๐ฉ๐ช
Holger
2026-10-02 08:32:23
(16 hours ago)
Bruteforce WebAttack
Brute-Force
Web App Attack
๐ช๐ธ
el-brujo
2026-09-30 04:35:48
(2 days ago)
Cloudflare WAF: Request Path: /@fs/home/ec2-user/.aws/credentials Request Query: ?raw?? Host: foro.e ...
show more
Cloudflare WAF: Request Path: /@fs/home/ec2-user/.aws/credentials Request Query: ?raw?? Host: foro.elhacker.net userAgent: Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/) Action: block Source: firewallCustom ASN Description: Google LLC Country: BR Method: GET Timestamp: 2026-09-30T04:35:48Z ruleId: 6b2d48d0415e4adb9f099d85f54d1de6. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
JustMeHere
2026-09-30 02:09:40
(2 days ago)
[Tue Sep 29 22:09:35.623194 2026] [security2:error] [pid 794:tid 915] [client 35.247.251.187:56160] ...
show more
[Tue Sep 29 22:09:35.623194 2026] [security2:error] [pid 794:tid 915] [client 35.247.251.187:56160] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "forum.yorknation.com"] [uri "/"] [unique_id "arxvX2sAeERpDBes91bGKAAAAAs"]
...
show less
Web App Attack
๐ง๐ช
cmbplf
2026-09-30 02:02:31
(2 days ago)
5.833 requests from abuseipdb.com blacklisted IP (3w1d6h)
Brute-Force
Bad Web Bot
Anonymous
2026-09-30 01:33:08
(2 days ago)
35.247.251.187 - - [30/Sep/2026:09:33:07 +0800] "GET /gou9yqa0kj2k61ajxb5j HTTP/1.1" 404 196 "-" "Mo ...
show more
35.247.251.187 - - [30/Sep/2026:09:33:07 +0800] "GET /gou9yqa0kj2k61ajxb5j HTTP/1.1" 404 196 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
35.247.251.187 - - [30/Sep/2026:09:33:07 +0800] "GET /z9x8c7v6b5-debug-trigger-folical.com.cn HTTP/1.1" 404 196 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
35.247.251.187 - - [30/Sep/2026:09:33:07 +0800] "GET /dpxmnu8g9alglg7hih3q HTTP/1.1" 404 196 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
35.247.251.187 - - [30/Sep/2026:09:33:07 +0800] "POST /login HTTP/1.1" 404 196 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
35.247.251.187 - - [30/Sep/2026:09:33:07 +0800] "POST /graphql HTTP/1.1" 404 196 "https://folical.com.cn" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.247.251.187 - - [30/Sep/2026:09:33:07 +0800] "GET /service-worker.js HTTP/1.1" 404 19
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 00:59:59
(2 days ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
[email protected]
2026-09-29 23:28:43
(3 days ago)
CrowdSec ban: crowdsecurity/http-admin-interface-probing (duration: 65h7m5s)
Web App Attack
๐ซ๐ท
ingroscart.it
2026-09-29 23:05:52
(3 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐ง๐ท
radardatelecom
2026-09-29 22:26:03
(3 days ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-09-29 21:48:04
(3 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
[email protected]
2026-09-29 21:18:36
(3 days ago)
CrowdSec ban: crowdsecurity/http-admin-interface-probing (duration: 67h17m13s)
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-29 21:07:31
(3 days ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack
Anonymous
2026-09-29 20:40:02
(3 days ago)
Web application attack detected.
Web App Attack
๐ฉ๐ช
AetherFox
2026-09-29 20:23:54
(3 days ago)
AetherFox VoidGuard detected: [Tue Sep 29 20:23:52.996015 2026] [authz_core:error] [pid 467610:tid 4 ...
show more
AetherFox VoidGuard detected: [Tue Sep 29 20:23:52.996015 2026] [authz_core:error] [pid 467610:tid 467652] [client 35.247.251.187:58886] AH01630: client denied by server configuration: proxy:https://[MASKED]/lib/terminal-xhr.php
[Tue Sep 29 20:23:53.001611 2026] [authz_core:error] [pid 535429:tid 535450] [client 35.247.251.187:58888] AH01630: client denied by server configuration: proxy:https://[MASKED]/z9x8c7v6b5-debug-trigger-draconigen.net
[Tue Sep 29 20:23:53.007230 2026] [authz_core:error] [pid 535429:tid 535443] [client 35.247.251.187:58906] AH01630: client denied by server configuration: proxy:https://[MASKED]/yc500jk2oanzqfs2glgy
[Tue Sep 29 20:23:53.014421 2026] [authz_core:error] [pid 535429:tid 535440] [client 35.247.251.187:58926] AH01630: client denied by server configuration: proxy:https://[MASKED]/e2i73by8b21ihk2faxpz
[Tue Sep 29 20:23:53.648635 2026] [authz_core:error] [pid 467611:tid 467661] [client 35.247.251.187:58980] AH01630: client
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 20:19:01
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.247.251.187 (187.251.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.247.251.187 (187.251.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:18:56.524600 2026] [security2:error] [pid 25386:tid 25386] [client 35.247.251.187:38358] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||grupoporvenir.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "grupoporvenir.com"] [uri "/z9x8c7v6b5-debug-trigger-grupoporvenir.com"] [unique_id "arwdMGBupfRj2ZU1Dk8rhAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack