🇪🇸
el-brujo
2026-08-30 16:41:44
(23 minutes ago)
Cloudflare WAF: Request Path: /wp-config.php.bak Request Query: Host: elhacker.net userAgent: Mozil ...
show more
Cloudflare WAF: Request Path: /wp-config.php.bak Request Query: Host: elhacker.net userAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Edg/149.0.0.0 Action: block Source: firewallManaged ASN Description: Amazon.com, Inc. Country: SG Method: GET Timestamp: 2026-08-30T16:41:44Z ruleId: 7994335d116849f7a0ab6b771d1d0db7. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
🇪🇸
el-brujo
2026-08-30 16:04:17
(1 hour ago)
13.214.34.236 - - [30/Aug/2026:18:04:16 +0200] "GET /dist/manifest.json HTTP/2.0" 404 15954 "-" "Moz ...
show more
13.214.34.236 - - [30/Aug/2026:18:04:16 +0200] "GET /dist/manifest.json HTTP/2.0" 404 15954 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Edg/149.0.0.0"
13.214.34.236 - - [30/Aug/2026:18:04:16 +0200] "GET /.vite/manifest.json HTTP/2.0" 404 15954 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Edg/149.0.0.0"
13.214.34.236 - - [30/Aug/2026:18:04:16 +0200] "GET /build/manifest.json HTTP/2.0" 404 15954 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Edg/149.0.0.0"
...
show less
DDoS Attack
Hacking
🇳🇱
BlueWire Hosting
2026-08-30 15:48:03
(1 hour ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇫🇷
bazter.pro
2026-08-30 15:08:38
(1 hour ago)
Auto-Ban [2026-08-30 18:08:38]: CRITICAL: .env attack; DC: Amazon Data Services Singapore [Paths: 33 ...
show more
Auto-Ban [2026-08-30 18:08:38]: CRITICAL: .env attack; DC: Amazon Data Services Singapore [Paths: 33] | Details: Exploit trap paths: /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ, /@fs/.env?url&raw??, /@fs/.env?raw&url??, /@fs/.env?import&?raw??, /storage/logs/laravel.log | Sensitive files/paths: /admin%2F.env, /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ, /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env, /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env, /settings%2F.env | 404 errors (29): /public/.env, /.env.swp, /graphql, /.env.dev, /dashboard%2F.env, /@fs/.env?import&?raw??, /laravel/.env, /admin%2F.env, /storage/.env, /@fs/.env?raw&url?? (and 19 more) | Other paths: /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ, /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ, /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env, /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env
show less
Web App Attack
Hacking
🇩🇪
arnisolutions
2026-08-30 14:40:48
(2 hours ago)
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production s ...
show more
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production server. Observed on 1 day(s) between 2026-08-30 and 2026-08-30 (UTC). Sample request: GET /wp-includes/js/dist/vendor/regenerator-runtime.min.js?ver=0.13.11 HTTP/2.0
show less
Web App Attack
Hacking
🇩🇪
maxpower
2026-08-30 14:30:15
(2 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 13.214.34.236 (SG/Singapore/ec2-13-214-3 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 13.214.34.236 (SG/Singapore/ec2-13-214-34-236.ap-southeast-1.compute.amazonaws.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 13.214.34.236 - - [30/Aug/2026:16:30:10 +0200] "GET /@fs/root/.aws/credentials?raw?? HTTP/2.0" 200 4742 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Mobile Safari/537.36" "10.20.195.48" host=ftp.ctpescara.it
show less
Port Scan
Anonymous
2026-08-30 14:27:05
(2 hours ago)
(caddyscan) Scanner path probe from 13.214.34.236 (SG/Singapore/ec2-13-214-34-236.ap-southeast-1.com ...
show more
(caddyscan) Scanner path probe from 13.214.34.236 (SG/Singapore/ec2-13-214-34-236.ap-southeast-1.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 13.214.34.236 - - [30/Aug/2026:14:26:59 +0000] "GET /@fs/.env?url&raw?? HTTP/1.1"
[REDACTED] 200 2627 13.214.34.236 - - [30/Aug/2026:14:26:59 +0000] "GET /@fs/.env?import&?raw?? HTTP/1.1"
[REDACTED] 200 2627 13.214.34.236 - - [30/Aug/2026:14:26:59 +0000] "GET /@fs/.env?raw&url?? HTTP/1.1"
[REDACTED] 200 2627 13.214.34.236 - - [30/Aug/2026:14:27:00 +0000] "GET /.env.php.bak HTTP/1.1"
[REDACTED] 200 2627 13.214.34.236 - - [30/Aug/2026:14:27:02 +0000] "GET /config/.env.php HTTP/1.1"
show less
Port Scan
🇸🇪
vaia.cloud
2026-08-30 13:25:01
(3 hours ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
🇫🇮
paissangroup
2026-08-30 13:01:10
(4 hours ago)
Multiple WAF Violations
Web App Attack
🇦🇺
rubixstudios
2026-08-30 12:17:02
(4 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇩🇪
raph
2026-08-30 11:26:06
(5 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
Anonymous
2026-08-30 10:58:26
(6 hours ago)
13.214.34.236 - - [30/Aug/2026:12:58:11 +0200] "GET /.aws/credentials HTTP/1.1" 403 525 "-" "Mozilla ...
show more
13.214.34.236 - - [30/Aug/2026:12:58:11 +0200] "GET /.aws/credentials HTTP/1.1" 403 525 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
13.214.34.236 - - [30/Aug/2026:12:58:12 +0200] "GET /manifest.json HTTP/1.1" 404 5519 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
13.214.34.236 - - [30/Aug/2026:12:58:12 +0200] "GET /asset-manifest.json HTTP/1.1" 404 5519 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
13.214.34.236 - - [30/Aug/2026:12:58:12 +0200] "GET /.git/config HTTP/1.1" 403 525 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
13.214.34.236 - - [30/Aug/2026:12:58:12 +0200] "GET /webpack-stats.json HTTP/1.1" 404 5519 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Ch
...
show less
DDoS Attack
🇳🇱
ConsulHosting
2026-08-30 09:59:49
(7 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇪🇸
el-brujo
2026-08-30 09:25:24
(7 hours ago)
13.214.34.236 - - [30/Aug/2026:11:25:23 +0200] "GET /.vite/manifest.json HTTP/2.0" 404 4620 "-" "Moz ...
show more
13.214.34.236 - - [30/Aug/2026:11:25:23 +0200] "GET /.vite/manifest.json HTTP/2.0" 404 4620 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Edg/149.0.0.0"
13.214.34.236 - - [30/Aug/2026:11:25:24 +0200] "GET /dist/.vite/manifest.json HTTP/2.0" 404 4620 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Edg/149.0.0.0"
13.214.34.236 - - [30/Aug/2026:11:25:24 +0200] "GET /dist/manifest.json HTTP/2.0" 404 4620 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Edg/149.0.0.0"
...
show less
DDoS Attack
Hacking
🇺🇸
cwytech
2026-08-30 08:31:12
(8 hours ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/wordpress-geofence-sus.
Bad Web Bot
Web App Attack