π¬π§
thetomtaylor.co.uk
2026-09-24 13:06:00
(22 hours ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01]
Hacking
SQL Injection
Web App Attack
πΊπΈ
[email protected]
2026-09-24 11:27:42
(23 hours ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 71h59m56s)
Port Scan
πͺπΈ
el-brujo
2026-09-23 23:12:03
(1 day ago)
Cloudflare WAF: Request Path: /api%2F.env Request Query: Host: api.elhacker.net userAgent: Mozilla/ ...
show more
Cloudflare WAF: Request Path: /api%2F.env Request Query: Host: api.elhacker.net userAgent: Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/) Action: block Source: firewallManaged ASN Description: Google LLC Country: DE Method: GET Timestamp: 2026-09-23T23:12:03Z ruleId: 23548ee2b36547a1be09bb2c0550c529. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
π§π·
radardatelecom
2026-09-23 22:23:08
(1 day ago)
Blocked by Radar da Telecom firewall β abuseipdb
Bad Web Bot
Web App Attack
πΊπΈ
Charlesiv
2026-09-23 22:00:30
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Endpoint: /functionRouter
Timestamp: 2026-09-23T20:39:19Z
Ray ID: a3fc5bab8e51444c
UA: Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36
show less
Bad Web Bot
π¬π§
stevendodd
2026-09-23 20:48:21
(1 day ago)
34.159.199.49 - - [23/Sep/2026:21:48:17 +0100] "GET /.github/workflows/deploy.yml HTTP/1.1" 404 262 ...
show more
34.159.199.49 - - [23/Sep/2026:21:48:17 +0100] "GET /.github/workflows/deploy.yml HTTP/1.1" 404 262 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
34.159.199.49 - - [23/Sep/2026:21:48:17 +0100] "GET /.gitlab-ci.yml HTTP/1.1" 404 262 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.159.199.49 - - [23/Sep/2026:21:48:18 +0100] "GET /.ssh/id_rsa HTTP/1.1" 404 262 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.159.199.49 - - [23/Sep/2026:21:48:18 +0100] "GET /.ssh/id_ed25519 HTTP/1.1" 404 262 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
34.159.199.49 - - [23/Sep/2026:21:48:18 +0100] "GET /.ssh/config HTTP/1.1" 404 262 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.159.199.49 - - [23/Sep/2026:21:48:19 +0100] "GET /wp-config.php.old HTTP/1.1" 404 262 "-" "Mozilla/5.0 AppleWebKit
...
show less
Brute-Force
Web App Attack
π©πͺ
webanyone
2026-09-23 20:47:03
(1 day ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
π³π±
Alt255
2026-09-23 20:27:14
(1 day ago)
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.159.199.49 - - \[23/Sep/2026:22:26:53 +0200\] "GET /.env.staging HTTP/2.0" 404 1863 "-" "Mozilla/5.0 AppleWebKit/537.36 \(KHTML, like Gecko\; compatible\; PerplexityBot/1.0\; +https://perplexity.ai/perplexitybot\)"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
slay3r9903
2026-09-23 20:15:06
(1 day ago)
IP address blocked by Cloudflare security rules due to suspicious activity and security violations.
Hacking
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-23 19:53:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.159.199.49 (49.199.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.199.49 (49.199.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:53:51.731313 2026] [security2:error] [pid 8542:tid 8542] [client 34.159.199.49:56066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotelcasadelsol.casadelsolmexico.net"] [uri "/web.config"] [unique_id "arQuT_95YMqJqb8oebzdKgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 19:32:58
(1 day ago)
Portscan: TCP/8443 (3x), TCP/8080 (3x)
Port Scan
πͺπΈ
el-brujo
2026-09-23 19:32:08
(1 day ago)
23/Sep/2026:21:32:08.190105 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
23/Sep/2026:21:32:08.190105 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 34.159.199.49] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1056"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "hwagm.elhacker.net"] [uri "/rclone.conf"] [unique
...
show less
Hacking
Web App Attack
πΈπͺ
sweplox.se
2026-09-23 19:29:46
(1 day ago)
Ip 34.159.199.49 performed 'crowdsecurity/appsec-vpatch' (2 events over 544.492023ms) at 2026-09-23 ...
show more
Ip 34.159.199.49 performed 'crowdsecurity/appsec-vpatch' (2 events over 544.492023ms) at 2026-09-23 19:29:45.074406345 +0000 UTC
show less
Hacking
π©πͺ
raph
2026-09-23 19:28:32
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
π³π±
middelkoopcc
2026-09-23 16:18:01
(1 day ago)
2026-09-23 18:16:03 GET /.env.save [301] && 2026-09-23 18:16:03 GET /.env.backup [301] && 2026-09-23 ...
show more
2026-09-23 18:16:03 GET /.env.save [301] && 2026-09-23 18:16:03 GET /.env.backup [301] && 2026-09-23 18:16:03 GET /.env.bak [301] && 237 more within 20 minutes
show less
Web App Attack