🇪🇸
el-brujo
2026-09-06 16:55:50
(1 hour ago)
Cloudflare WAF: Request Path: / Request Query: ?board=18 Host: foro.elhacker.net userAgent: Mozilla/ ...
show more
Cloudflare WAF: Request Path: / Request Query: ?board=18 Host: foro.elhacker.net userAgent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; SleepBot/1.0; +http://sleepbot.com/) Chrome/131.0.0.0 Safari/537.36 Action: block Source: firewallCustom ASN Description: Google LLC Country: US Method: GET Timestamp: 2026-09-06T16:55:50Z ruleId: 4821220fef034cccba731dd0aebd9cc3. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
Anonymous
2026-09-06 15:05:27
(3 hours ago)
IP matched detection query 50 and more bad rqs apache.
Hacking
Bad Web Bot
Brute-Force
Web App Attack
🇩🇪
jbcrn
2026-09-06 13:28:16
(4 hours ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /deictic-nephrostome. User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; SleepBot/1.0; +http://sleepbot.com/) Chrome/131.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
🇵🇱
sefinek.net
2026-09-05 06:31:46
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: /booru/artist/%E3%81%99%E3%81%90%E3%81%A4%E3%81%8B%E3%83%AC%E3%83%AB%E3%83%B3 | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; SleepBot/1.0; +http://sleepbot.com/) Chrome/131.0.0.0 Safari/537.36 • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇪🇸
el-brujo
2026-09-05 02:09:02
(1 day ago)
05/Sep/2026:04:09:02.064707 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
05/Sep/2026:04:09:02.064707 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 136.111.186.12] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1056"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".resources"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "vlc.elhacker.net"] [uri "/vlc-winrt/3.0.1/V
...
show less
Hacking
Web App Attack
🇬🇷
setupgr
2026-09-04 15:12:40
(2 days ago)
(mod_security) mod_security (id:11000011) triggered by 136.111.186.12 (US/United States/Iowa/Council ...
show more
(mod_security) mod_security (id:11000011) triggered by 136.111.186.12 (US/United States/Iowa/Council Bluffs/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Fri Sep 04 18:12:37.719149 2026] [security2:error] [pid 569553:tid 569647] [remote 136.111.186.12:35744] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 12.186.111.136.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "tavernadimitris.com"] [uri "/sitemap.rss"] [unique_id "aprf5UZQ_yGXwx5N6Y81pwAC0Rc"]
show less
Port Scan
🇫🇷
service Informatique
2026-09-04 04:00:37
(2 days ago)
GET /robots.txt
Web App Attack
🇸🇪
SkyDancer
2026-09-04 02:26:18
(2 days ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
🇩🇪
jbcrn
2026-09-03 17:47:41
(3 days ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /cryptographical-sleeveband. User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; SleepBot/1.0; +http://sleepbot.com/) Chrome/131.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-09-03 11:42:06
(3 days ago)
block ruleset 798ECF92F12ADC636D3520C2890AF17ADEFDE3BE
Bad Web Bot
Anonymous
2026-09-03 07:57:02
(3 days ago)
Malicious activity detected
Hacking
Web App Attack
🇺🇸
www.winos.me
2026-09-03 00:59:20
(3 days ago)
Scanning for sensitive files/paths: /wp-login.php
Hacking
Web App Attack
🇨🇦
polycoda
2026-09-02 23:05:15
(3 days ago)
📄 Probes for tons of inexistent files and/or PHP scripts
Hacking
Web App Attack
🇩🇪
jbcrn
2026-09-02 17:17:20
(4 days ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /deflagration.ficoid. User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; SleepBot/1.0; +http://sleepbot.com/) Chrome/131.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack