๐ฉ๐ช
updown.io
2026-10-09 03:26:29
(3 hours ago)
{"level":"info","ts":1791516387.8989315,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1791516387.8989315,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.246.140.96","remote_port":"60974","client_ip":"35.246.140.96","proto":"HTTP/2.0","method":"POST","host":"status.aftontickets.com","uri":"/api/graphql","headers":{"Accept-Language":["en-US,en;q=0.9"],"Origin":["https://status.aftontickets.com"],"Content-Length":["86"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Sec-Ch-Ua":["\"Chromium\";v=\"152\", \"Not?A_Brand\";v=\"24\", \"Google Chrome\";v=\"152\""],"Sec-Ch-Ua-Platform":["\"Android\""],"Accept":["*/*"],"User-Agent":["Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"],"Priority":["u=1, i"],"Sec-Ch-Ua-Mobile":["?1"],"Sec-Fetch-Mode":["cors"],"Sec-Fetch-Dest":["empty"],"Cookie":["REDACTED"],"Content-Type":["application/json"],"Sec-Fetch-Site":["same-origin"],"Referer":["https://status.aftontickets.com"]},"tls":{"resumed":false,"version":772,"cipher_su
...
show less
DDoS Attack
Web App Attack
๐ฎ๐ฉ
Burayot
2026-10-08 23:32:22
(7 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.246.140.96 (DE/Germany/96.140.246 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.246.140.96 (DE/Germany/96.140.246.35.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
Anonymous
2026-10-08 17:31:10
(13 hours ago)
malicious scanning tool activity
Web App Attack
๐ธ๐ฌ
khairilgunawan
2026-10-08 17:25:26
(13 hours ago)
ZonaKuota Sentinel: Malicious automated scanner/exploit probe trapped. Blocked.
Web App Attack
Bad Web Bot
Anonymous
2026-10-08 17:22:04
(13 hours ago)
GET / | rule: automated-client-blocked | ua: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 ( ...
show more
GET / | rule: automated-client-blocked | ua: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36 EdgA/153.0.0.0
show less
Bad Web Bot
๐ช๐ธ
pipeline.es
2026-10-08 17:21:34
(13 hours ago)
Web scanning / probing for vulnerable paths | URL: /api/graphql | Evidence: vpttours.com 35.246.140. ...
show more
Web scanning / probing for vulnerable paths | URL: /api/graphql | Evidence: vpttours.com 35.246.140.96 - - [08/Oct/2026:19:19:06 +0200] \"POST /api/graphql HTTP/2.0\" 404 26385 \"https://vpttours.com\" \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=DE 16311 | ASN: GOOGLE-CLOUD-PLATFORM | Country: DE
show less
Port Scan
Web App Attack
๐ฉ๐ช
tvipper.com
2026-10-08 17:17:02
(13 hours ago)
path traversal, vulnerability scanning and probing for exposed files and admin pages: 38 attempts wi ...
show more
path traversal, vulnerability scanning and probing for exposed files and admin pages: 38 attempts within 1 minutes, seen by web server log, WAF, fail2ban and CrowdSec (reported by RemotePower)
show less
Web App Attack
Bad Web Bot
Anonymous
2026-10-08 17:09:38
(13 hours ago)
Banned by Fail2Ban on server
Web App Attack
Anonymous
2026-10-08 17:06:18
(13 hours ago)
Web App Attack
๐ซ๐ท
dynamix
2026-10-08 17:06:04
(13 hours ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ท
setupgr
2026-10-08 17:05:33
(13 hours ago)
(mod_security) mod_security (id:11000011) triggered by 35.246.140.96 (DE/Germany/Hesse/Frankfurt am ...
show more
(mod_security) mod_security (id:11000011) triggered by 35.246.140.96 (DE/Germany/Hesse/Frankfurt am Main/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:05:33.117899 2026] [security2:error] [pid 97870:tid 325684] [remote 35.246.140.96:59856] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 96.140.246.35.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "setworldup365.com"] [uri "/"] [unique_id "asfNXApfNPlzDC_u3ovjUQADRCQ"]
show less
Port Scan
๐ซ๐ท
Stara
2026-10-08 16:58:38
(13 hours ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
๐บ๐ธ
Major Hostility
2026-10-08 16:44:17
(14 hours ago)
"GET /login HTTP/1.1" 404
"GET /users/login HTTP/1.1" 404
"GET /auth/login HTTP/1.1" 404
"GET /sign- ...
show more
"GET /login HTTP/1.1" 404
"GET /users/login HTTP/1.1" 404
"GET /auth/login HTTP/1.1" 404
"GET /sign-in HTTP/1.1" 404
"GET /account/login HTTP/1.1" 404
"GET /user/login HTTP/1.1" 404
"GET /z9x8c7v6b5-debug-trigger-[DOMAIN].com HTTP/1.1" 404
"GET /assets/manifest.json HTTP/1.1" 404
"GET /wfiaw3hx9gw1fgpvcuzt HTTP/1.1" 404
"GET /signin HTTP/1.1" 404
"GET /auth HTTP/1.1" 404
"GET /signup HTTP/1.1" 404
"GET /forgot-password HTTP/1.1" 404
"GET /register HTTP/1.1" 404
"GET /admin HTTP/1.1" 404
"GET /reset-password HTTP/1.1" 404
"POST /graphql HTTP/1.1" 404
"GET /dashboard HTTP/1.1" 404
"GET /admin/login HTTP/1.1" 404
"GET /console HTTP/1.1" 404
"GET /portal
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 16:36:52
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.246.140.96 (96.140.246.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.246.140.96 (96.140.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 12:36:46.062309 2026] [security2:error] [pid 13802:tid 13802] [client 35.246.140.96:32928] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||joeordie.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "joeordie.com"] [uri "/z9x8c7v6b5-debug-trigger-joeordie.com"] [unique_id "asfGnovbQk0lAYdoN6GyZwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 16:35:03
(14 hours ago)
suspicious request in access.log
Web App Attack