๐บ๐ธ
Charlesiv
2026-09-23 06:00:28
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Endpoint: /functionRouter
Timestamp: 2026-09-23T03:40:50Z
Ray ID: a3f687bdda96fcfc
UA: Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)
show less
Bad Web Bot
๐ฎ๐ณ
evicky2002
2026-09-23 06:00:01
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-09-23 03:45:18
(1 day ago)
Automatic report - Vulnerability scan
/trace.axd
Web App Attack
๐ช๐ธ
el-brujo
2026-09-23 03:36:55
(1 day ago)
23/Sep/2026:05:36:54.861959 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
23/Sep/2026:05:36:54.861959 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 34.21.178.90] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1056"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "warzone.elhacker.net"] [uri "/rclone.conf"] [uniqu
...
show less
Hacking
Web App Attack
๐บ๐ธ
RamSet
2026-09-23 03:35:34
(1 day ago)
[wx] HTTP-Probe on port 443 (via domain). 189 distinct paths probed in 20s. Sustained 202 req/min, 1 ...
show more
[wx] HTTP-Probe on port 443 (via domain). 189 distinct paths probed in 20s. Sustained 202 req/min, 171 nonexistent paths (404). Paths: /static//home/user/.env, /@fs/src/.env?raw??, /.env.local?import&raw, /@fs/app/.env?raw??, /static/home/user/.env, /.//.env, /api/.env/public/.env, /@fs/../.env?raw??, //.env, /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw??, /img../.env, /uploads../.env, /@fs/home/ubuntu/.aws/credentials?raw??, /@fs/root/.aws/credentials?raw??, /@fs/var/task/.env?raw??, /@fs/home/ec2-user/.aws/credentials?raw??, /@fs/proc/self/cwd/.env?raw??, /actuator/loggers, /assets../.env, /images../.env, /.env.production?raw, /.env.js, /_nuxt/../.env, /static../.env, /dashboard%2F.env, /media../.env, /admin%2F.env, /files../.env, /actuator/configprops, /static//.env, /settings%2F.env, /api%2F.env, /static//app/.env, /static/.env, /actuator/mappings, /@fs/.env?url&raw??, /@fs/.env?raw&url??, /static/app/.env, /@fs/.env?import&?raw??, โฆ
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
regishoussin
2026-09-23 03:05:40
(1 day ago)
Automated web scanning detected by Wazuh (rule 100240): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100240): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-23 03:05 UTC.
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-23 02:46:21
(1 day ago)
2026/09/23 03:46:19 [error] 325888#325888: *1452862 access forbidden by rule, client: 34.21.178.90, ...
show more
2026/09/23 03:46:19 [error] 325888#325888: *1452862 access forbidden by rule, client: 34.21.178.90, server: webapp.gwynethllewelyn.net, request: "GET /api/.env HTTP/2.0", host: "webapp.gwynethllewelyn.net"
2026/09/23 03:46:19 [error] 325888#325888: *1452862 access forbidden by rule, client: 34.21.178.90, server: webapp.gwynethllewelyn.net, request: "GET /config/.env HTTP/2.0", host: "webapp.gwynethllewelyn.net"
2026/09/23 03:46:19 [error] 325888#325888: *1452862 access forbidden by rule, client: 34.21.178.90, server: webapp.gwynethllewelyn.net, request: "GET /backend/.env HTTP/2.0", host: "webapp.gwynethllewelyn.net"
show less
Brute-Force
Web App Attack
Anonymous
2026-09-23 01:08:34
(1 day ago)
Web application attack detected.
Web App Attack
๐ฉ๐ช
itsolon
2026-09-23 00:43:38
(1 day ago)
[23/Sep/2026:02:43:37 +0200] 17901242174.514907 34.21.178.90 42182 217.154.7.177 443
[23/Sep/2026:02 ...
show more
[23/Sep/2026:02:43:37 +0200] 17901242174.514907 34.21.178.90 42182 217.154.7.177 443
[23/Sep/2026:02:43:37 +0200] 179012421788.945043 34.21.178.90 42182 217.154.7.177 443
[23/Sep/2026:02:43:38 +0200] 179012421829.384819 34.21.178.90 42182 217.154.7.177 443
[23/Sep/2026:02:43:38 +0200] 179012421866.570774 34.21.178.90 42182 217.154.7.177 443
[23/Sep/2026:02:43:38 +0200] 17901242182.601721 34.21.178.90 42182 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-09-23 00:10:06
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 23:38:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.21.178.90 (90.178.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.178.90 (90.178.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 19:38:13.298842 2026] [security2:error] [pid 6273:tid 6273] [client 34.21.178.90:49408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.deargrampy.net"] [uri "/.env"] [unique_id "arMRZcgI4ZVNQrW7fJZFLAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 23:18:17
(1 day ago)
[cb-10al] Excessive 404 errors (web scanning): 26 suspicious requests detected by fail2ban jail ngin ...
show more
[cb-10al] Excessive 404 errors (web scanning): 26 suspicious requests detected by fail2ban jail nginx-404. Example: 34.21.178.90 - - [23/Sep/2026:01:18:15 +0200] "GET /assets/manifest.json HTTP/2.0" 404 1422 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.21.178.90 - - [23/Sep/2026:01:18:16 +0200] "GET /dist/manifest.json HTTP/2.0" 404 1422 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.21.178.90 - - [23/Sep/2026:01:18:16 +0200] "GET /wbqwxf8wmwn5bw4xnpna HTTP/2.0" 404 1422 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.21.178.90 - - [23/Sep/2026:01:18:16 +0200] "GET /dq7cz7lpghnd71qly8ck HTTP/2.0" 404 1422 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.21.178.90 - - [23/Sep/2026:01:18:16 +0200] "POST /graphql H
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-09-22 23:14:47
(1 day ago)
34.21.178.90 - - [23/Sep/2026:07:14:44 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 301 473 "-" "Mozilla ...
show more
34.21.178.90 - - [23/Sep/2026:07:14:44 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 301 473 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.21.178.90 - - [23/Sep/2026:07:14:45 +0800] "GET /media../.env HTTP/1.1" 301 461 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.21.178.90 - - [23/Sep/2026:07:14:46 +0800] "GET /files../.env HTTP/1.1" 301 461 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
34.21.178.90 - - [23/Sep/2026:07:14:46 +0800] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 301 480 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.21.178.90 - - [23/Sep/2026:07:14:46 +0800] "GET /assets../.env HTTP/1.1" 301 461 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
34.21.178.90 - - [23/Sep/2026:07:14:46 +0800] "GET /static../.env HTTP/1.1" 301 461 "-" "Mozilla/5.0 (compatible; GrokBot
...
show less
Brute-Force
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-22 23:11:13
(1 day ago)
2026/09/23 00:11:11 [error] 325888#325888: *1417038 access forbidden by rule, client: 34.21.178.90, ...
show more
2026/09/23 00:11:11 [error] 325888#325888: *1417038 access forbidden by rule, client: 34.21.178.90, server: webshop.gwynethllewelyn.net, request: "GET /admin/.env HTTP/2.0", host: "webshop.gwynethllewelyn.net"
2026/09/23 00:11:11 [error] 325888#325888: *1417061 access forbidden by rule, client: 34.21.178.90, server: webshop.gwynethllewelyn.net, request: "GET /api/.env HTTP/2.0", host: "webshop.gwynethllewelyn.net"
2026/09/23 00:11:11 [error] 325888#325888: *1417062 access forbidden by rule, client: 34.21.178.90, server: webshop.gwynethllewelyn.net, request: "GET /backend/.env HTTP/2.0", host: "webshop.gwynethllewelyn.net"
show less
Brute-Force
Web App Attack
๐ต๐ฑ
sefinek.net
2026-09-22 23:08:42
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: /serverless.yml | UA: CCBot/2.0 (https://commoncrawl.org/faq/) โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot