grabbing URLs:
GET /admin/config?cmd=cat+/root/.aws/credentials HTTP/1.1
GET /.git/config HTTP/1.1
GET /WEB-INF/web.xml HTTP/1.1
GET /appsettings.Development.json HTTP/1.1
GET /database.sql HTTP/1.1
GET /config.php.bak HTTP/1.1
GET /aws/.env HTTP/1.1
show less
{"level":"info","ts":1786846888.9346685,"logger":"http.log.access.log0","msg":"handled request","req ...
show more{"level":"info","ts":1786846888.9346685,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.91.51.199","remote_port":"2346","client_ip":"34.91.51.199","proto":"HTTP/1.1","method":"GET","host":"mijh.status.updown.io","uri":"/.mcp.json","headers":{"Accept-Language":["en-US,en;q=0.9"],"Accept-Encoding":["gzip"],"User-Agent":["Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"mijh.status.updown.io","ech":false}},"bytes_read":0,"user_id":"","duration":0.000506096,"size":0,"status":429,"resp_headers":{"Retry-After":["1"],"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"]}}
{"level":"info","ts":1786846888.9411147,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.91.51.199","remote_port":"2356","client_ip":"34.91.51.199","prot
...
show less
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show moreInbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Possible Remote File Inclusion (RFI) Attack: URL Parameter using IP Address. Pattern match "^(?i:fil ...
show morePossible Remote File Inclusion (RFI) Attack: URL Parameter using IP Address. Pattern match "^(?i:file|ftps?|https?)://(?:\\\\d{1,3}\\\\.\\\\d{1,3}\\\\.\\\\d{1,3}\\\\.\\\\d{1,3})" at ARGS:uri. (931100-195)
show less
Hacking
Anonymous
Multiple web server 400 error codes from same source ip