๐ฎ๐น
CoreTech srl
2026-09-18 23:39:31
(1 day ago)
[DC: IP:151.1.252.27] ntopng alert: blacklisted_client_contact
Hacking
๐จ๐ฆ
Anytech
2026-09-18 18:38:32
(2 days ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
๐ซ๐ฎ
paissangroup
2026-09-18 17:25:51
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-18 17:08:18
(2 days ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.140.208.125 - - [18/Sep/2026:19:08:10 +0200] "GET /.github/.env HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
...
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-09-18 14:38:00
(2 days ago)
HTTP DDoS Attack Layer 7
DDoS Attack
Anonymous
2026-09-18 13:21:30
(2 days ago)
Portscan: TCP/8443 (7x), TCP/8080 (7x), TCP/80, TCP/443
Port Scan
๐ช๐ธ
el-brujo
2026-09-18 10:36:54
(2 days ago)
34.140.208.125 - - [18/Sep/2026:12:36:54 +0200] "GET /docker-compose.yaml HTTP/2.0" 404 15997 "-" "M ...
show more
34.140.208.125 - - [18/Sep/2026:12:36:54 +0200] "GET /docker-compose.yaml HTTP/2.0" 404 15997 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.140.208.125 - - [18/Sep/2026:12:36:54 +0200] "GET /rclone.conf HTTP/2.0" 404 15997 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
34.140.208.125 - - [18/Sep/2026:12:36:54 +0200] "GET /.vite/manifest.json HTTP/2.0" 404 15997 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
34.140.208.125 - - [18/Sep/2026:12:36:54 +0200] "GET /build/manifest.json HTTP/2.0" 404 15997 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
...
show less
Web App Attack
Hacking
๐ฉ๐ช
itsolon
2026-09-18 10:31:02
(2 days ago)
[18/Sep/2026:12:31:02 +0200] 178972746216.982242 34.140.208.125 49168 217.154.7.177 443
[18/Sep/2026 ...
show more
[18/Sep/2026:12:31:02 +0200] 178972746216.982242 34.140.208.125 49168 217.154.7.177 443
[18/Sep/2026:12:31:02 +0200] 178972746224.220868 34.140.208.125 49168 217.154.7.177 443
[18/Sep/2026:12:31:02 +0200] 178972746276.102575 34.140.208.125 49168 217.154.7.177 443
[18/Sep/2026:12:31:02 +0200] 178972746272.747512 34.140.208.125 49168 217.154.7.177 443
[18/Sep/2026:12:31:02 +0200] 178972746256.432005 34.140.208.125 49168 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ช๐ธ
el-brujo
2026-09-18 08:44:09
(2 days ago)
Cloudflare WAF: Request Path: /.github/.env Request Query: Host: mysql.elhacker.net:8443 userAgent: ...
show more
Cloudflare WAF: Request Path: /.github/.env Request Query: Host: mysql.elhacker.net:8443 userAgent: Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler) Action: block Source: firewallManaged ASN Description: Google LLC Country: BE Method: GET Timestamp: 2026-09-18T08:44:09Z ruleId: 23548ee2b36547a1be09bb2c0550c529. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
๐ช๐ธ
el-brujo
2026-09-18 08:25:04
(2 days ago)
34.140.208.125 - - [18/Sep/2026:10:25:03 +0200] "GET /_nuxt/../.env HTTP/2.0" 403 199 "-" "Mozilla/5 ...
show more
34.140.208.125 - - [18/Sep/2026:10:25:03 +0200] "GET /_nuxt/../.env HTTP/2.0" 403 199 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.140.208.125 - - [18/Sep/2026:10:25:03 +0200] "GET /@fs/../.env?raw?? HTTP/2.0" 403 199 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.140.208.125 - - [18/Sep/2026:10:25:03 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/2.0" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
34.140.208.125 - - [18/Sep/2026:10:25:03 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/2.0" 403 199 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.140.208.125 - - [18/Sep/2026:10:25:03 +0200] "GET /%2e%2e/.env HTTP/2.0" 400 226 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
34.140.208.125 - - [18/Sep/2026:10:25:04 +0200] "GET /
...
show less
DDoS Attack
Hacking
๐ช๐ธ
el-brujo
2026-09-18 07:43:00
(2 days ago)
18/Sep/2026:09:43:00.275716 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
18/Sep/2026:09:43:00.275716 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 34.140.208.125] ModSecurity: Warning. Pattern match "(?i)(?:\\\\\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "48"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /..%252f found within REQUEST_URI_RAW: /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw??"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [hostname "grafana.elhacker.net"] [uri "/@fs/..%2f..%2f..%2f..%2f..
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2026-09-18 06:40:52
(2 days ago)
Cloudflare WAF: Request Path: /api/inngest Request Query: Host: chat.elhacker.net:8443 userAgent: M ...
show more
Cloudflare WAF: Request Path: /api/inngest Request Query: Host: chat.elhacker.net:8443 userAgent: Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/) Action: block Source: firewallManaged ASN Description: Google LLC Country: BE Method: DELETE Timestamp: 2026-09-18T06:40:52Z ruleId: 8e361ee4328f4a3caf6caf3e664ed6fe. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-18 03:36:25
(2 days ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-18 03:12:34
(2 days ago)
20 attempts against mh-misbehave-ban on onion
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-18 02:48:27
(2 days ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack