๐บ๐ธ
slay3r9903
2026-09-26 22:45:18
(35 minutes ago)
IP address blocked by Cloudflare security rules due to suspicious activity and security violations.
Hacking
Bad Web Bot
๐ฉ๐ช
pscriptos
2026-09-26 22:42:59
(38 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
slay3r9903
2026-09-26 22:26:47
(54 minutes ago)
Wazuh rule 100308: NPM sensitive-path storm: rule 100304 โฅ5 times in 10s from same IP
Brute-Force
Port Scan
๐ช๐ธ
el-brujo
2026-09-26 22:06:51
(1 hour ago)
27/Sep/2026:00:06:50.759169 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
27/Sep/2026:00:06:50.759169 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 34.169.11.105] ModSecurity: Warning. Matched phrase "proc/self/environ" at ARGS:0. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "98"] [id "930120"] [msg "OS File Access Attempt"] [data "Matched Data: proc/self/environ found within ARGS:0: {\\\\x22then\\\\x22:\\\\x22$1:__proto__:then\\\\x22,\\\\x22status\\\\x22:\\\\x22resolved_model\\\\x22,\\\\x22reason\\\\x22:-1,\\\\x22value\\\\x22:\\\\x22{/\\\\x22then/\\\\x22:/\\\\x22$b1337/\\\\x22}\\\\x22,\\\\x22_response\\\\x22:{\\\\x22_prefix\\\\x22:\\\\x22process.mainmodule.require('child_process').execsync('env 2>/dev/null || cat /proc/self/environ 2>/dev/null');\\\\x22,\\\\x22_formdata\\\\x22:{\\\\x22get\\\\x22:\\\\x22$1:constructor:constructor\\\\x22}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "
...
show less
Hacking
Web App Attack
๐บ๐ธ
JonathanYoung2161
2026-09-26 21:05:49
(2 hours ago)
pairfinder.simplifiedmedia.net 34.169.11.105 - - [26/Sep/2026:16:05:47 -0500] "GET /.env.js HTTP/2.0 ...
show more
pairfinder.simplifiedmedia.net 34.169.11.105 - - [26/Sep/2026:16:05:47 -0500] "GET /.env.js HTTP/2.0" 429 162 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
pairfinder.simplifiedmedia.net 34.169.11.105 - - [26/Sep/2026:16:05:47 -0500] "GET /config/env/aws_credentials.env HTTP/2.0" 429 8742 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
pairfinder.simplifiedmedia.net 34.169.11.105 - - [26/Sep/2026:16:05:48 -0500] "GET /static../.env HTTP/2.0" 429 162 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-09-26 19:14:10
(4 hours ago)
Automatic report - Vulnerability scan
/trace.axd
Web App Attack
๐บ๐ธ
Charlesiv
2026-09-26 18:00:45
(5 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Pro ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Endpoint: /read-document
Timestamp: 2026-09-26T16:42:55Z
Ray ID: a413b9837c4defbe
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)
show less
Bad Web Bot
๐ฌ๐ง
noise.agency
2026-09-26 17:24:43
(5 hours ago)
34.169.11.105 (US/United States/105.11.169.34.bc.googleusercontent.com), more than 10 Apache 403 hit ...
show more
34.169.11.105 (US/United States/105.11.169.34.bc.googleusercontent.com), more than 10 Apache 403 hits
show less
Hacking
๐ฟ๐ฆ
conure.sh
2026-09-26 15:21:04
(8 hours ago)
csagent: score 21.4: 404 noise floor x6, spoofed crawler UA x1, secrets grab x1; 1 domain(s) in 4s
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-26 15:12:15
(8 hours ago)
COMODO WAF: PHP Injection Attack: I/O Stream Found. Pattern match "(?i)php://(std(in|out|err)|(in|ou ...
show more
COMODO WAF: PHP Injection Attack: I/O Stream Found. Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. (218420-srv1)
show less
Hacking
๐ฉ๐ช
itsolon
2026-09-26 10:35:56
(12 hours ago)
[26/Sep/2026:12:35:55 +0200] 179041895563.702868 34.169.11.105 0 217.154.7.177 443
[26/Sep/2026:12:3 ...
show more
[26/Sep/2026:12:35:55 +0200] 179041895563.702868 34.169.11.105 0 217.154.7.177 443
[26/Sep/2026:12:35:55 +0200] 179041895566.658243 34.169.11.105 0 217.154.7.177 443
[26/Sep/2026:12:35:55 +0200] 179041895513.989568 34.169.11.105 0 217.154.7.177 443
[26/Sep/2026:12:35:55 +0200] 179041895520.781586 34.169.11.105 0 217.154.7.177 443
[26/Sep/2026:12:35:55 +0200] 179041895525.794700 34.169.11.105 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
Charlesiv
2026-09-26 10:00:12
(13 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Endpoint: /cgi-bin/php-cgi.exe
Query: ?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input
Timestamp: 2026-09-26T09:52:13Z
Ray ID: a4115fe22fc412b1
UA: Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)
show less
Bad Web Bot
๐บ๐ธ
Charlesiv
2026-09-26 02:05:45
(21 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /phpinfo.php
Timestamp: 2026-09-26T00:09:11Z
Ray ID: a40e09d4fd011509
UA: Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)
show less
Bad Web Bot
๐ฉ๐ช
raph
2026-09-25 21:56:55
(1 day ago)
[PROTECTED PATHS] crawler credentials.ini, aws.ini, aws.yml, etc.
Bad Web Bot
Web App Attack
๐ญ๐ฐ
zhengka
2026-09-25 21:36:03
(1 day ago)
ZhengKa WAF detected scan_probe. Rule: scan_probe #/(?:\.env|\.git|\.svn|composer\.json|composer\.lo ...
show more
ZhengKa WAF detected scan_probe. Rule: scan_probe #/(?:\.env|\.git|\.svn|composer\.json|composer\.lock|id_rsa|server-status)(?:$|[/?])#. Method: GET. URI: /admin/.env. Incident: CA13F5785263162C. UA: Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)
show less
Port Scan
Web App Attack