๐บ๐ธ
Charlesiv
2026-10-09 04:00:16
(21 hours ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Endpoint: /cgi-bin/php
Query: ?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input
Timestamp: 2026-10-09T03:35:30Z
Ray ID: a47a55f04e71a1fc
UA: Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)
show less
Bad Web Bot
๐ฉ๐ช
pscriptos
2026-10-09 03:51:45
(21 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ด
Abuse Buster
2026-10-09 01:46:00
(23 hours ago)
35.203.83.31 - - [09/Oct/2026:03:45:57 +0200] "GET /build../.env HTTP/2.0" 404 22 "-" "Mozilla/5.0 ( ...
show more
35.203.83.31 - - [09/Oct/2026:03:45:57 +0200] "GET /build../.env HTTP/2.0" 404 22 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
35.203.83.31 - - [09/Oct/2026:03:45:57 +0200] "GET /css../.env HTTP/2.0" 404 22 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
...
show less
Web App Attack
๐ซ๐ฎ
oh.mg
2026-10-09 01:41:55
(23 hours ago)
[Fri Oct 09 03:41:55.158388 2026] [security2:error] [pid 1077665:tid 1077691] [client 35.203.83.31:0 ...
show more
[Fri Oct 09 03:41:55.158388 2026] [security2:error] [pid 1077665:tid 1077691] [client 35.203.83.31:0] [client 35.203.83.31] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "api.mmn.ca"] [uri "/login"] [unique_id "ashGY8FPwCzO9wp1ch1zigAAABg"]
[Fri Oct 09 03:41:55.193758 2026] [security2:error] [pid 1103053:tid 1103057] [client 35.203.83.31:0] [client 35.203.83.31] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evalu
...
show less
Web App Attack
Bad Web Bot
๐ฉ๐ช
s@ch@
2026-10-09 01:30:01
(1 day ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack
๐ช๐ธ
el-brujo
2026-10-09 01:28:23
(1 day ago)
Cloudflare WAF: Request Path: /php-cgi/php-cgi.exe Request Query: ?%ADd+allow_url_include%3d1+%ADd+a ...
show more
Cloudflare WAF: Request Path: /php-cgi/php-cgi.exe Request Query: ?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input Host: api.elhacker.net userAgent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] ) Action: block Source: firewallCustom ASN Description: Google LLC Country: CA Method: POST Timestamp: 2026-10-09T01:28:23Z ruleId: 6b2d48d0415e4adb9f099d85f54d1de6. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
๐ฌ๐ง
andypiper
2026-10-09 01:01:47
(1 day ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ฉ๐ช
raph
2026-10-09 00:34:07
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
jfz-abuse
2026-10-09 00:13:49
(1 day ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐ช๐ธ
robotstxt
2026-10-09 00:09:21
(1 day ago)
35.203.83.31 - - [08/Oct/2026:23:28:36 +0000] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+ ...
show more
35.203.83.31 - - [08/Oct/2026:23:28:36 +0000] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 189 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" "-" edge="35.203.83.31"
35.203.83.31 - - [08/Oct/2026:23:28:36 +0000] "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 189 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" "-" edge="35.203.83.31"
35.203.83.31 - - [08/Oct/2026:23:28:36 +0000] "POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1" 404 189 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "-" edge="35.203.83.31"
35.203.83.31 - - [08/Oct/2026:23:28:36 +0000] "POST /cgi-bin/php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1" 404 189 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" "-" edge="35.2
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-09 00:01:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.203.83.31 (31.83.203.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.83.31 (31.83.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:00:49.397328 2026] [security2:error] [pid 29465:tid 29465] [client 35.203.83.31:47554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tracytappan.net"] [uri "/static../.env"] [unique_id "asgusYdpahLMlxMXMMWW5wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2026-10-08 23:47:36
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action: BLOCK | Protocol: HTTP/2 (POST) | Endpoin ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action: BLOCK | Protocol: HTTP/2 (POST) | Endpoint: /cgi-bin/php-cgi | UA: Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/) โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
oijon.net
2026-10-08 23:32:47
(1 day ago)
[Thu Oct 08 19:32:45.582939 2026] [php:error] [pid 2276037:tid 2276037] [client 35.203.83.31:55978] ...
show more
[Thu Oct 08 19:32:45.582939 2026] [php:error] [pid 2276037:tid 2276037] [client 35.203.83.31:55978] script '/var/www/oijon/document.php' not found or unable to stat
[Thu Oct 08 19:32:46.514167 2026] [php:error] [pid 2275933:tid 2275933] [client 35.203.83.31:56064] script '/var/www/oijon/i.php' not found or unable to stat
[Thu Oct 08 19:32:46.761844 2026] [php:error] [pid 2275933:tid 2275933] [client 35.203.83.31:56064] script '/var/www/oijon/info.php' not found or unable to stat
[Thu Oct 08 19:32:46.767108 2026] [php:error] [pid 2276036:tid 2276036] [client 35.203.83.31:56096] script '/var/www/oijon/phpinfo.php' not found or unable to stat
[Thu Oct 08 19:32:46.771796 2026] [php:error] [pid 2275962:tid 2275962] [client 35.203.83.31:55982] script '/var/www/oijon/pi.php' not found or unable to stat
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 23:30:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.203.83.31 (31.83.203.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.83.31 (31.83.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:30:05.309190 2026] [security2:error] [pid 25143:tid 25143] [client 35.203.83.31:41864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yeejia.net"] [uri "/.htpasswd"] [unique_id "asgnfarUADcc7Fwzt0o9CwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-10-08 23:28:32
(1 day ago)
35.203.83.31 - - [08/Oct/2026:23:28:28 +0000] "GET /..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="35 ...
show more
35.203.83.31 - - [08/Oct/2026:23:28:28 +0000] "GET /..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.203.83.31"
35.203.83.31 - - [08/Oct/2026:23:28:28 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.203.83.31"
35.203.83.31 - - [08/Oct/2026:23:28:28 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.203.83.31"
35.203.83.31 - - [08/Oct/2026:23:28:28 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="35.203.83.31"
35.203.83.31 - - [08/Oct/2026:23:28:28 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="35.203.83.31"
...
show less
Web Spam
Web App Attack