๐ช๐ธ
el-brujo
2026-09-19 14:49:10
(2 hours ago)
34.143.171.96 - - [19/Sep/2026:16:49:09 +0200] "GET /.env.local?import&raw HTTP/2.0" 404 15989 "-" " ...
show more
34.143.171.96 - - [19/Sep/2026:16:49:09 +0200] "GET /.env.local?import&raw HTTP/2.0" 404 15989 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.143.171.96 - - [19/Sep/2026:16:49:10 +0200] "GET /.env.local?raw HTTP/2.0" 404 15989 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
34.143.171.96 - - [19/Sep/2026:16:49:10 +0200] "GET /.vite/manifest.json HTTP/2.0" 404 15989 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
34.143.171.96 - - [19/Sep/2026:16:49:10 +0200] "GET /dist/manifest.json HTTP/2.0" 404 15989 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
...
show less
Web App Attack
Hacking
๐ณ๐ฑ
Savvii
2026-09-19 14:48:15
(2 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-19 14:41:36
(2 hours ago)
[BestVouchers.net] Honeypot trap triggered | Path: /.env | Time: 2026-09-19T14:41:36.799Z | UA: Mozi ...
show more
[BestVouchers.net] Honeypot trap triggered | Path: /.env | Time: 2026-09-19T14:41:36.799Z | UA: Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/) | Action: Automatically blocked for 24h and reported
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-19 14:19:13
(3 hours ago)
http scanning for .env files
...
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2026-09-19 13:35:47
(3 hours ago)
Cloudflare WAF: Request Path: /api/templates/preview Request Query: Host: wiki.elhacker.net userAge ...
show more
Cloudflare WAF: Request Path: /api/templates/preview Request Query: Host: wiki.elhacker.net userAgent: Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/) Action: block Source: firewallManaged ASN Description: Google LLC Country: SG Method: POST Timestamp: 2026-09-19T13:35:47Z ruleId: e7e4b386797e417c998d872956c390a1. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
slay3r9903
2026-09-19 13:21:34
(4 hours ago)
IP address blocked by Cloudflare security rules due to suspicious activity and security violations.
Hacking
Bad Web Bot
๐ฑ๐ป
garmtech.com
2026-09-19 12:51:22
(4 hours ago)
Attempted access to sensitive endpoint (/login) detected. Automated scan or unauthorized probing.
Web App Attack
๐บ๐ธ
Charlesiv
2026-09-19 12:11:45
(5 hours ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /public../.env
Timestamp: 2026-09-19T11:28:43Z
Ray ID: a3d83f9e5a0ba8d3
UA: Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)
show less
Bad Web Bot
๐บ๐ธ
Charlesiv
2026-09-19 06:01:51
(11 hours ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /
Timestamp: 2026-09-19T00:20:25Z
Ray ID: a3d46caa1ae8d976
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )
show less
Bad Web Bot
๐ฌ๐ง
NotCool
2026-09-19 05:39:05
(11 hours ago)
(CRAWLDELAY) Generic Bot Crawl-delay Violation 34.143.171.96 (SG/Singapore/96.171.143.34.bc.googleus ...
show more
(CRAWLDELAY) Generic Bot Crawl-delay Violation 34.143.171.96 (SG/Singapore/96.171.143.34.bc.googleusercontent.com): 50 in the last 3600 secs
show less
Bad Web Bot
๐ฎ๐ฉ
Burayot
2026-09-19 02:34:24
(14 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.143.171.96 (SG/Singapore/96.171.1 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.143.171.96 (SG/Singapore/96.171.143.34.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐ช๐ธ
el-brujo
2026-09-19 01:13:54
(16 hours ago)
19/Sep/2026:03:13:54.016605 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
19/Sep/2026:03:13:54.016605 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 34.143.171.96] ModSecurity: Warning. Matched phrase ".docker/" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .docker/ found within REQUEST_FILENAME: /.docker/config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "ns2.elhacker.net"] [uri "/.docker/config.json"] [unique_id "aq3h0p_GcIuOJl8iuYtiqABeS2w"]
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-19 00:19:05
(17 hours ago)
[ti-01al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-01al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.143.171.96 - - [19/Sep/2026:02:18:56 +0200] "GET /backoffice HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.143.171.96 - - [19/Sep/2026:02:18:56 +0200] "GET /app HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.143.171.96 - - [19/Sep/2026:02:18:56 +0200] "GET /terraform.tfstate HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
34.143.171.96 - - [19/Sep/2026:02:18:56 +0200] "GET /portal HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-18 23:16:06
(18 hours ago)
34.143.171.96 - - [19/Sep/2026:01:16:05 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/sel ...
show more
34.143.171.96 - - [19/Sep/2026:01:16:05 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 150 "-" "-"
34.143.171.96 - - [19/Sep/2026:01:16:05 +0200] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env HTTP/1.1" 400 150 "-" "-"
34.143.171.96 - - [19/Sep/2026:01:16:05 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 150 "-" "-"
34.143.171.96 - - [19/Sep/2026:01:16:05 +0200] "GET /appearance/../../.env HTTP/1.1" 400 150 "-" "-"
34.143.171.96 - - [19/Sep/2026:01:16:05 +0200] "GET /api/attachments/img/avatar/..%2F..%2F..%2F..%2F..%2F.env HTTP/1.1" 400 150 "-" "-"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 23:14:19
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.143.171.96 (96.171.143.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.143.171.96 (96.171.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 19:14:12.877604 2026] [security2:error] [pid 28645:tid 28645] [client 34.143.171.96:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.assistguide.net|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.assistguide.net"] [uri "/ssl/localhost.key"] [unique_id "aq3FxHFujund_pHbjLLISAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack