Anonymous
2026-10-08 16:59:57
(1 minute ago)
Web App Attack
๐ช๐ธ
el-brujo
2026-10-08 16:50:44
(11 minutes ago)
Cloudflare WAF: Request Path: /wp-css.php Request Query: Host: hwagm.elhacker.net userAgent: Actio ...
show more
Cloudflare WAF: Request Path: /wp-css.php Request Query: Host: hwagm.elhacker.net userAgent: Action: block Source: firewallCustom ASN Description: Microsoft Corporation Country: KR Method: GET Timestamp: 2026-10-08T16:50:44Z ruleId: b5ebfc56c6c14a5fbe89a464530cebf6. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
๐ฉ๐ช
kkwemi
2026-10-08 16:48:38
(13 minutes ago)
Blocked by allow2ban-hard-stop on /admin.php
Bad Web Bot
Anonymous
2026-10-08 16:48:23
(13 minutes ago)
Automated Report: Fail2Ban block triggered by nginx-botsearch jail.
Brute-Force
SSH
๐ฌ๐ท
setupgr
2026-10-08 16:45:43
(16 minutes ago)
(mod_security) mod_security (id:1000001) triggered by 20.194.96.114 (KR/South Korea/Seoul/Seoul/-/[A ...
show more
(mod_security) mod_security (id:1000001) triggered by 20.194.96.114 (KR/South Korea/Seoul/Seoul/-/[AS8075 Microsoft Corporation]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:45:39.957400 2026] [security2:error] [pid 208507:tid 208517] [remote 20.194.96.114:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/about.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "103"] [id "1000001"] [msg "Bad file blocked: /about.php"] [severity "CRITICAL"] [tag "security"] [hostname "endoscope.center"] [uri "/about.php"] [unique_id "asfIs4uaZYeZ0Q9YS7VPNgAAEQk"]
show less
Port Scan
Anonymous
2026-10-08 16:38:01
(23 minutes ago)
20.194.96.114 - - [09/Oct/2026:00:38:00 +0800] "GET /.well-known/acme-challenge/index.php HTTP/1.1" ...
show more
20.194.96.114 - - [09/Oct/2026:00:38:00 +0800] "GET /.well-known/acme-challenge/index.php HTTP/1.1" 404 212968 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
JLKnoch Software GmbH
2026-10-08 16:37:40
(24 minutes ago)
CrowdSec crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
ruusvuu
2026-10-08 16:37:12
(24 minutes ago)
Automated abuse report: 84 attack/probe requests from Microsoft Corporation / KR.
Targeted paths: /f ...
show more
Automated abuse report: 84 attack/probe requests from Microsoft Corporation / KR.
Targeted paths: /file56.php, /wp-includes/PHPMailer/admin.php, /wp-admin/css/index.php, /wp-content/edit.php, /2.php.
Sample log lines:
[istood] 20.194.96.114 - - [08/Oct/2026:09:54:12 +0000] "GET /rip.php HTTP/1.1" - - "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.3โฆ
[istood] 20.194.96.114 - - [08/Oct/2026:09:54:12 +0000] "GET /php.php HTTP/1.1" - - "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.3โฆ
[helpdesk] 10/8/2026 09:37:12 20.194.96.114 GET /public/css.php 404 153 1.0 ms
Detected by an automated web-server log monitor.
show less
Web App Attack
๐ง๐ท
ufn.edu.br
2026-10-08 16:33:08
(28 minutes ago)
[Thu Oct 08 13:33:02.386903 2026] [access_compat:error] [pid 6299] [client 20.194.96.114:38388] AH01 ...
show more
[Thu Oct 08 13:33:02.386903 2026] [access_compat:error] [pid 6299] [client 20.194.96.114:38388] AH01797: client denied by server configuration: /var/www/html/this_is_a_new_hello_world.php
[Thu Oct 08 13:33:07.251107 2026] [access_compat:error] [pid 6299] [client 20.194.96.114:38388] AH01797: client denied by server configuration: /var/www/html/wsd.php
[Thu Oct 08 13:33:07.568979 2026] [access_compat:error] [pid 6299] [client 20.194.96.114:38388] AH01797: client denied by server configuration: /var/www/html/go.php
...
show less
Exploited Host
Web App Attack
๐ณ๐ฑ
debestelapp
2026-10-08 16:20:01
(41 minutes ago)
Web App Attack
๐ง๐ท
ufn.edu.br
2026-10-08 16:16:51
(44 minutes ago)
[Thu Oct 08 13:16:50.097469 2026] [access_compat:error] [pid 20635] [client 20.194.96.114:46099] AH0 ...
show more
[Thu Oct 08 13:16:50.097469 2026] [access_compat:error] [pid 20635] [client 20.194.96.114:46099] AH01797: client denied by server configuration: /var/www/html/this_is_a_new_hello_world.php
[Thu Oct 08 13:16:50.400836 2026] [access_compat:error] [pid 20635] [client 20.194.96.114:46099] AH01797: client denied by server configuration: /var/www/html/wsd.php
[Thu Oct 08 13:16:50.703899 2026] [access_compat:error] [pid 20635] [client 20.194.96.114:46099] AH01797: client denied by server configuration: /var/www/html/go.php
...
show less
Exploited Host
Web App Attack
๐บ๐ธ
mc4bbs
2026-10-08 16:10:04
(51 minutes ago)
Automated Apache detection on Windows host. 5 suspicious HTTP requests within 300 seconds. Examples: ...
show more
Automated Apache detection on Windows host. 5 suspicious HTTP requests within 300 seconds. Examples: GET /wp-content/plugins/hellopress/wp_filemanager.php -> 404 UA=""; GET /wp-admin/ -> 404 UA=""; GET /wp-content/admin.php -> 404 UA=""; GET /wp-content/index.php -> 404 UA=""; GET /wp-admin/wp.php -> 404 UA=""
show less
Web App Attack
Hacking
๐ซ๐ท
regishoussin
2026-10-08 16:09:47
(51 minutes ago)
Automated web scanning detected by Wazuh (rule 100180): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100180): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-10-08 16:09 UTC.
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
yvoictra
2026-10-08 16:06:39
(55 minutes ago)
20.194.96.114 - - [08/Oct/2026:18:06:36 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.ph ...
show more
20.194.96.114 - - [08/Oct/2026:18:06:36 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 404 19 "-" "-"
20.194.96.114 - - [08/Oct/2026:18:06:37 +0200] "GET /this_is_a_new_hello_world.php HTTP/1.1" 404 19 "-" "-"
20.194.96.114 - - [08/Oct/2026:18:06:37 +0200] "GET /wsd.php HTTP/1.1" 404 19 "-" "-"
20.194.96.114 - - [08/Oct/2026:18:06:38 +0200] "GET /go.php HTTP/1.1" 404 19 "-" "-"
20.194.96.114 - - [08/Oct/2026:18:06:38 +0200] "GET /z60.php?p= HTTP/1.1" 404 19 "-" "-"
...
show less
Brute-Force
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-10-08 16:06:01
(55 minutes ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack