๐ง๐ช
voormedia
2026-09-18 01:31:39
(2 hours ago)
Accessed trap at '/.aws/config'
Web App Attack
๐ซ๐ท
dynamix
2026-09-18 01:17:03
(3 hours ago)
Multiple WAF Violations
Web App Attack
๐จ๐ญ
backslash
2026-09-18 00:06:10
(4 hours ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
๐ช๐ธ
el-brujo
2026-09-17 23:45:40
(4 hours ago)
18/Sep/2026:01:45:39.696140 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
18/Sep/2026:01:45:39.696140 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 34.87.8.86] ModSecurity: Warning. Pattern match "(?i)(?:\\\\\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "48"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /..%252f found within REQUEST_URI_RAW: /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw??"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [hostname "grafana.elhacker.net"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fp
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2026-09-17 22:45:48
(5 hours ago)
34.87.8.86 - - [18/Sep/2026:00:45:47 +0200] "GET /rclone.conf HTTP/2.0" 404 4620 "-" "Mozilla/5.0 (c ...
show more
34.87.8.86 - - [18/Sep/2026:00:45:47 +0200] "GET /rclone.conf HTTP/2.0" 404 4620 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.87.8.86 - - [18/Sep/2026:00:45:47 +0200] "GET /.env.backup HTTP/2.0" 404 4620 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.87.8.86 - - [18/Sep/2026:00:45:47 +0200] "GET /z9x8c7v6b5-debug-trigger-foro.elhacker.net HTTP/2.0" 404 4620 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.87.8.86 - - [18/Sep/2026:00:45:48 +0200] "POST /graphql HTTP/2.0" 404 4620 "https://foro.elhacker.net" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
...
show less
Web App Attack
Hacking
๐ฎ๐ฉ
sockominfo
2026-09-17 20:00:09
(8 hours ago)
Active Response: IP 34.87.8.86 Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). Report ...
show more
Active Response: IP 34.87.8.86 Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
Anonymous
2026-09-17 18:37:03
(9 hours ago)
Web App Attack
๐ฉ๐ช
4server
2026-09-17 16:56:07
(11 hours ago)
[2026-09-1718:56:04 0200]info[cpaneld]34.87.8.86--\"GET/404.shtmlHTTP/1.1\"FAILEDLOGINcpaneld:logina ...
show more
[2026-09-1718:56:04 0200]info[cpaneld]34.87.8.86--\"GET/404.shtmlHTTP/1.1\"FAILEDLOGINcpaneld:loginattemptwithoutusername[2026-09-1718:56:04 0200]info[cpaneld]34.87.8.86--\"GET/@fs/.env\?url\
show less
Port Scan
Brute-Force
Web App Attack
๐ฆ๐บ
rubixstudios
2026-09-17 16:52:02
(11 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 16:39:55
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.8.86 (86.8.87.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.8.86 (86.8.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 12:39:49.573065 2026] [security2:error] [pid 936:tid 936] [client 34.87.8.86:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cloudex.click"] [uri "/@fs/app/.env"] [unique_id "aqwX1RmNWzM6bngDthtMOQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-17 15:43:07
(12 hours ago)
excessive HTTP 404 errors
Bad Web Bot
๐ฉ๐ช
itsolon
2026-09-17 14:42:08
(13 hours ago)
[17/Sep/2026:16:42:06 +0200] 178965612678.886492 34.87.8.86 54726 217.154.7.177 443
[17/Sep/2026:16: ...
show more
[17/Sep/2026:16:42:06 +0200] 178965612678.886492 34.87.8.86 54726 217.154.7.177 443
[17/Sep/2026:16:42:07 +0200] 178965612763.888338 34.87.8.86 54726 217.154.7.177 443
[17/Sep/2026:16:42:07 +0200] 178965612758.970535 34.87.8.86 54726 217.154.7.177 443
[17/Sep/2026:16:42:07 +0200] 178965612749.798080 34.87.8.86 54726 217.154.7.177 443
[17/Sep/2026:16:42:07 +0200] 178965612712.549748 34.87.8.86 54726 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ช๐ธ
el-brujo
2026-09-17 13:55:49
(14 hours ago)
Cloudflare WAF: Request Path: /mcp Request Query: Host: chat.elhacker.net userAgent: Mozilla/5.0 (c ...
show more
Cloudflare WAF: Request Path: /mcp Request Query: Host: chat.elhacker.net userAgent: Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/) Action: block Source: firewallManaged ASN Description: Google LLC Country: SG Method: POST Timestamp: 2026-09-17T13:55:49Z ruleId: e7e4b386797e417c998d872956c390a1. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
Anonymous
2026-09-17 12:44:42
(15 hours ago)
Aggressive web scan
Web App Attack
Anonymous
2026-09-17 08:39:47
(19 hours ago)
34.87.8.86 - - [17/Sep/2026:08:39:46 +0000] "GET /secrets.env HTTP/1.1" 404 2960 "-" "CCBot/2.0 (htt ...
show more
34.87.8.86 - - [17/Sep/2026:08:39:46 +0000] "GET /secrets.env HTTP/1.1" 404 2960 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
...
show less
Brute-Force
Web App Attack