๐บ๐ธ
Charlesiv
2026-09-02 16:00:25
(7 minutes ago)
Triggered Cloudflare WAF (botFight) from US.
Action taken: MANAGED_CHALLENGE
ASN: 14618 (Amazon.com, ...
show more
Triggered Cloudflare WAF (botFight) from US.
Action taken: MANAGED_CHALLENGE
ASN: 14618 (Amazon.com, Inc.)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-09-02T15:08:55Z
Ray ID: a34d6ecea85df3e0
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Bad Web Bot
๐ฉ๐ช
dispaisyenterprises
2026-09-02 15:22:02
(45 minutes ago)
Triggered Cloudflare WAF (botFight) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (GET) | ...
show more
Triggered Cloudflare WAF (botFight) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (GET) | Endpoint: / | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 โข Reported by DisPaisy Enterprises (dispaisy.systems)
show less
Bad Web Bot
๐บ๐ธ
Rip
2026-09-02 14:09:04
(1 hour ago)
PHP Injection Attack โ High-Risk PHP Function Call Found
Web App Attack
๐บ๐ธ
nekoify
2026-09-02 14:07:14
(2 hours ago)
IP has triggered Cloudflare WAF. action: managed_challenge source: botFight clientAsn: 14618 clientA ...
show more
IP has triggered Cloudflare WAF. action: managed_challenge source: botFight clientAsn: 14618 clientASNDescription: Amazon.com, Inc. clientCountryName: US clientIP: 44.201.34.192 clientRequestHTTPMethodName: POST clientRequestHTTPProtocol: HTTP/1.1 clientRequestPath: / clientRequestQuery: datetime: 2026-09-02T14:07:14Z rayName: a34d1471b9518651 ruleId: bot_fight_mode userAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36.
show less
Open Proxy
VPN IP
Port Scan
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
thesimonmanuel
2026-09-02 13:48:01
(2 hours ago)
2026/09/02 17:22:15 [error] 1832021#1832021: *348522 directory index of "/home/[redacted]/htdocs/[re ...
show more
2026/09/02 17:22:15 [error] 1832021#1832021: *348522 directory index of "/home/[redacted]/htdocs/[redacted].com/" is forbidden, client: 44.201.34.192, server: [redacted].com, request: "POST / HTTP/1.1", host: "[redacted].com", referrer: "https://[redacted].com/"
2026/09/02 17:22:15 [error] 1832020#1832020: *348524 directory index of "/home/[redacted]/htdocs/[redacted].com/" is forbidden, client: 44.201.34.192, server: [redacted].com, request: "POST / HTTP/1.1", host: "[redacted].com", referrer: "https://[redacted].[redacted]/"
2026/09/02 19:18:01 [error] 1832020#1832020: *349657 directory index of "/home/[redacted]/htdocs/[redacted].com/" is forbidden, client: 44.201.34.192, server: [redacted].com, request: "POST / HTTP/1.1", host: "[redacted].com", referrer: "https://www.[redacted].[redacted]/"
show less
Port Scan
Web App Attack
๐จ๐ฟ
ddw
2026-09-02 13:27:46
(2 hours ago)
ModSecurity detection - Rules: 949110(Inbound Anomaly Score Exceeded (Total Score: 60))
Web App Attack
๐ฉ๐ช
IVski.com
2026-09-02 12:59:12
(3 hours ago)
IVski WAF | Blocked POST to site root โ likely automated form/exploit spam or probe
Hacking
Brute-Force
Web App Attack
๐จ๐ญ
Ribeye375
2026-09-02 12:41:01
(3 hours ago)
HIPS nginx-access-errors - Block tcp/http,https
Brute-Force
๐บ๐ธ
Rip
2026-09-02 12:37:31
(3 hours ago)
403 Errors: Access Forbidden
Brute-Force
๐ฎ๐น
eliosbrocchi
2026-09-02 12:26:29
(3 hours ago)
44.201.34.192 - - [02/Sep/2026:13:22:36 +0200] "POST / HTTP/1.1" 404 4717 "https://plex.crislio.com/ ...
show more
44.201.34.192 - - [02/Sep/2026:13:22:36 +0200] "POST / HTTP/1.1" 404 4717 "https://plex.crislio.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
44.201.34.192 - - [02/Sep/2026:13:48:30 +0200] "POST / HTTP/1.1" 404 4668 "https://servermet.crislio.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
44.201.34.192 - - [02/Sep/2026:14:26:24 +0200] "POST / HTTP/1.1" 403 4725 "https://ups.crislio.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
44.201.34.192 - - [02/Sep/2026:14:26:25 +0200] "POST / HTTP/1.1" 403 783 "https://ups.crislio.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
44.201.34.192 - - [02/Sep/2026:14:26:25 +0200] "POST / HTTP/1.1" 403 460 "https://ups.crislio.com/" "Mozilla/5.0 (Windows NT 10.
...
show less
VPN IP
๐จ๐ญ
4server
2026-09-02 12:23:26
(3 hours ago)
[WedSep0214:23:20.0129942026][security2:error][pid3722208:tid3722977][client44.201.34.192:0]ModSecur ...
show more
[WedSep0214:23:20.0129942026][security2:error][pid3722208:tid3722977][client44.201.34.192:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?i\)\\\\\\\\b\(\?:i\(\?:s\(\?:_\(\?:in\(\?:t\(\?:eger\)\?\|finite\)\|n\(\?:u\(\?:meric\|ll\)\|an\)\|\(\?:calla\|dou\)ble\|s\(\?:calar\|tring\)\|f\(\?:inite\|loat\)\|re\(\?:source\|al\)\|l\(\?:ink\|ong\)\|a\(\?:rray\)\?\|object\|bool\)\|set\)\|n\(\?:\(\?:clud\|vok\)e\|t\(\?:div\|val\)\)\|\(\?:mplod\|dat\)e\|conv\)\|s\(\?:t\(\?:r\(\?:\(\?:le\|sp\)n\|...\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"582\"][id\"380026\"][rev\"27\"][msg\"Atomicorp.comWAFRules:PHPpayloaddetected\"][data\"split\(\\\\x5c\\\\x22\\\\x5c\\\\x22\).reverse\(\).join\(\\\\x5c\\\\x22\\\\x5c\\\\x22\)].from\(\'kgfzew5jigz1bmn0aw9ukcl7ci8vigzhc3rfcmvjb25fdjyg4ocuihnpz25hdhvyzs1yb3rhdgvkihjly29uihbhewxvywqkly8gq2hhbmdlcybmcm9tihy1ogovlyagic0gumfuzg9taxplzcb0b3atbgv2zwwgslnptibrzxlzichubybmaxhlzcbzy2hlbwegdg8gzmluz2vychjpbnqpci8vicaglsbwyxjpywjszsbvdxrwdxqgc3rydwn
show less
Hacking
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-02 12:07:28
(4 hours ago)
HTTP header is restricted by policy (/content-encoding/). String match within "/content-encoding/ /p ...
show more
HTTP header is restricted by policy (/content-encoding/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_content-encoding. (920450-mnz6-7)
show less
Bad Web Bot
๐ซ๐ฎ
mnazibo
2026-09-02 12:00:16
(4 hours ago)
Date: Sep 02 14:28:30 2026 EAT | Reported IP: 44.201.34.192 mod_security | id: 933160 934100 934130 ...
show more
Date: Sep 02 14:28:30 2026 EAT | Reported IP: 44.201.34.192 mod_security | id: 933160 934100 934130 942550 949110 200002 920450 | US/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; PHP Injection Attack: High-Risk PHP Function Call Found; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; JavaScript Prototype Pollution; JavaScript Prototype Pollution; JavaScript Prototype Pollution; JSON-Based SQL Injection; Inbound Anomaly Score Exceeded (Total Score: 45); Failed to parse request body.; HTTP header is restricted by policy (/content-encoding/)
show less
SQL Injection
Brute-Force
Bad Web Bot
๐ฉ๐ช
thesimonmanuel
2026-09-02 11:52:15
(4 hours ago)
2026/09/02 17:22:14 [error] 1832021#1832021: *348522 directory index of "/home/[redacted]/htdocs/[re ...
show more
2026/09/02 17:22:14 [error] 1832021#1832021: *348522 directory index of "/home/[redacted]/htdocs/[redacted].com/" is forbidden, client: 44.201.34.192, server: [redacted].com, request: "POST / HTTP/1.1", host: "[redacted].com", referrer: "https://[redacted].com/"
2026/09/02 17:22:15 [error] 1832021#1832021: *348522 directory index of "/home/[redacted]/htdocs/[redacted].com/" is forbidden, client: 44.201.34.192, server: [redacted].com, request: "POST / HTTP/1.1", host: "[redacted].com", referrer: "https://[redacted].[redacted]/"
2026/09/02 17:22:15 [error] 1832020#1832020: *348524 directory index of "/home/[redacted]/htdocs/[redacted].com/" is forbidden, client: 44.201.34.192, server: [redacted].com, request: "POST / HTTP/1.1", host: "[redacted].com", referrer: "https://[redacted].com/"
show less
Port Scan
Web App Attack
๐บ๐ธ
CollideTech
2026-09-02 11:51:51
(4 hours ago)
probing for vulnerabilities
Web App Attack