๐บ๐ธ
Secure Gatewayยฎ๏ธ
2026-10-06 22:00:33
(3 hours ago)
Report By Secure Gateway Security Team: Unsolicited Connection Attempt
SQL Injection
๐บ๐ธ
ALSCOยฎ๏ธ
2026-10-06 22:00:33
(3 hours ago)
Report By ALSCO Security Team: Unsolicited Connection Attempt
Web App Attack
๐บ๐ธ
Charlesiv
2026-10-06 18:01:14
(7 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Endpoint: /cgi-bin/php-cgi.exe
Query: ?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input
Timestamp: 2026-10-06T16:36:16Z
Ray ID: a4661582acc6c4cb
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )
show less
Bad Web Bot
๐ช๐ธ
el-brujo
2026-10-06 17:44:08
(7 hours ago)
Cloudflare WAF: Request Path: /php-cgi/php-cgi.exe Request Query: ?%ADd+allow_url_include%3d1+%ADd+a ...
show more
Cloudflare WAF: Request Path: /php-cgi/php-cgi.exe Request Query: ?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input Host: live.elhacker.net userAgent: Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/) Action: block Source: firewallCustom ASN Description: Google LLC Country: US Method: POST Timestamp: 2026-10-06T17:44:08Z ruleId: 6b2d48d0415e4adb9f099d85f54d1de6. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
๐ช๐ธ
el-brujo
2026-10-06 15:15:12
(9 hours ago)
06/Oct/2026:17:15:11.751348 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
06/Oct/2026:17:15:11.751348 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 136.67.135.237] ModSecurity: Warning. Pattern match "(?i)(?:\\\\\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "48"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /..%252f found within REQUEST_URI_RAW: /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw??"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [hostname "grafana.elhacker.net"] [uri "/@fs/..%2f..%2f..%2f..%2f..
...
show less
Hacking
Web App Attack
๐ต๐ฑ
strefapi_com
2026-10-06 11:16:52
(13 hours ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
๐ณ๐ฑ
Starburst SysOp Team
2026-10-06 11:03:00
(13 hours ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-ams6-1)
show less
Bad Web Bot
Anonymous
2026-10-06 11:01:30
(14 hours ago)
136.67.135.237 - - [06/Oct/2026:13:01:28 +0200] "-" 400 150 "-" "-"
136.67.135.237 - - [06/Oct/2026: ...
show more
136.67.135.237 - - [06/Oct/2026:13:01:28 +0200] "-" 400 150 "-" "-"
136.67.135.237 - - [06/Oct/2026:13:01:29 +0200] "-" 400 150 "-" "-"
136.67.135.237 - - [06/Oct/2026:13:01:29 +0200] "-" 400 150 "-" "-"
136.67.135.237 - - [06/Oct/2026:13:01:29 +0200] "-" 400 150 "-" "-"
136.67.135.237 - - [06/Oct/2026:13:01:30 +0200] "-" 400 150 "-" "-"
...
show less
Web App Attack
๐ฉ๐ช
raph
2026-10-06 10:55:36
(14 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-10-06 10:48:09
(14 hours ago)
06/Oct/2026:12:48:08.300415 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
06/Oct/2026:12:48:08.300415 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 136.67.135.237] ModSecurity: Warning. Pattern match "(?:;|\\\\\\\\{|\\\\\\\\||\\\\\\\\|\\\\\\\\||&|&&|\\\\\\\\n|\\\\\\\\r|\\\\\\\\$\\\\\\\\(|\\\\\\\\$\\\\\\\\(\\\\\\\\(|`|\\\\\\\\${|<\\\\\\\\(|>\\\\\\\\(|\\\\\\\\(\\\\\\\\s*\\\\\\\\))\\\\\\\\s*(?:{|\\\\\\\\s*\\\\\\\\(\\\\\\\\s*|\\\\\\\\w+=(?:[^\\\\\\\\s]*|\\\\\\\\$.*|\\\\\\\\$.*|<.*|>.*|\\\\\\\\'.*\\\\\\\\'|\\\\".*\\\\")\\\\\\\\s+|!\\\\\\\\s*|\\\\\\\\$)*\\\\\\\\s*(?:'|\\\\")*(?:[\\\\\\\\?\\\\\\\\*\\\\\\\\[\\\\\\\\]\\\\\\\\(\\\\\\\\)\\\\\\\\-\\\\\\\\|+\\\\\\\\w'\\\\"\\\\\\\\./\\\\\\\\\\\\\\\\]+/)?[\\\\\\\\\\\\\\\\'\\\\"]*(?:s[\\\\\\\\\\\\\\\\'\\\\"]* ..." at ARGS_NAMES:<?php echo shell_exec('env 2>/dev/null || set 2>nul'); die(); ?>. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "159"] [id "932105"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: || set 2>nul')
...
show less
Hacking
Web App Attack
๐บ๐ธ
daveoctober
2026-10-06 10:19:09
(14 hours ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
๐บ๐ธ
Charlesiv
2026-10-06 10:01:09
(15 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Endpoint: /index.php
Query: ?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input
Timestamp: 2026-10-06T08:44:26Z
Ray ID: a463625a1f567645
UA: Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)
show less
Bad Web Bot
๐ฉ๐ช
s@ch@
2026-10-06 10:00:02
(15 hours ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack
๐ฉ๐ช
AetherFox
2026-10-06 09:54:12
(15 hours ago)
AetherFox VoidGuard detected: [Tue Oct 06 09:54:11.989631 2026] [authz_core:error] [pid 1580532:tid ...
show more
AetherFox VoidGuard detected: [Tue Oct 06 09:54:11.989631 2026] [authz_core:error] [pid 1580532:tid 1580536] [client 136.67.135.237:56778] AH01630: client denied by server configuration: proxy:https://freebeegee.draconigen.de/fd1c156su5gh2lfg0hp3
[Tue Oct 06 09:54:11.989817 2026] [authz_core:error] [pid 1580532:tid 1580536] [client 136.67.135.237:56778] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Tue Oct 06 09:54:11.997943 2026] [authz_core:error] [pid 1580532:tid 1580539] [client 136.67.135.237:56708] AH01630: client denied by server configuration: proxy:https://freebeegee.draconigen.de/lib/terminal-xhr.php
[Tue Oct 06 09:54:11.998315 2026] [authz_core:error] [pid 1580532:tid 1580539] [client 136.67.135.237:56708] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Tue Oct 06 09:54:12.003635 2026] [authz_core:error] [pid 1580533:tid 1580585] [client 136.67.135.237:56780] AH01630: client denied by
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
NotCool
2026-10-06 09:33:36
(15 hours ago)
[7200] (CRAWLDELAY,DOTENVPROBE) Login failure/trigger from 136.67.135.237 (US/United States/237.135. ...
show more
[7200] (CRAWLDELAY,DOTENVPROBE) Login failure/trigger from 136.67.135.237 (US/United States/237.135.67.136.bc.googleusercontent.com): 50 in the last 3600 secs
show less
Brute-Force