πΊπΈ
ipblock.com
2026-02-27 02:11:00
(4 months ago)
IPBlock protected site ID [4055-d][s=07].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-02-26 22:05:10
(4 months ago)
Blocked: Reason='Vulnerability probing β PHP scan detected (17/60 min)'; Requests=17
Port Scan
πΊπΈ
jlcorrea
2026-02-26 20:45:10
(4 months ago)
#malware explotaciΓ³n CVE-2017-9841.
Brute-Force
SSH
π«π·
masterguru
2026-02-25 22:05:10
(4 months ago)
GET or HEAD Request with Body Content. Match of "rx ^0?$" against "REQUEST_HEADERS:Content-Length" r ...
show more
GET or HEAD Request with Body Content. Match of "rx ^0?$" against "REQUEST_HEADERS:Content-Length" required. (920170-135)
show less
Hacking
Anonymous
2026-02-25 08:06:20
(4 months ago)
"GET /vendor/phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1"
Hacking
Web App Attack
π¬π§
CrystalMaker
2026-01-08 07:59:20
(5 months ago)
Vulnerability scan - GET /_fragment?_path=_controller%3Dphpcredits%26flag%3D2&_hash=Lelo2bS9/73ardUc ...
show more
Vulnerability scan - GET /_fragment?_path=_controller%3Dphpcredits%26flag%3D2&_hash=Lelo2bS9/73ardUc96i5I6Bh0Iz/lls5CeIL1OmyI8I=
show less
Hacking
πͺπΈ
el-brujo
2026-01-07 07:19:50
(5 months ago)
Cloudflare WAF: Request Path: /wp-admin/admin-ajax.php Request Query: Host: warzone.elhacker.net us ...
show more
Cloudflare WAF: Request Path: /wp-admin/admin-ajax.php Request Query: Host: warzone.elhacker.net userAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36 Action: block Source: firewallManaged ASN Description: CTGSERVERLIMITED-AS-AP CTG Server Limited Country: JP Method: POST Timestamp: 2026-01-07T07:19:50Z ruleId: 390b6273c8dc4366b36e52fc6f35c356. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
πͺπΈ
el-brujo
2026-01-07 06:49:44
(5 months ago)
Cloudflare WAF: Request Path: /wp-content/plugins/web-portal-lite-client-portal-secure-file-sharing- ...
show more
Cloudflare WAF: Request Path: /wp-content/plugins/web-portal-lite-client-portal-secure-file-sharing-private-messaging/includes/libs/pdf/dompdf.php Request Query: ?input_file=php://filter/resource=/etc/passwd Host: warzone.elhacker.net userAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Mobile/15E148 Safari/604.1 Action: block Source: firewallManaged ASN Description: CTGSERVERLIMITED-AS-AP CTG Server Limited Country: JP Method: GET Timestamp: 2026-01-07T06:49:44Z ruleId: 65ff155bc71c4f6cb147e323945fae29. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
πͺπΈ
el-brujo
2026-01-07 06:40:23
(5 months ago)
Cloudflare WAF: Request Path: /webadm/ Request Query: ?q=moni_detail.do&action=gragh Host: warzone.e ...
show more
Cloudflare WAF: Request Path: /webadm/ Request Query: ?q=moni_detail.do&action=gragh Host: warzone.elhacker.net userAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:133.0) Gecko/20100101 Firefox/133.0 Action: log Source: firewallManaged ASN Description: CTGSERVERLIMITED-AS-AP CTG Server Limited Country: JP Method: POST Timestamp: 2026-01-07T06:40:23Z ruleId: e35c9a670b864a3ba0203ffb1bc977d1. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
π±π»
garmtech.com
2025-12-10 03:32:51
(6 months ago)
IM360 WAF: PHP Injection Attack: I/O Stream Found MV:d cgi.force_redirect=0 d disable_functions="" d ...
show more
IM360 WAF: PHP Injection Attack: I/O Stream Found MV:d cgi.force_redirect=0 d disable_functions="" d allow_url_include=1 d auto_prepend_file=php://input
show less
Web App Attack
π©πͺ
paissangroup
2025-12-09 12:25:56
(6 months ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-09 10:59:46
(6 months ago)
(mod_security) mod_security (id:211190) triggered by 134.122.140.210 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:211190) triggered by 134.122.140.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 05:59:42.493330 2025] [security2:error] [pid 25677:tid 25677] [client 134.122.140.210:51470] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||dev.ericadamsdesign.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /sites/all/modules/avatar_uploader/lib/demo/view.php?file=../../../../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dev.ericadamsdesign.com"] [uri "/sites/all/modules/avatar_uploader/lib/demo/view.php"] [unique_id "aTgBHn6ZwmqF398Jx4cCyAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-09 10:43:41
(6 months ago)
(mod_security) mod_security (id:211190) triggered by 134.122.140.210 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:211190) triggered by 134.122.140.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 05:43:34.952857 2025] [security2:error] [pid 19380:tid 19380] [client 134.122.140.210:38024] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||dancingmountainsbrewing.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /sites/all/modules/avatar_uploader/lib/demo/view.php?file=../../../../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dancingmountainsbrewing.com"] [uri "/sites/all/modules/avatar_uploader/lib/demo/view.php"] [unique_id "aTf9VhUgf6W04pXU7wD6SAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-09 09:27:18
(6 months ago)
(mod_security) mod_security (id:211190) triggered by 134.122.140.210 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:211190) triggered by 134.122.140.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 04:27:10.970800 2025] [security2:error] [pid 30709:tid 30709] [client 134.122.140.210:42072] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||btsalesrep.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /sites/all/modules/avatar_uploader/lib/demo/view.php?file=../../../../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "btsalesrep.com"] [uri "/sites/all/modules/avatar_uploader/lib/demo/view.php"] [unique_id "aTfrbnlG2JhbrSvlLRAXOQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
kosada.com
2025-12-09 09:21:30
(6 months ago)
Web bot cloaking: Firefox/3.0
Bad Web Bot