๐ฉ๐ช
updown.io
2026-09-21 05:14:17
(17 hours ago)
{"level":"info","ts":1789967655.0800297,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1789967655.0800297,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.196.237.164","remote_port":"60912","client_ip":"35.196.237.164","proto":"HTTP/2.0","method":"GET","host":"status.lynxtransmit.com","uri":"/dist/manifest.json","headers":{"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8"],"Sec-Fetch-User":["?1"],"Sec-Ch-Ua-Platform":["\"Android\""],"Priority":["u=0, i"],"X-Nextjs-Data":["1"],"Sec-Fetch-Site":["none"],"Sec-Ch-Ua-Mobile":["?1"],"Upgrade-Insecure-Requests":["1"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Sec-Fetch-Dest":["document"],"Sec-Fetch-Mode":["navigate"],"User-Agent":["Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"],"Accept-Language":["en-US,en;q=0.9"],"Sec-Ch-Ua":["\"Chromium\";v=\"152\", \"Not?A_Brand\";v=\"24\", \"Microsoft Edge\";v=\"152\""],"X-Middleware-Subrequest":["src/mid
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
mnsf
2026-09-21 04:05:25
(18 hours ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:04:31
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.196.237.164 (164.237.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.196.237.164 (164.237.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:04:26.978882 2026] [security2:error] [pid 24447:tid 24569] [client 35.196.237.164:45426] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nimbll.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nimbll.com"] [uri "/localhost.key"] [unique_id "arCeuvzEoV0VPutBAZW3dgAAAZY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:56:41
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.237.164 (164.237.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.237.164 (164.237.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:56:38.458591 2026] [security2:error] [pid 28712:tid 28712] [client 35.196.237.164:56204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.njonker.com"] [uri "/.git/HEAD"] [unique_id "arCAxuEFZdS03OD2RWQbsQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:21:48
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.237.164 (164.237.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.237.164 (164.237.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:21:42.724755 2026] [security2:error] [pid 15241:tid 15241] [client 35.196.237.164:34512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.innovacionesnimba.com"] [uri "/.git/HEAD"] [unique_id "arB4lvKF7H1sbG2moXk4LwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:11:28
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.237.164 (164.237.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.237.164 (164.237.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:11:21.370451 2026] [security2:error] [pid 23356:tid 23356] [client 35.196.237.164:42156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.norbertesser.com"] [uri "/project/.env"] [unique_id "arBoGY5XqQ6Fup77poSZKwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-20 21:50:01
(1 day ago)
crowdsecurity/grafana-cve-2021-43798
Brute-Force
Web App Attack
Anonymous
2026-09-20 21:07:56
(1 day ago)
git/env leak probe
Web App Attack
๐ซ๐ท
dynamix
2026-09-20 20:41:41
(1 day ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-20 20:20:03
(1 day ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐จ๐ฆ
zXero
2026-09-20 20:02:51
(1 day ago)
Fail2Ban automatic report - jail: web-exploit
Brute-Force
SSH
DDoS Attack
Anonymous
2026-09-20 19:34:46
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
OceanTreasure
2026-09-20 16:50:53
(1 day ago)
tcp/8080; Unsolicited SYN to a port that has never been offered on this address (closed, no service ...
show more
tcp/8080; Unsolicited SYN to a port that has never been offered on this address (closed, no service ever) @ 2026-09-20T16:47:25Z
show less
Port Scan