๐ซ๐ท
Sklurk
2026-07-09 00:52:48
(1 month ago)
Web App Attack
Web App Attack
๐ธ๐ฌ
anotherwatcher
2026-06-27 14:45:57
(1 month ago)
bad bot
Bad Web Bot
๐ช๐ธ
el-brujo
2026-02-19 17:08:25
(6 months ago)
Cloudflare WAF: Request Path: / Request Query: Host: elhacker.net userAgent: Mozilla/5.0 (X11; Linu ...
show more
Cloudflare WAF: Request Path: / Request Query: Host: elhacker.net userAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36 Action: block Source: firewallManaged ASN Description: DREI-K-TECH-GMBH Country: DE Method: GET Timestamp: 2026-02-19T17:08:25Z ruleId: 8e361ee4328f4a3caf6caf3e664ed6fe. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ช๐ธ
el-brujo
2026-02-19 17:08:15
(6 months ago)
[Thu Feb 19 18:08:14.624552 2026] [proxy_fcgi:error] [pid 2927953:tid 2928830] [remote 65.111.24.81: ...
show more
[Thu Feb 19 18:08:14.624552 2026] [proxy_fcgi:error] [pid 2927953:tid 2928830] [remote 65.111.24.81:0] AH01071: Got error 'Primary script unknown\n', referer: https://www.google.com
[Thu Feb 19 18:08:15.595451 2026] [proxy_fcgi:error] [pid 2927956:tid 2928870] [remote 65.111.24.81:0] AH01071: Got error 'Primary script unknown\n', referer: https://www.google.com
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2026-01-28 17:41:40
(6 months ago)
WP Login Scan Activities
Web App Attack
Anonymous
2026-01-26 19:31:27
(6 months ago)
wordpress-trap
Web App Attack
๐ช๐ธ
10dencehispahard SL
2026-01-26 12:13:40
(6 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:01:58
(7 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-12-27 15:53:58
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.24.81 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.24.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 10:53:55.052652 2025] [security2:error] [pid 22954:tid 22954] [client 65.111.24.81:13331] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brittaniaenterprises.com"] [uri "/.svn/wc.db"] [unique_id "aVABE-hVTsblmyt-V9FjpgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-10 14:52:11
(8 months ago)
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized ac ...
show more
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized access"
show less
DDoS Attack
SQL Injection
Exploited Host
๐ฉ๐ช
Vegascosmetics
2025-11-25 22:50:22
(8 months ago)
Kingcopy(AI-IDS):IP does Multiple AWS Environment Abuse
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 07:34:44
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.24.81 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.24.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 02:34:34.835686 2025] [security2:error] [pid 22745:tid 22745] [client 65.111.24.81:31411] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nbreen.nancybcatering.com"] [uri "/.env"] [unique_id "aSVcCr6p1jWeCIPYSZem0QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 07:18:22
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.24.81 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.24.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 02:18:13.809946 2025] [security2:error] [pid 11124:tid 11124] [client 65.111.24.81:45311] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.portalvasco.com"] [uri "/.env"] [unique_id "aSVYNTlpFapDnOzCzDlHtwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 06:36:06
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.24.81 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.24.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:35:47.254696 2025] [security2:error] [pid 7844:tid 7844] [client 65.111.24.81:19291] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.stage15.com"] [uri "/.env"] [unique_id "aSVOQ0is5JtIkiVUf3EvsgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-13 18:39:22
(9 months ago)
This IP was involved in an brute force and password spray attack on 2025/11/13 12:37:20
Port Scan
Brute-Force
Exploited Host
Web App Attack