🇺🇸
Charlesiv
2026-09-20 04:00:39
(1 hour ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.idea/WebServers.xml
Timestamp: 2026-09-19T23:06:38Z
Ray ID: a3dc3df68ccbfd8c
UA: Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36
show less
Bad Web Bot
🇺🇸
Charlesiv
2026-09-19 22:00:39
(7 hours ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /store/.env
Timestamp: 2026-09-19T20:29:57Z
Ray ID: a3db5873d892ff85
UA: Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)
show less
Bad Web Bot
🇪🇸
el-brujo
2026-09-19 21:41:38
(7 hours ago)
Cloudflare WAF: Request Path: /api/templates/preview Request Query: Host: grafana.elhacker.net user ...
show more
Cloudflare WAF: Request Path: /api/templates/preview Request Query: Host: grafana.elhacker.net userAgent: Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/) Action: block Source: firewallManaged ASN Description: Google LLC Country: SG Method: POST Timestamp: 2026-09-19T21:41:38Z ruleId: e7e4b386797e417c998d872956c390a1. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
🇪🇸
el-brujo
2026-09-19 21:41:20
(7 hours ago)
19/Sep/2026:23:41:20.280021 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
19/Sep/2026:23:41:20.280021 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 34.21.186.146] ModSecurity: Warning. Pattern match "(?i)(?:\\\\\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "48"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /userfiles/x?path=../../../../proc/self/environ"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [hostname "grafana.elhacker.net"] [uri "/userfiles/x"] [unique_id "aq8BgAfvrQ1YDwiP-iCNL
...
show less
Hacking
Web App Attack
🇩🇪
pscriptos
2026-09-19 20:38:40
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇩🇪
mzaiser12
2026-09-19 20:34:56
(8 hours ago)
Web application probing: 76 requests to typical attack paths (/.aws/credentials, /.docker/.env, /.en ...
show more
Web application probing: 76 requests to typical attack paths (/.aws/credentials, /.docker/.env, /.env, /.aws/config) within 5 min. Reported automatically by a SIEM; contact via abuse mailbox of the reporting network.
show less
Bad Web Bot
Web App Attack
🇺🇸
HamSammich
2026-09-19 19:04:56
(10 hours ago)
Automated sensor: 7 HTTPS connection/probe attempts over the last 24h (latest 2026-09-19T19:04Z).
Brute-Force
Web App Attack
🇩🇪
updown.io
2026-09-19 18:11:14
(11 hours ago)
{"level":"info","ts":1789841469.2320578,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1789841469.2320578,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.21.186.146","remote_port":"34284","client_ip":"34.21.186.146","proto":"HTTP/2.0","method":"POST","host":"eu.pandahut.net","uri":"/graphql","headers":{"Content-Length":["86"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Cookie":["REDACTED"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"],"Sec-Ch-Ua-Mobile":["?0"],"Origin":["https://eu.pandahut.net"],"Sec-Fetch-Mode":["cors"],"Sec-Ch-Ua":["\"Chromium\";v=\"152\", \"Not?A_Brand\";v=\"24\", \"Brave\";v=\"152\""],"Content-Type":["application/json"],"Priority":["u=1, i"],"Referer":["https://eu.pandahut.net"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Sec-Fetch-Dest":["empty"],"Accept-Language":["en-US,en;q=0.9"],"Accept":["*/*"],"Sec-Fetch-Site":["same-origin"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name"
...
show less
DDoS Attack
Web App Attack
🇫🇷
dynamix
2026-09-19 09:45:02
(19 hours ago)
Multiple WAF Violations
Web App Attack
🇪🇸
el-brujo
2026-09-19 04:45:56
(1 day ago)
Cloudflare WAF: Request Path: /api/designer/v1/file-content Request Query: Host: comfyui.elhacker.n ...
show more
Cloudflare WAF: Request Path: /api/designer/v1/file-content Request Query: Host: comfyui.elhacker.net userAgent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot) Action: block Source: firewallManaged ASN Description: Google LLC Country: SG Method: POST Timestamp: 2026-09-19T04:45:56Z ruleId: e7e4b386797e417c998d872956c390a1. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
🇮🇹
CoreTech srl
2026-09-19 03:24:01
(1 day ago)
[DC: IP:151.1.252.27] ntopng alert: blacklisted_server_contact,ndpi_suspicious_entropy
Hacking
🇺🇸
entangled_mongoose
2026-09-18 22:21:16
(1 day ago)
Probed /wp-json.
Web App Attack
🇩🇪
pscriptos
2026-09-18 19:01:22
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇩🇪
Hagen Schoebel
2026-09-18 18:59:10
(1 day ago)
Blocked by CrowdSec - crowdsecurity/http-probing (SG)
Port Scan
Brute-Force
Web App Attack
SSH
🇩🇪
pscriptos
2026-09-18 18:39:01
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack