๐บ๐ธ
Charlesiv
2026-10-01 07:50:31
(6 days ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /actuator/gateway/routes
Timestamp: 2026-10-01T03:08:14Z
Ray ID: a43842fcdb3cdc8a
UA: Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)
show less
Bad Web Bot
๐บ๐ธ
[email protected]
2026-10-01 07:06:58
(6 days ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 71h59m54s)
Port Scan
๐ณ๐ฑ
Site.eu
2026-10-01 05:02:48
(6 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
Starburst SysOp Team
2026-10-01 04:49:25
(6 days ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-mnz6-1)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 03:29:38
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.159.136.39 (39.136.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.136.39 (39.136.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 23:29:34.266873 2026] [security2:error] [pid 30779:tid 30846] [client 34.159.136.39:33412] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.helppeopleshare.net"] [uri "/wp-config.php.bak"] [unique_id "ar3TnqefsK571sIigJmWqQAAAYc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rhofas
2026-10-01 03:01:58
(6 days ago)
Automated PHP shell scanner - 404 flood on hofas.net
Web App Attack
Hacking
๐บ๐ธ
[email protected]
2026-10-01 02:58:58
(6 days ago)
CrowdSec ban: crowdsecurity/http-admin-interface-probing (duration: 71h59m54s)
Web App Attack
Anonymous
2026-10-01 02:50:22
(6 days ago)
34.159.136.39 - - [01/Oct/2026:04:50:22 +0200] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1 ...
show more
34.159.136.39 - - [01/Oct/2026:04:50:22 +0200] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 403 107 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
...
show less
Brute-Force
Web App Attack
๐ช๐ธ
el-brujo
2026-10-01 02:33:24
(6 days ago)
01/Oct/2026:04:33:23.953494 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
01/Oct/2026:04:33:23.953494 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 34.159.136.39] ModSecurity: Warning. Pattern match "(?i)(?:\\\\\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "48"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /api/w/admins/jobs_u/get_log_file/../../../../proc/self/environ"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [hostname "hwagm.elhacker.net"] [uri "/api/proc/self/environ"] [unique_i
...
show less
Hacking
Web App Attack
๐ซ๐ท
guillaume illien
2026-10-01 02:18:12
(6 days ago)
34.159.136.39 - - [01/Oct/2026:02:17:59 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2 ...
show more
34.159.136.39 - - [01/Oct/2026:02:17:59 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 166 "-" "-"
34.159.136.39 - - [01/Oct/2026:02:18:04 +0000] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/proc/self/environ HTTP/1.1" 400 166 "-" "-"
34.159.136.39 - - [01/Oct/2026:02:18:04 +0000] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env HTTP/1.1" 400 166 "-" "-"
34.159.136.39 - - [01/Oct/2026:02:18:04 +0000] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
34.159.136.39 - - [01/Oct/2026:02:18:04 +0000] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
34.159.136.39 - - [01/Oct/2026:02:18:04 +0000] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
34.159.136.39 - - [01/Oct/2026:02:18:11 +0000] "GET /..%2f.env HTTP/1.1" 400 166 "-" "-"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
๐ฉ๐ช
AetherFox
2026-10-01 02:08:11
(6 days ago)
AetherFox VoidGuard detected: [Thu Oct 01 02:08:10.475472 2026] [authz_core:error] [pid 780942:tid 7 ...
show more
AetherFox VoidGuard detected: [Thu Oct 01 02:08:10.475472 2026] [authz_core:error] [pid 780942:tid 780959] [client 34.159.136.39:60820] AH01630: client denied by server configuration: proxy:https://[MASKED]/
[Thu Oct 01 02:08:10.539522 2026] [authz_core:error] [pid 780942:tid 780961] [client 34.159.136.39:60820] AH01630: client denied by server configuration: proxy:https://[MASKED]/2yv88qm8xfz2kbdrn2fh
[Thu Oct 01 02:08:10.573991 2026] [authz_core:error] [pid 780942:tid 780945] [client 34.159.136.39:60844] AH01630: client denied by server configuration: proxy:https://[MASKED]/v98r33bme1ypf9msp9ic
[Thu Oct 01 02:08:10.576368 2026] [authz_core:error] [pid 780942:tid 780968] [client 34.159.136.39:60856] AH01630: client denied by server configuration: proxy:https://[MASKED]/z9x8c7v6b5-debug-trigger-support.draconigen.net
[Thu Oct 01 02:08:10.582314 2026] [authz_core:error] [pid 780942:tid 780965] [client 34.159.136.39:60832] AH01630: client denied by server
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 01:44:36
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.159.136.39 (39.136.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.136.39 (39.136.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 21:44:30.007253 2026] [security2:error] [pid 16587:tid 16587] [client 34.159.136.39:39242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ryanc.net"] [uri "/config/.env"] [unique_id "ar26_qJxraLp7QFFV2WLkgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Philister11
2026-10-01 01:35:45
(6 days ago)
CrowdSec: crowdsecurity/grafana-cve-2021-43798 (DE/AS396982)
Web App Attack
Hacking
๐ฉ๐ช
Philister11
2026-10-01 00:49:10
(6 days ago)
CrowdSec: crowdsecurity/http-path-traversal-probing (DE/AS396982)
Web App Attack
Hacking
๐บ๐ธ
magnetosphere-tarpit
2026-10-01 00:47:43
(6 days ago)
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not ...
show more
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not exist on this host. Tarpitted, then banned: 10 requests within 24h0m0s
show less
Port Scan
Bad Web Bot
Web App Attack