๐บ๐ธ
Charlesiv
2026-10-09 06:01:10
(2 days ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Endpoint: /exec-py
Timestamp: 2026-10-09T04:50:46Z
Ray ID: a47ac42fc84a180e
UA: Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)
show less
Bad Web Bot
๐ฉ๐ช
itsolon
2026-10-09 05:06:42
(2 days ago)
[09/Oct/2026:07:06:41 +0200] 179152240184.157465 35.203.78.248 51308 217.154.7.177 443
[09/Oct/2026: ...
show more
[09/Oct/2026:07:06:41 +0200] 179152240184.157465 35.203.78.248 51308 217.154.7.177 443
[09/Oct/2026:07:06:41 +0200] 179152240127.303324 35.203.78.248 51308 217.154.7.177 443
[09/Oct/2026:07:06:41 +0200] 179152240162.779253 35.203.78.248 51308 217.154.7.177 443
[09/Oct/2026:07:06:41 +0200] 179152240175.804267 35.203.78.248 51308 217.154.7.177 443
[09/Oct/2026:07:06:41 +0200] 17915224016.522751 35.203.78.248 51308 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ช๐ธ
el-brujo
2026-10-09 04:35:29
(2 days ago)
Cloudflare WAF: Request Path: /flowise/api/v1/node-load-method/customMCP Request Query: Host: chat. ...
show more
Cloudflare WAF: Request Path: /flowise/api/v1/node-load-method/customMCP Request Query: Host: chat.elhacker.net userAgent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] ) Action: block Source: firewallManaged ASN Description: Google LLC Country: CA Method: POST Timestamp: 2026-10-09T04:35:29Z ruleId: 3fe69f2a728e40dfabd2cfb602a9ee96. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
Anonymous
2026-10-09 01:06:43
(2 days ago)
35.203.78.248 - - [08/Oct/2026:16:53:11 -0500] "GET /.env.js HTTP/1.1" 403 199 "-" "Mozilla/5.0 (com ...
show more
35.203.78.248 - - [08/Oct/2026:16:53:11 -0500] "GET /.env.js HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" 35.203.78.248
35.203.78.248 - - [08/Oct/2026:17:59:01 -0500] "GET /.env.js HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" 35.203.78.248
35.203.78.248 - - [08/Oct/2026:20:06:41 -0500] "GET /.env.js HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" 35.203.78.248
35.203.78.248 - - [08/Oct/2026:20:06:42 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" 35.203.78.248
35.203.78.248 - - [08/Oct/2026:20:06:42 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" 35.203.78.248
35.203.78.248 - - [08/Oct/2026:20:06:42 -0500] "GET /.env.production?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; MistralAI-U
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Omega Threat-ID
2026-10-09 01:02:03
(2 days ago)
Omega Point Threat ID honeypot sensor observed: abuse-reported
Port Scan
๐ฉ๐ช
zumbo.net
2026-10-08 23:11:44
(2 days ago)
[Fri Oct 09 02:11:42.228732 2026] [proxy_fcgi:error] [pid 1524340:tid 1524384] [client 35.203.78.248 ...
show more
[Fri Oct 09 02:11:42.228732 2026] [proxy_fcgi:error] [pid 1524340:tid 1524384] [client 35.203.78.248:0] AH01071: Got error 'Primary script unknown'
[Fri Oct 09 02:11:43.013495 2026] [proxy_fcgi:error] [pid 1524340:tid 1524389] [client 35.203.78.248:0] AH01071: Got error 'Primary script unknown'
[Fri Oct 09 02:11:43.143471 2026] [proxy_fcgi:error] [pid 1524340:tid 1524368] [client 35.203.78.248:0] AH01071: Got error 'Primary script unknown'
[Fri Oct 09 02:11:43.348071 2026] [proxy_fcgi:error] [pid 1524339:tid 1524344] [client 35.203.78.248:0] AH01071: Got error 'Primary script unknown'
[Fri Oct 09 02:11:43.408331 2026] [proxy_fcgi:error] [pid 1524339:tid 1524369] [client 35.203.78.248:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
guillaume illien
2026-10-08 23:11:20
(2 days ago)
35.203.78.248 - - [08/Oct/2026:23:11:18 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2 ...
show more
35.203.78.248 - - [08/Oct/2026:23:11:18 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 166 "-" "-"
35.203.78.248 - - [08/Oct/2026:23:11:19 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 166 "-" "-"
35.203.78.248 - - [08/Oct/2026:23:11:19 +0000] "GET /..%2f.env HTTP/1.1" 400 166 "-" "-"
35.203.78.248 - - [08/Oct/2026:23:11:19 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 166 "-" "-"
35.203.78.248 - - [08/Oct/2026:23:11:20 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 166 "-" "-"
35.203.78.248 - - [08/Oct/2026:23:11:20 +0000] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 166 "-" "-"
35.203.78.248 - - [08/Oct/2026:23:11:20 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 166 "-" "-"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
๐ณ๐ด
Abuse Buster
2026-10-08 23:11:16
(2 days ago)
35.203.78.248 - - [09/Oct/2026:01:11:15 +0200] "GET /z9x8c7v6b5-debug-trigger-api.wingthor.net HTTP/ ...
show more
35.203.78.248 - - [09/Oct/2026:01:11:15 +0200] "GET /z9x8c7v6b5-debug-trigger-api.wingthor.net HTTP/2.0" 404 22 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
35.203.78.248 - - [09/Oct/2026:01:11:15 +0200] "GET /g2honur34duvoxc64s93 HTTP/2.0" 404 22 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
35.203.78.248 - - [09/Oct/2026:01:11:15 +0200] "GET /k9xo23kpukn1airul1bu HTTP/2.0" 404 22 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Web App Attack
๐ซ๐ฎ
oh.mg
2026-10-08 23:07:39
(2 days ago)
[Fri Oct 09 01:07:39.059820 2026] [security2:error] [pid 1077665:tid 1077682] [client 35.203.78.248: ...
show more
[Fri Oct 09 01:07:39.059820 2026] [security2:error] [pid 1077665:tid 1077682] [client 35.203.78.248:0] [client 35.203.78.248] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "api.mmn.ca"] [uri "/"] [unique_id "asgiO8FPwCzO9wp1ch1hXgAAAA8"]
[Fri Oct 09 01:07:39.427059 2026] [security2:error] [pid 1077665:tid 1077684] [client 35.203.78.248:0] [client 35.203.78.248] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evalua
...
show less
Web App Attack
Bad Web Bot
๐ช๐ธ
el-brujo
2026-10-08 22:58:15
(2 days ago)
Cloudflare WAF: Request Path: /cgi-bin/php Request Query: ?-d+allow_url_include%3don+-d+auto_prepend ...
show more
Cloudflare WAF: Request Path: /cgi-bin/php Request Query: ?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input Host: api.elhacker.net userAgent: Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html) Action: block Source: firewallCustom ASN Description: Google LLC Country: CA Method: POST Timestamp: 2026-10-08T22:58:15Z ruleId: 6b2d48d0415e4adb9f099d85f54d1de6. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
[email protected]
2026-10-08 22:53:08
(2 days ago)
CrowdSec ban: crowdsecurity/http-crawl-non_statics (duration: 70h44m39s)
Web App Attack
๐ธ๐ช
mrmister
2026-10-08 22:33:38
(2 days ago)
Automated report from a Cowrie/web honeypot (no legitimate users). web honeypot: 290 requests. Last ...
show more
Automated report from a Cowrie/web honeypot (no legitimate users). web honeypot: 290 requests. Last seen 2026-10-08 22:26:33 UTC.
show less
Web App Attack
๐ง๐ท
radardatelecom
2026-10-08 22:27:03
(2 days ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-10-08 22:16:11
(2 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-10-08 21:50:11
(2 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack