๐ณ๐ฑ
JCB
2025-09-01 15:55:00
(1 year ago)
45.9.148.131 - - [01/Sep/2025:11:32:28 +0300] "PUT /check.txt HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Ub ...
show more
45.9.148.131 - - [01/Sep/2025:11:32:28 +0300] "PUT /check.txt HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
45.9.148.131 - - [01/Sep/2025:11:32:28 +0300] "PUT /uploads/../sessions/absholi7ly.session HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Kubuntu; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
๐ง๐ช
Ivo Vynckier
2025-09-01 08:26:00
(1 year ago)
45.9.148.131 - - [01/Sep/2025:00:23:51 +0200] "PUT /check.txt HTTP/1.1" 405 760 "-" "Mozilla/5.0 (X1 ...
show more
45.9.148.131 - - [01/Sep/2025:00:23:51 +0200] "PUT /check.txt HTTP/1.1" 405 760 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/118.0"
45.9.148.131 - - [01/Sep/2025:00:23:51 +0200] "PUT /uploads/../sessions/absholi7ly.session HTTP/1.1" 405 760 "-" "Mozilla/5.0 (Debian; Linux i686; rv:121.0) Gecko/20100101 Firefox/121.0"
45.9.148.131 - - [01/Sep/2025:00:23:51 +0200] "GET /index.jsp HTTP/1.1" 404 2322 "-" "Mozilla/5.0 (Ubuntu; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
show less
Hacking
๐ฎ๐ฉ
Burayot
2025-09-01 07:25:35
(1 year ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 45.9.148.131 (NL/The Netherlands/-): ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 45.9.148.131 (NL/The Netherlands/-): 2 in the last 3600 secs
show less
Web App Attack
๐ช๐ธ
el-brujo
2025-09-01 06:53:49
(1 year ago)
Cloudflare WAF: Request Path: /uploads/../sessions/absholi7ly.session Request Query: Host: warzone. ...
show more
Cloudflare WAF: Request Path: /uploads/../sessions/absholi7ly.session Request Query: Host: warzone.elhacker.net userAgent: Mozilla/5.0 (Kubuntu; Linux i686; rv:133.0) Gecko/20100101 Firefox/133.0 Action: block Source: firewallManaged ASN Description: NICEIT Country: NL Method: PUT Timestamp: 2025-09-01T06:53:49Z ruleId: d104e3246dc14ac7851b4049d9d8c5f2. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐จ๐ญ
backslash
2025-09-01 00:05:22
(1 year ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
๐บ๐ธ
jcbriar
2025-08-31 22:40:59
(1 year ago)
Searching for vulnerable scripts
Hacking
Web App Attack
๐บ๐ธ
thefoofighter
2025-08-31 21:55:03
(1 year ago)
[Sun Aug 31 21:55:02.183913 2025] [:error] [pid 1618617] [client 45.9.148.131:41096] [client 45.9.14 ...
show more
[Sun Aug 31 21:55:02.183913 2025] [:error] [pid 1618617] [client 45.9.148.131:41096] [client 45.9.148.131] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 17)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "sourcemodding.com"] [uri "/check.txt"] [unique_id "aLTEtiRqNYc8-MjZeN7YvQAAAAU"]
[Sun Aug 31 21:55:02.629564 2025] [:error] [pid 1618776] [client 45.9.148.131:41098] [client 45.9.148.131] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [ver "OWASP_CRS/3
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
jhuisi
2025-08-31 21:20:14
(1 year ago)
Mod Security Hit
Web App Attack
Anonymous
2025-08-31 11:41:02
(1 year ago)
Malicious activity detected
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2025-08-31 11:32:18
(1 year ago)
31/Aug/2025:13:32:17.816549 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
31/Aug/2025:13:32:17.816549 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 45.9.148.131] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "44"] [id "911100"] [msg "Method is not allowed by policy"] [data "PUT"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "ns2.elhacker.net"] [uri "/check.txt"] [unique_id "aLQywSORfw7Jzj28byjk7QADhyw"]
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2025-08-31 11:32:17
(1 year ago)
Cloudflare WAF: Request Path: /uploads/../sessions/absholi7ly.session Request Query: Host: ns2.elha ...
show more
Cloudflare WAF: Request Path: /uploads/../sessions/absholi7ly.session Request Query: Host: ns2.elhacker.net userAgent: Mozilla/5.0 (Kubuntu; Linux i686; rv:128.0) Gecko/20100101 Firefox/128.0 Action: block Source: firewallManaged ASN Description: NICEIT Country: NL Method: PUT Timestamp: 2025-08-31T11:32:17Z ruleId: d104e3246dc14ac7851b4049d9d8c5f2. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ซ๐ฎ
oh.mg
2025-08-31 09:07:43
(1 year ago)
[Sun Aug 31 11:07:43.125044 2025] [security2:error] [pid 1742814:tid 1742829] [client 45.9.148.131:4 ...
show more
[Sun Aug 31 11:07:43.125044 2025] [security2:error] [pid 1742814:tid 1742829] [client 45.9.148.131:49780] [client 45.9.148.131] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 12)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "oh.mg"] [uri "/check.txt"] [unique_id "aLQQ34ded0yDPNSAKqqavQAAAIY"]
[Sun Aug 31 11:07:43.222746 2025] [security2:error] [pid 1742778:tid 1742795] [client 45.9.148.131:49790] [client 45.9.148.131] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anoma
...
show less
Bad Web Bot
Web App Attack
Anonymous
2025-08-31 07:42:53
(1 year ago)
Path traversal vulnerability attempt: /uploads/../sessions/absholi7ly.session
Hacking
Web App Attack
Anonymous
2025-08-31 05:00:04
(1 year ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2025-08-30 22:04:56
(1 year ago)
31/Aug/2025:00:04:54.866483 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
31/Aug/2025:00:04:54.866483 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 45.9.148.131] ModSecurity: Warning. Match of "within %{tx.allowed_methods}" against "REQUEST_METHOD" required. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-911-METHOD-ENFORCEMENT.conf"] [line "44"] [id "911100"] [msg "Method is not allowed by policy"] [data "PUT"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272/220/274"] [tag "PCI/12.1"] [hostname "hwagm.elhacker.net"] [uri "/check.txt"] [unique_id "aLN1htu-9FS8iSuOVaGKRAAD7xY"]
...
show less
Hacking
Web App Attack