Anonymous
2026-10-09 05:14:00
(5 hours ago)
Brute-Force
π³π±
Site.eu
2026-10-09 03:53:43
(6 hours ago)
Excessive multi-domain requests
Brute-Force
π«π·
guillaume illien
2026-10-09 03:36:58
(7 hours ago)
35.203.63.34 - - [09/Oct/2026:03:36:57 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e ...
show more
35.203.63.34 - - [09/Oct/2026:03:36:57 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 166 "-" "-"
35.203.63.34 - - [09/Oct/2026:03:36:58 +0000] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
35.203.63.34 - - [09/Oct/2026:03:36:58 +0000] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env HTTP/1.1" 400 166 "-" "-"
35.203.63.34 - - [09/Oct/2026:03:36:58 +0000] "GET /api/attachments/img/avatar/..%2F..%2F..%2F..%2F..%2F.env HTTP/1.1" 400 166 "-" "-"
35.203.63.34 - - [09/Oct/2026:03:36:58 +0000] "GET /appearance/../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
35.203.63.34 - - [09/Oct/2026:03:36:58 +0000] "GET /appearance/../../.env HTTP/1.1" 400 166 "-" "-"
35.203.63.34 - - [09/Oct/2026:03:36:58 +0000] "GET /api/attachments/img/avatar/..%2F..%2F..%2F..%2F..%2Fproc%2Fself%2Fenviron HTTP/1.1" 400 166 "-" "-"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
π«π·
regishoussin
2026-10-09 03:20:36
(7 hours ago)
Automated web scanning detected by Wazuh (rule 100240): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100240): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-10-09 03:20 UTC.
show less
Bad Web Bot
Web App Attack
π«π·
guillaume illien
2026-10-09 02:39:38
(8 hours ago)
35.203.63.34 - - [09/Oct/2026:02:39:37 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e ...
show more
35.203.63.34 - - [09/Oct/2026:02:39:37 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 166 "-" "-"
35.203.63.34 - - [09/Oct/2026:02:39:37 +0000] "GET /appearance/../../.env HTTP/1.1" 400 166 "-" "-"
35.203.63.34 - - [09/Oct/2026:02:39:37 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 166 "-" "-"
35.203.63.34 - - [09/Oct/2026:02:39:37 +0000] "GET /..%2f.env HTTP/1.1" 400 166 "-" "-"
35.203.63.34 - - [09/Oct/2026:02:39:37 +0000] "GET /appearance/../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
35.203.63.34 - - [09/Oct/2026:02:39:37 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 166 "-" "-"
35.203.63.34 - - [09/Oct/2026:02:39:38 +0000] "GET /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 166 "-" "-"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
π³π΄
Abuse Buster
2026-10-09 02:39:34
(8 hours ago)
35.203.63.34 - - [09/Oct/2026:04:39:32 +0200] "GET /j91pxk4kb8o93iaugt4o HTTP/2.0" 404 22 "-" "Mozil ...
show more
35.203.63.34 - - [09/Oct/2026:04:39:32 +0200] "GET /j91pxk4kb8o93iaugt4o HTTP/2.0" 404 22 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
35.203.63.34 - - [09/Oct/2026:04:39:32 +0200] "GET /jsspem6c30zk884ics4w HTTP/2.0" 404 22 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
35.203.63.34 - - [09/Oct/2026:04:39:32 +0200] "GET /z9x8c7v6b5-debug-trigger-api.wingthor.net HTTP/2.0" 404 22 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
...
show less
Web App Attack
πͺπΈ
el-brujo
2026-10-09 02:23:56
(8 hours ago)
Cloudflare WAF: Request Path: /api/v1/build_public_tmp/00000000-0000-0000-0000-000000000000/flow Req ...
show more
Cloudflare WAF: Request Path: /api/v1/build_public_tmp/00000000-0000-0000-0000-000000000000/flow Request Query: Host: api.elhacker.net userAgent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot) Action: block Source: ratelimit ASN Description: Google LLC Country: CA Method: POST Timestamp: 2026-10-09T02:23:56Z ruleId: c0c2d5c2a7024f7fbdba4d0f7a002ea8. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
πΊπΈ
Charlesiv
2026-10-09 02:12:05
(8 hours ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Endpoint: /exec-py
Timestamp: 2026-10-09T01:58:16Z
Ray ID: a479c782d8743786
UA: Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)
show less
Bad Web Bot
π©πͺ
Bedios GmbH
2026-10-09 01:57:48
(8 hours ago)
Keyfile theft attempt
Hacking
π©πͺ
raph
2026-10-09 01:26:52
(9 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
ππ°
zhengka
2026-10-09 00:56:09
(9 hours ago)
ZhengKa WAF detected scan_probe. Rule: scan_probe #/(?:\.env|\.git|\.svn|composer\.json|composer\.lo ...
show more
ZhengKa WAF detected scan_probe. Rule: scan_probe #/(?:\.env|\.git|\.svn|composer\.json|composer\.lock|id_rsa|server-status)(?:$|[/?])#. Method: GET. URI: /.ssh/id_rsa. Incident: A4A25C88F8A732E0. UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)
show less
Port Scan
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 00:41:33
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.63.34 (34.63.203.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.63.34 (34.63.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:41:29.978570 2026] [security2:error] [pid 21591:tid 21591] [client 35.203.63.34:33834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "utilis.net"] [uri "/.env"] [unique_id "asg4OWITESrGRltpYAh8GQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 00:38:16
(10 hours ago)
$f2bV_matches
Brute-Force
Web App Attack
π©πͺ
pscriptos
2026-10-09 00:29:00
(10 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
πΊπΈ
entangled_mongoose
2026-10-09 00:28:09
(10 hours ago)
Probed /wp-json.
Web App Attack