๐ช๐ธ
el-brujo
2026-09-02 00:05:30
(7 hours ago)
02/Sep/2026:02:05:28.894279 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
02/Sep/2026:02:05:28.894279 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 64.112.56.104] ModSecurity: Warning. Matched phrase "etc/passwd" at REQUEST_COOKIES_NAMES:/bin/cat /etc/passwd. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "98"] [id "930120"] [msg "OS File Access Attempt"] [data "Matched Data: etc/passwd found within REQUEST_COOKIES_NAMES:/bin/cat /etc/passwd: /bin/cat /etc/passwd"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "elhacker.info"] [uri "/cgi-bin/status"] [unique_id "apdoSOeAZGsdGHPjicjF-wAH8B8"]
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2026-09-01 22:48:15
(8 hours ago)
02/Sep/2026:00:48:13.559094 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
02/Sep/2026:00:48:13.559094 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 64.112.56.104] ModSecurity: Access denied with code 400 (phase 2). Match of "eq 0" against "MULTIPART_STRICT_ERROR" required. [file "/etc/httpd/conf.d/mod_security.conf"] [line "155"] [id "200002"] [msg "Multipart request body failed strict validation: PE 0, BQ 0, BW 0, DB 0, DA 0, HF 0, LF 1, SM 0, IQ 0, IP 0, IH 0, FL 0"] [hostname "elhacker.info"] [uri "/"] [unique_id "apdWLYHTOa7hExjwuLjtjAAPMD4"]
...
show less
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-01 22:34:20
(8 hours ago)
[02/Sep/2026:01:34:19 +0300] -- 64.112.56.104 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[02/Sep/2026:01:34:19 +0300] -- 64.112.56.104 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.production HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-09-01 02:53:00
(1 day ago)
IPBlock protected site ID [4055-d][s=06].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-08-31 06:00:53
(2 days ago)
Active Response: IP 64.112.56.104 Blocked via Firewall Drop. Threat Score: 3.8/10 (LOW). Confidence: ...
show more
Active Response: IP 64.112.56.104 Blocked via Firewall Drop. Threat Score: 3.8/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-08-31 05:00:53
(2 days ago)
Active Response: IP 64.112.56.104 Blocked via Firewall Drop. Threat Score: 3.8/10 (LOW). Confidence: ...
show more
Active Response: IP 64.112.56.104 Blocked via Firewall Drop. Threat Score: 3.8/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 33%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐บ๐ธ
ipblock.com
2026-08-31 02:22:00
(2 days ago)
IPBlock protected site ID [4055-d][s=06].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
rdpguard.com
2026-08-30 10:48:25
(2 days ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ช๐ธ
librebit
2026-08-30 07:37:33
(2 days ago)
Brute force
Brute-Force
Anonymous
2026-08-30 02:23:24
(3 days ago)
64.112.56.104 - - [30/Aug/2026:10:23:23 +0800] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Mozilla/5.0 ...
show more
64.112.56.104 - - [30/Aug/2026:10:23:23 +0800] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-29 23:45:48
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐บ๐ธ
ipblock.com
2026-08-29 23:37:00
(3 days ago)
IPBlock protected site ID [4730-fr].
Exploit request, vulnerability probe.
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 21:42:42
(3 days ago)
64.112.56.104 - - [29/Aug/2026:18:42:42 -0300] "GET /phpmyadmin/ HTTP/2.0" 404 1807 "-" "Mozilla/5.0 ...
show more
64.112.56.104 - - [29/Aug/2026:18:42:42 -0300] "GET /phpmyadmin/ HTTP/2.0" 404 1807 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
...
show less
Port Scan
๐ซ๐ท
claude CALVET
2026-08-29 20:09:29
(3 days ago)
gee-12 : Block return, carriage return, ... characters=>/index.php?view=article&id=20:formastro& ...
show more
gee-12 : Block return, carriage return, ... characters=>/index.php?view=article&id=20:formastro&catid=8&modjemcal_id=113'&modjemcal_month=08&modjemcal_year=2025(')
show less
Hacking
๐ง๐ท
Halux
2026-08-29 19:41:02
(3 days ago)
64.112.56.104 Probing protected path or service
Web App Attack