๐ซ๐ฎ
tjs
2026-10-08 22:35:00
(1 day ago)
web attack
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-08 15:39:24
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-10-08 13:01:23
(1 day ago)
08/Oct/2026:15:01:23.145827 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
08/Oct/2026:15:01:23.145827 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 136.92.15.181] ModSecurity: Warning. Matched phrase ".zshrc" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .zshrc found within REQUEST_FILENAME: /.zshrc"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "ns2.elhacker.net"] [uri "/.zshrc"] [unique_id "aseUI6S9zGCCDe-yLFhcKAAUqwo"]
...
show less
Hacking
Web App Attack
๐บ๐ธ
EvilTurkey
2026-10-08 12:25:43
(1 day ago)
Web app attack against financial institution website.
Web App Attack
Hacking
Anonymous
2026-10-08 10:00:28
(1 day ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ช๐ธ
el-brujo
2026-10-08 09:52:25
(1 day ago)
Cloudflare WAF: Request Path: /cgi-bin/php-cgi Request Query: ?-d+allow_url_include%3don+-d+auto_pre ...
show more
Cloudflare WAF: Request Path: /cgi-bin/php-cgi Request Query: ?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input Host: live.elhacker.net userAgent: Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/) Action: block Source: firewallCustom ASN Description: Google LLC Country: DE Method: POST Timestamp: 2026-10-08T09:52:25Z ruleId: 6b2d48d0415e4adb9f099d85f54d1de6. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
Anonymous
2026-10-08 08:27:48
(1 day ago)
Suspicious URL access.
Hacking
๐บ๐ธ
MakoWish
2026-10-08 07:16:38
(1 day ago)
Fuzzing for misconfigured web servers.
Hacking
Web App Attack
๐ฉ๐ช
raph
2026-10-08 06:17:03
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-10-08 05:57:13
(1 day ago)
08/Oct/2026:07:57:12.811585 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
08/Oct/2026:07:57:12.811585 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 136.92.15.181] ModSecurity: Warning. Pattern match "(?i)(?:\\\\\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "48"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /..%252f found within REQUEST_URI_RAW: /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw??"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [hostname "grafana.elhacker.net"] [uri "/@fs/..%2f..%2f..%2f..%2f..%
...
show less
Hacking
Web App Attack
Anonymous
2026-10-08 05:16:17
(1 day ago)
136.92.15.181 - - [08/Oct/2026:07:16:16 +0200] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1 ...
show more
136.92.15.181 - - [08/Oct/2026:07:16:16 +0200] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 7100 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
136.92.15.181 - - [08/Oct/2026:07:16:16 +0200] "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 7092 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-08 04:17:14
(1 day ago)
[08/Oct/2026:07:17:13 +0300] -- 136.92.15.181 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[08/Oct/2026:07:17:13 +0300] -- 136.92.15.181 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /assets/manifest.json HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
mgarofano80
2026-10-08 02:33:03
(1 day ago)
Brute-Force
Web App Attack
๐ฉ๐ช
Phenix Info
2026-10-07 23:36:05
(2 days ago)
SmallGuard.fr/Prestashop Forbidden Ext.
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-10-07 22:15:53
(2 days ago)
Brute-Force
Web App Attack