๐ซ๐ท
dynamix
2026-09-24 16:12:51
(2 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-24 14:15:12
(4 hours ago)
Automatic report - Vulnerability scan
/trace.axd
Web App Attack
๐บ๐ธ
Charlesiv
2026-09-24 14:03:10
(4 hours ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Endpoint: /lib/terminal-xhr.php
Timestamp: 2026-09-24T14:00:51Z
Ray ID: a402515a7872fbf4
UA: Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)
show less
Bad Web Bot
๐บ๐ธ
RamSet
2026-09-24 13:55:56
(4 hours ago)
[wx] HTTP-Probe on port 443 (via domain). 269 distinct paths probed in 15s. Sustained 286 req/min, 2 ...
show more
[wx] HTTP-Probe on port 443 (via domain). 269 distinct paths probed in 15s. Sustained 286 req/min, 245 nonexistent paths (404). Paths: /.env, /config/env/aws_credentials.env, /static//.env, /.env.example, /static//app/.env, /config/.env, /_nuxt/../.env, /.env.local, /static/.env, /static/app/.env, /.env.production, /.env.bak, /@fs/app/.env?raw??, /static../.env, /.env.save, /media../.env, /.env.backup, /@fs/../.env?raw??, /files../.env, /.env.old, /@fs/src/.env?raw??, /.env.prod, /api/.env, /admin/.env, /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw??, /backend/.env, /src/.env, /server/.env, /app/.env, /public/.env, /web/.env, /frontend/.env, /.next/.env, /docker/.env, /dist/.env, /build/.env, /.aws/credentials, /core/.env, /.git/config, /.aws/config, /.git/HEAD, /.git-credentials, /secrets.env, /static//home/user/.env, /static/home/user/.env, /.env.js, /.ssh/id_rsa, /.htpasswd, /.ssh/id_ed25519, /wp-config.php~, /.ssh/config, /wp-config.php.swp, โฆ
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-24 12:04:43
(6 hours ago)
2026/09/24 13:04:41 [error] 325888#325888: *1831686 access forbidden by rule, client: 34.178.148.21, ...
show more
2026/09/24 13:04:41 [error] 325888#325888: *1831686 access forbidden by rule, client: 34.178.148.21, server: webapp.gwynethllewelyn.net, request: "GET /laravel/.env HTTP/2.0", host: "webapp.gwynethllewelyn.net"
2026/09/24 13:04:41 [error] 325888#325888: *1831686 access forbidden by rule, client: 34.178.148.21, server: webapp.gwynethllewelyn.net, request: "GET /storage/.env HTTP/2.0", host: "webapp.gwynethllewelyn.net"
2026/09/24 13:04:41 [error] 325888#325888: *1831686 access forbidden by rule, client: 34.178.148.21, server: webapp.gwynethllewelyn.net, request: "GET /wp/.env HTTP/2.0", host: "webapp.gwynethllewelyn.net"
show less
Brute-Force
Web App Attack
๐บ๐ธ
zwebvigil
2026-09-24 12:04:18
(6 hours ago)
34.178.148.21 [24/Sep/2026:05:04:17 -0700] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/se ...
show more
34.178.148.21 [24/Sep/2026:05:04:17 -0700] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 404 196 "-" port=35876 "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" "JSESSIONID=D6F588DA13BB3A69CBD4393792AF014A" "-" "webauthn.<host>" 196
34.178.148.21 [24/Sep/2026:05:04:17 -0700] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 404 196 "-" port=35798 "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" "JSESSIONID=D6F588DA13BB3A69CBD4393792AF014A" "-" "webauthn.<host>" 208
34.178.148.21 [24/Sep/2026:05:04:17 -0700] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 404 196 "-" port=35798 "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" "JSESSIONID=D6F588DA13BB3A69CBD4393792AF014A" "-" "webauthn.<host>" 208
34.178.148.21 [24/Sep/2026:05:04:17 -0700] "GET /resources/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 404 196 "-" port=35902 "Mozilla
show less
Web App Attack
๐บ๐ธ
[email protected]
2026-09-24 11:28:12
(7 hours ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 71h59m54s)
Port Scan
๐ณ๐ฑ
i-turnradio.nl
2026-09-24 09:59:10
(8 hours ago)
2026-09-24 @ 11:58:55 (CET) ~ Blocked for trying to access: /graphql
Web App Attack
๐ง๐ท
hostmach
2026-09-24 09:43:37
(9 hours ago)
(cpanel) Failed cPanel login from 34.178.148.21 (NL/The Netherlands/21.148.178.34.bc.googleuserconte ...
show more
(cpanel) Failed cPanel login from 34.178.148.21 (NL/The Netherlands/21.148.178.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CPANEL; Logs: [2026-09-24 09:43:31 +0000] info [cphttpd] 34.178.148.21 - - "GET /assets/manifest.json HTTP/1.1" FAILED LOGIN webmaild: login attempt without username
[2026-09-24 09:43:31 +0000] info [cphttpd] 34.178.148.21 - - "GET /manifest.json HTTP/1.1" FAILED LOGIN webmaild: login attempt without username
[2026-09-24 09:43:31 +0000] info [cphttpd] 34.178.148.21 - - "GET /z9x8c7v6b5-debug-trigger-webmail.nx3.tdnx.net HTTP/1.1" FAILED LOGIN webmaild: login attempt without username
[2026-09-24 09:43:31 +0000] info [cphttpd] 34.178.148.21 - - "GET /webpack-stats.json HTTP/1.1" FAILED LOGIN webmaild: login attempt without username
[2026-09-24 09:43:32 +0000] info [cphttpd] 34.178.148.21 - - "POST /v1/graphql HTTP/1.1" FAILED LOGIN webmaild: login attempt without username
show less
Brute-Force
SSH
๐ฉ๐ช
itsolon
2026-09-24 09:35:06
(9 hours ago)
[24/Sep/2026:11:35:05 +0200] 179024250598.419554 34.178.148.21 33012 217.154.7.177 443
[24/Sep/2026: ...
show more
[24/Sep/2026:11:35:05 +0200] 179024250598.419554 34.178.148.21 33012 217.154.7.177 443
[24/Sep/2026:11:35:06 +0200] 179024250629.549221 34.178.148.21 33012 217.154.7.177 443
[24/Sep/2026:11:35:06 +0200] 179024250650.194894 34.178.148.21 33012 217.154.7.177 443
[24/Sep/2026:11:35:06 +0200] 179024250663.098252 34.178.148.21 33012 217.154.7.177 443
[24/Sep/2026:11:35:06 +0200] 179024250672.087473 34.178.148.21 33012 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-09-24 08:18:28
(10 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "OAI-SearchBot" at REQUEST_HEADERS:user-agent. (1100 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "OAI-SearchBot" at REQUEST_HEADERS:user-agent. (1100000-135)
show less
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-09-24 07:39:24
(11 hours ago)
[cb-06al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail ngin ...
show more
[cb-06al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail nginx-404. Example: 34.178.148.21 - - [24/Sep/2026:09:39:21 +0200] "GET /static/manifest.json HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.178.148.21 - - [24/Sep/2026:09:39:21 +0200] "GET /asset-manifest.json HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.178.148.21 - - [24/Sep/2026:09:39:21 +0200] "GET /dist/manifest.json HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.178.148.21 - - [24/Sep/2026:09:39:21 +0200] "GET /d2ag1fap8nn33b82e4h3 HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
34.178.148.21 - -
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-24 07:28:59
(11 hours ago)
2026/09/24 08:28:57 [error] 325891#325891: *1781506 access forbidden by rule, client: 34.178.148.21, ...
show more
2026/09/24 08:28:57 [error] 325891#325891: *1781506 access forbidden by rule, client: 34.178.148.21, server: webshop.gwynethllewelyn.net, request: "GET /admin%2F.env HTTP/2.0", host: "webshop.gwynethllewelyn.net"
2026/09/24 08:28:57 [error] 325888#325888: *1781532 access forbidden by rule, client: 34.178.148.21, server: webshop.gwynethllewelyn.net, request: "GET /api%2F.env HTTP/2.0", host: "webshop.gwynethllewelyn.net"
2026/09/24 08:28:57 [error] 325888#325888: *1781533 access forbidden by rule, client: 34.178.148.21, server: webshop.gwynethllewelyn.net, request: "GET /dashboard%2F.env HTTP/2.0", host: "webshop.gwynethllewelyn.net"
show less
Brute-Force
Web App Attack
๐ช๐ธ
el-brujo
2026-09-24 06:57:21
(11 hours ago)
Cloudflare WAF: Request Path: /api/templates/preview Request Query: Host: wiki.elhacker.net userAge ...
show more
Cloudflare WAF: Request Path: /api/templates/preview Request Query: Host: wiki.elhacker.net userAgent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) Action: block Source: firewallManaged ASN Description: Google LLC Country: NL Method: POST Timestamp: 2026-09-24T06:57:21Z ruleId: e7e4b386797e417c998d872956c390a1. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
๐ซ๐ท
IRISIO
2026-09-24 06:31:22
(12 hours ago)
scans/SQL injection/spam posts : 1195 queries
Web App Attack
SQL Injection