🇪🇸
alferez
2026-07-28 02:36:52
(1 month ago)
Searching hacked php files
Hacking
Exploited Host
Web App Attack
🇳🇱
BlueWire Hosting
2026-07-20 09:13:47
(1 month ago)
Bad bot ignoring robot.txt
Bad Web Bot
🇺🇸
nationaleventpros.com
2026-07-20 09:07:16
(1 month ago)
vulnerability scan
Web App Attack
🇫🇮
6kilowatti
2026-07-20 08:42:45
(1 month ago)
2026/07/20 11:42:44 [error] 4060105#4060105: *35458 FastCGI sent in stderr: "Primary script unknown" ...
show more
2026/07/20 11:42:44 [error] 4060105#4060105: *35458 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 107.149.152.77, server: oh6ah.fi, request: "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1", upstream: "fastcgi://unix:/var/run/oh6ah.fi.sock:", host: "oh6ah.fi", referrer: "www.google.com"
2026/07/20 11:42:44 [error] 4060105#4060105: *35464 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 107.149.152.77, server: oh6ah.fi, request: "GET /wp-content/plugins/fix/up.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/oh6ah.fi.sock:", host: "oh6ah.fi"
...
show less
Web App Attack
🇩🇪
paissangroup
2026-07-20 07:00:47
(1 month ago)
Multiple WAF Violations
Web App Attack
🇬🇷
setupgr
2026-07-20 06:09:11
(1 month ago)
(mod_security) mod_security (id:1000001) triggered by 107.149.152.77 (BR/Brazil/São Paulo/São Paul ...
show more
(mod_security) mod_security (id:1000001) triggered by 107.149.152.77 (BR/Brazil/São Paulo/São Paulo/-/[AS212238 CDNEXT]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Mon Jul 20 09:09:09.127108 2026] [security2:error] [pid 1733941:tid 1734109] [client 107.149.152.77:48933] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/db.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "103"] [id "1000001"] [msg "Bad file blocked: /wp-content/themes/seotheme/db.php"] [severity "CRITICAL"] [tag "security"] [hostname "grafeioteletonkaragiannis.gr"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al27hcghew1RiwP0_anYmwAAAE4"], referer: www.google.com
show less
Port Scan
🇦🇺
paulshipley.com.au
2026-07-20 04:36:28
(1 month ago)
[Mon Jul 20 14:36:28.061532 2026] [security2:error] [pid 62206] [client 107.149.152.77:32483] [clien ...
show more
[Mon Jul 20 14:36:28.061532 2026] [security2:error] [pid 62206] [client 107.149.152.77:32483] [client 107.149.152.77] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "angleseaarthouse.com.au"] [uri "/wp-plain.php"] [unique_id "al2lzMQSWIb9Fh0CM3N_uwAAAAE"], referer: www.google.com
...
show less
Web App Attack
🇲🇽
octageeks.com
2026-07-20 04:18:10
(1 month ago)
Wordpress malicious attack:[octablocked]
Web App Attack
🇬🇷
setupgr
2026-07-20 03:01:38
(1 month ago)
(mod_security) mod_security (id:1000001) triggered by 107.149.152.77 (BR/Brazil/São Paulo/São Paul ...
show more
(mod_security) mod_security (id:1000001) triggered by 107.149.152.77 (BR/Brazil/São Paulo/São Paulo/-/[AS212238 CDNEXT]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Mon Jul 20 06:01:35.262309 2026] [security2:error] [pid 1734577:tid 1734721] [client 107.149.152.77:32411] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/db.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "103"] [id "1000001"] [msg "Bad file blocked: /wp-content/themes/seotheme/db.php"] [severity "CRITICAL"] [tag "security"] [hostname "cpanagiotou.gr"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al2Pj-0u9P8c-kNnDKubpwAABAc"], referer: www.google.com
show less
Port Scan
🇬🇧
Mendip_Defender
2026-07-20 02:02:53
(1 month ago)
107.149.152.77 - - [20/Jul/2026:03:02:52 +0100] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 16 ...
show more
107.149.152.77 - - [20/Jul/2026:03:02:52 +0100] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36"
107.149.152.77 - - [20/Jul/2026:03:02:52 +0100] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 301 162 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
107.149.152.77 - - [20/Jul/2026:03:02:52 +0100] "POST /wp-plain.php HTTP/1.1" 301 162 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Hacking
Web App Attack
🇪🇸
masterguru
2026-07-20 02:01:29
(1 month ago)
BAD BOT - Detected and Blocked.. Matched phrase "mozlila" at REQUEST_HEADERS:User-Agent. (1100000-12 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "mozlila" at REQUEST_HEADERS:User-Agent. (1100000-122)
show less
Bad Web Bot
🇫🇷
Tilellit.PRO
2026-07-20 01:01:25
(1 month ago)
Malicious web traffic detected by CrowdSec
Hacking
🇩🇪
Lino Project
2026-07-20 00:22:36
(1 month ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-bad-user-agent
Hacking
🇫🇷
dynamix
2026-07-19 22:39:36
(1 month ago)
Multiple WAF Violations
Web App Attack
🇩🇪
LRob
2026-07-19 20:00:27
(1 month ago)
CrowdSec: crowdsecurity/http-bad-user-agent | req: / | 2 distinct paths | UA: Mozlila/5.0 (Linux; An ...
show more
CrowdSec: crowdsecurity/http-bad-user-agent | req: / | 2 distinct paths | UA: Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.
show less
Bad Web Bot