๐ช๐ธ
el-brujo
2026-09-25 18:56:51
(9 hours ago)
Cloudflare WAF: Request Path: /api/v1/node-load-method/customMCP Request Query: Host: www.elhacker. ...
show more
Cloudflare WAF: Request Path: /api/v1/node-load-method/customMCP Request Query: Host: www.elhacker.net:8443 userAgent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] ) Action: block Source: ratelimit ASN Description: Google LLC Country: CA Method: POST Timestamp: 2026-09-25T18:56:51Z ruleId: 11a71ad4659e48b29b5173e3bcc61b4a. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
๐ช๐ธ
el-brujo
2026-09-25 18:43:59
(9 hours ago)
Cloudflare WAF: Request Path: /index.php Request Query: ?%ADd+allow_url_include%3d1+%ADd+auto_prepen ...
show more
Cloudflare WAF: Request Path: /index.php Request Query: ?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input Host: web.elhacker.net:8443 userAgent: Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot) Action: block Source: firewallCustom ASN Description: Google LLC Country: CA Method: POST Timestamp: 2026-09-25T18:43:59Z ruleId: 6b2d48d0415e4adb9f099d85f54d1de6. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
๐ช๐ธ
el-brujo
2026-09-25 15:29:23
(13 hours ago)
Cloudflare WAF: Request Path: /.env.backup Request Query: Host: chat.elhacker.net:8443 userAgent: M ...
show more
Cloudflare WAF: Request Path: /.env.backup Request Query: Host: chat.elhacker.net:8443 userAgent: Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/) Action: block Source: firewallCustom ASN Description: Google LLC Country: CA Method: GET Timestamp: 2026-09-25T15:29:23Z ruleId: 6b2d48d0415e4adb9f099d85f54d1de6. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
๐ฉ๐ช
s@ch@
2026-09-25 14:45:02
(13 hours ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack
๐ซ๐ท
dynamix
2026-09-25 14:42:35
(13 hours ago)
Multiple WAF Violations
Web App Attack
๐ช๐ธ
el-brujo
2026-09-25 14:20:42
(14 hours ago)
34.152.46.235 - - [25/Sep/2026:16:20:42 +0200] "GET /dist/.vite/manifest.json HTTP/2.0" 404 16132 "- ...
show more
34.152.46.235 - - [25/Sep/2026:16:20:42 +0200] "GET /dist/.vite/manifest.json HTTP/2.0" 404 16132 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.152.46.235 - - [25/Sep/2026:16:20:42 +0200] "GET /sjmyy7hr146dn1ydtryn HTTP/2.0" 404 16132 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.152.46.235 - - [25/Sep/2026:16:20:42 +0200] "GET /dist/manifest.json HTTP/2.0" 404 16132 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.152.46.235 - - [25/Sep/2026:16:20:42 +0200] "GET /.vite/manifest.json HTTP/2.0" 404 16132 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
...
show less
Web App Attack
Hacking
๐ช๐ธ
el-brujo
2026-09-23 13:42:39
(2 days ago)
Cloudflare WAF: Request Path: /app_dev.php/_profiler Request Query: Host: api.elhacker.net:8443 use ...
show more
Cloudflare WAF: Request Path: /app_dev.php/_profiler Request Query: Host: api.elhacker.net:8443 userAgent: Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/) Action: block Source: firewallManaged ASN Description: Google LLC Country: CA Method: GET Timestamp: 2026-09-23T13:42:39Z ruleId: 8e361ee4328f4a3caf6caf3e664ed6fe. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
๐ฉ๐ช
dave
2026-09-23 11:57:25
(2 days ago)
threat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity ...
show more
threat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity/appsec-vpatch,crowdsecurity/vpatch-CVE-2025-55182,crowdsecurity/vpatch-env-access,crowdsecurity/vpatch-git-config,custom/traefik-sensitive-path-probe observed_by=1_hosts hit_count=124 first_seen=2026-09-23T11:57:16Z last_seen=2026-09-23T11:57:25Z
show less
Web App Attack
๐ช๐ธ
el-brujo
2026-09-23 11:55:53
(2 days ago)
34.152.46.235 - - [23/Sep/2026:13:55:52 +0200] "GET /en9dea4zj4qdq4h7st9d HTTP/2.0" 404 15908 "-" "M ...
show more
34.152.46.235 - - [23/Sep/2026:13:55:52 +0200] "GET /en9dea4zj4qdq4h7st9d HTTP/2.0" 404 15908 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
34.152.46.235 - - [23/Sep/2026:13:55:52 +0200] "GET /z9x8c7v6b5-debug-trigger-www.elhacker.net HTTP/2.0" 404 15908 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
34.152.46.235 - - [23/Sep/2026:13:55:52 +0200] "GET /dist/manifest.json HTTP/2.0" 404 15908 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.152.46.235 - - [23/Sep/2026:13:55:52 +0200] "GET /dist/.vite/manifest.json HTTP/2.0" 404 15908 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
...
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-23 11:34:41
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.152.46.235 (235.46.152.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.46.235 (235.46.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 07:34:37.980886 2026] [security2:error] [pid 18246:tid 18246] [client 34.152.46.235:56820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keyston.net"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "arO5Ta1y8qR66E27cHwxRQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
s@ch@
2026-09-23 11:30:04
(2 days ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack
Anonymous
2026-09-23 11:30:03
(2 days ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection