๐ฉ๐ช
igerman
2025-10-18 16:08:29
(8 months ago)
caddy probes:
[web] GET /testas.php -> 403
[web] GET /nope.php -> 403
[web] GET /reyna.php -> 403
[w ...
show more
caddy probes:
[web] GET /testas.php -> 403
[web] GET /nope.php -> 403
[web] GET /reyna.php -> 403
[web] GET /ma1.php -> 403
[web] GET /bypltspd.php -> 403
[web] GET /aaa.php -> 403
[wordpress] GET /wp-xx.php -> 403
[wordpress] GET /wp-xm.php -> 403
[web] GET /zeal.php -> 403
[web] GET /h8h9.php -> 403
show less
Web App Attack
๐ซ๐ท
GEDAL
2025-10-06 13:40:53
(8 months ago)
Fail2ban webexploits @ <hostname> : 130.33.66.108 - - [29/Sep/2025:23:52:23 +0200] "GET /wp-login.ph ...
show more
Fail2ban webexploits @ <hostname> : 130.33.66.108 - - [29/Sep/2025:23:52:23 +0200] "GET /wp-login.php HTTP/1.1" 404 146 "-" "-"
show less
Brute-Force
SSH
๐ธ๐ช
SkyDancer
2025-10-05 01:05:47
(8 months ago)
Multiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blo ...
show more
Multiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blocked by SkyDancer Ai(web-X).
show less
Hacking
Brute-Force
Anonymous
2025-10-02 02:58:00
(8 months ago)
hacking
DDoS Attack
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ญ๐บ
NyaljBe
2025-10-02 02:16:00
(8 months ago)
130.33.66.108 - - [30/Sep/2025:05:51:19 +0200] "GET /wp-includes/xraycustom.php HTTP/1.1" 404 153 "- ...
show more
130.33.66.108 - - [30/Sep/2025:05:51:19 +0200] "GET /wp-includes/xraycustom.php HTTP/1.1" 404 153 "-" "-"
130.33.66.108 - - [30/Sep/2025:05:51:19 +0200] "GET /wp-includes/omega3.php HTTP/1.1" 404 153 "-" "-"
130.33.66.108 - - [30/Sep/2025:05:51:19 +0200] "GET /modules/zeta3.inc HTTP/1.1" 404 153 "-" "-"
130.33.66.108 - - [30/Sep/2025:05:51:19 +0200] "GET /wp-content/themes/thetav2.inc HTTP/1.1" 404 153 "-" "-"
130.33.66.108 - - [30/Sep/2025:05:51:18 +0200] "GET /assets/iotav1.php HTTP/1.1" 404 153 "-" "-"
130.33.66.108 - - [30/Sep/2025:05:51:18 +0200] "GET /assets/iotav3.inc HTTP/1.1" 404 153 "-" "-"
130.33.66.108 - - [30/Sep/2025:05:51:18 +0200] "GET /custom-scripts/lambda4.inc HTTP/1.1" 404 153 "-" "-"
130.33.66.108 - - [30/Sep/2025:05:51:18 +0200] "GET /assets/iota3.php HTTP/1.1" 404 153 "-" "-"
130.33.66.108 - - [30/Sep/2025:05:51:17 +0200] "GET /wp-includes/phiv2.module HTTP/1.1" 404 153 "-" "-"
130.33.66.108 - - [30/Sep/2025:05:51:17 +0200] "GET /assets/zeta2.module HTTP/1.1" 404
show less
Web App Attack
๐ญ๐บ
NyaljBe
2025-10-02 01:56:00
(8 months ago)
130.33.66.108 - - [30/Sep/2025:03:07:23 +0200] "GET /makeasmtp.php?p= HTTP/1.1" 404 153 "-" "-"
130 ...
show more
130.33.66.108 - - [30/Sep/2025:03:07:23 +0200] "GET /makeasmtp.php?p= HTTP/1.1" 404 153 "-" "-"
130.33.66.108 - - [30/Sep/2025:03:07:22 +0200] "GET /wp-includes/pomo/pomo.php HTTP/1.1" 404 153 "-" "-"
130.33.66.108 - - [30/Sep/2025:03:07:21 +0200] "GET /file.php HTTP/1.1" 404 153 "-" "-"
130.33.66.108 - - [30/Sep/2025:03:07:21 +0200] "GET /wp-content/content.php HTTP/1.1" 404 153 "-" "-"
130.33.66.108 - - [30/Sep/2025:03:07:20 +0200] "GET /xmlrpc.php HTTP/1.1" 405 53 "-" "-"
130.33.66.108 - - [30/Sep/2025:03:07:20 +0200] "GET /wp-mail.php HTTP/1.1" 403 2634 "-" "-"
130.33.66.108 - - [30/Sep/2025:03:07:18 +0200] "GET /.well-known/content.php HTTP/1.1" 404 153 "-" "-"
130.33.66.108 - - [30/Sep/2025:03:07:17 +0200] "GET /wp-includes/css/wp-conflg.php HTTP/1.1" 404 153 "-" "-"
130.33.66.108 - - [30/Sep/2025:03:07:16 +0200] "GET /wp-admin/function.php HTTP/1.1" 404 153 "-" "-"
130.33.66.108 - - [30/Sep/2025:03:07:16 +0200] "GET /chosen.php?p= HTTP/1.1" 404 153 "-" "-"
show less
Web App Attack
๐ฉ๐ช
NetShield-DE
2025-10-01 23:07:44
(8 months ago)
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb, modsecurity.
Events: 8. First ...
show more
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb, modsecurity.
Events: 8. First: 2025-10-02T01:07:02+0200. Last: 2025-10-02T01:07:02+0200.
Samples:
- 2025-09-29 22:48:48,673 fail2ban.actions [47044]: NOTICE [modsecurity] Ban 130.33.66.108
- 2025-09-29 22:48:49,516 fail2ban.actions [47044]: NOTICE [abuseipdb] Ban 130.33.66.108
- 2025-09-30 18:36:50,727 fail2ban.actions [353099]: NOTICE [modsecurity] Restore Ban 130.33.66.108
- 2025-09-30 18:42:17,184 fail2ban.actions [353099]: NOTICE [abuseipdb] Restore Ban 130.33.66.108
- 2025-09-30 20:11:49,602 fail2ban.actions [412582]: NOTICE [modsecurity] Restore Ban 130.33.66.108
- 2025-09-30 20:15:18,965 fail2ban.actions [412582]: NOTICE [abuseipdb] Restore Ban 130.33.66.108
- 2025-09-30 22:38:29,712 fail2ban.actions [412582]: NOTICE [modsecurity] Restore Ban 130.33.66.108
- 2025-09-30 22:42:26,706 fail2ban.actions [412582]: NOTICE [abuseipdb] Restore Ban 130.33.66.108
show less
Web App Attack
๐น๐ท
rtbh.com.tr
2025-10-01 20:09:07
(8 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ฉ๐ช
NetShield-DE
2025-10-01 19:07:08
(8 months ago)
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb, modsecurity.
Events: 8. First ...
show more
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb, modsecurity.
Events: 8. First: 2025-10-01T21:07:01+0200. Last: 2025-10-01T21:07:02+0200.
Samples:
- 2025-09-29 22:48:48,673 fail2ban.actions [47044]: NOTICE [modsecurity] Ban 130.33.66.108
- 2025-09-29 22:48:49,516 fail2ban.actions [47044]: NOTICE [abuseipdb] Ban 130.33.66.108
- 2025-09-30 18:36:50,727 fail2ban.actions [353099]: NOTICE [modsecurity] Restore Ban 130.33.66.108
- 2025-09-30 18:42:17,184 fail2ban.actions [353099]: NOTICE [abuseipdb] Restore Ban 130.33.66.108
- 2025-09-30 20:11:49,602 fail2ban.actions [412582]: NOTICE [modsecurity] Restore Ban 130.33.66.108
- 2025-09-30 20:15:18,965 fail2ban.actions [412582]: NOTICE [abuseipdb] Restore Ban 130.33.66.108
- 2025-09-30 22:38:29,712 fail2ban.actions [412582]: NOTICE [modsecurity] Restore Ban 130.33.66.108
- 2025-09-30 22:42:26,706 fail2ban.actions [412582]: NOTICE [abuseipdb] Restore Ban 130.33.66.108
show less
Web App Attack
๐ฉ๐ช
NetShield-DE
2025-10-01 14:07:08
(8 months ago)
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb, modsecurity.
Events: 8. First ...
show more
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb, modsecurity.
Events: 8. First: 2025-10-01T16:07:01+0200. Last: 2025-10-01T16:07:02+0200.
Samples:
- 2025-09-29 22:48:48,673 fail2ban.actions [47044]: NOTICE [modsecurity] Ban 130.33.66.108
- 2025-09-29 22:48:49,516 fail2ban.actions [47044]: NOTICE [abuseipdb] Ban 130.33.66.108
- 2025-09-30 18:36:50,727 fail2ban.actions [353099]: NOTICE [modsecurity] Restore Ban 130.33.66.108
- 2025-09-30 18:42:17,184 fail2ban.actions [353099]: NOTICE [abuseipdb] Restore Ban 130.33.66.108
- 2025-09-30 20:11:49,602 fail2ban.actions [412582]: NOTICE [modsecurity] Restore Ban 130.33.66.108
- 2025-09-30 20:15:18,965 fail2ban.actions [412582]: NOTICE [abuseipdb] Restore Ban 130.33.66.108
- 2025-09-30 22:38:29,712 fail2ban.actions [412582]: NOTICE [modsecurity] Restore Ban 130.33.66.108
- 2025-09-30 22:42:26,706 fail2ban.actions [412582]: NOTICE [abuseipdb] Restore Ban 130.33.66.108
show less
Web App Attack
๐ซ๐ท
geot
2025-10-01 12:51:07
(8 months ago)
28 requests, including :
GET /file<<removed>>.php HTTP/1.1
GET /<<removed>>.php HTTP/1.1
GET /wp-<< ...
show more
28 requests, including :
GET /file<<removed>>.php HTTP/1.1
GET /<<removed>>.php HTTP/1.1
GET /wp-<<removed>>.php HTTP/1.1
GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1
show less
Web App Attack
๐ฉ๐ช
NetShield-DE
2025-10-01 09:07:09
(8 months ago)
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb, modsecurity.
Events: 8. First ...
show more
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb, modsecurity.
Events: 8. First: 2025-10-01T11:07:02+0200. Last: 2025-10-01T11:07:02+0200.
Samples:
- 2025-09-29 22:48:48,673 fail2ban.actions [47044]: NOTICE [modsecurity] Ban 130.33.66.108
- 2025-09-29 22:48:49,516 fail2ban.actions [47044]: NOTICE [abuseipdb] Ban 130.33.66.108
- 2025-09-30 18:36:50,727 fail2ban.actions [353099]: NOTICE [modsecurity] Restore Ban 130.33.66.108
- 2025-09-30 18:42:17,184 fail2ban.actions [353099]: NOTICE [abuseipdb] Restore Ban 130.33.66.108
- 2025-09-30 20:11:49,602 fail2ban.actions [412582]: NOTICE [modsecurity] Restore Ban 130.33.66.108
- 2025-09-30 20:15:18,965 fail2ban.actions [412582]: NOTICE [abuseipdb] Restore Ban 130.33.66.108
- 2025-09-30 22:38:29,712 fail2ban.actions [412582]: NOTICE [modsecurity] Restore Ban 130.33.66.108
- 2025-09-30 22:42:26,706 fail2ban.actions [412582]: NOTICE [abuseipdb] Restore Ban 130.33.66.108
show less
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2025-10-01 05:12:56
(8 months ago)
248 attacks on PHP URLs:
GET /saiga.php HTTP/1.1
Web App Attack
๐ฉ๐ช
NetShield-DE
2025-10-01 04:07:08
(8 months ago)
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb, modsecurity.
Events: 8. First ...
show more
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb, modsecurity.
Events: 8. First: 2025-10-01T06:07:02+0200. Last: 2025-10-01T06:07:02+0200.
Samples:
- 2025-09-29 22:48:48,673 fail2ban.actions [47044]: NOTICE [modsecurity] Ban 130.33.66.108
- 2025-09-29 22:48:49,516 fail2ban.actions [47044]: NOTICE [abuseipdb] Ban 130.33.66.108
- 2025-09-30 18:36:50,727 fail2ban.actions [353099]: NOTICE [modsecurity] Restore Ban 130.33.66.108
- 2025-09-30 18:42:17,184 fail2ban.actions [353099]: NOTICE [abuseipdb] Restore Ban 130.33.66.108
- 2025-09-30 20:11:49,602 fail2ban.actions [412582]: NOTICE [modsecurity] Restore Ban 130.33.66.108
- 2025-09-30 20:15:18,965 fail2ban.actions [412582]: NOTICE [abuseipdb] Restore Ban 130.33.66.108
- 2025-09-30 22:38:29,712 fail2ban.actions [412582]: NOTICE [modsecurity] Restore Ban 130.33.66.108
- 2025-09-30 22:42:26,706 fail2ban.actions [412582]: NOTICE [abuseipdb] Restore Ban 130.33.66.108
show less
Web App Attack
๐ฌ๐ง
SecondEdge
2025-10-01 02:57:31
(8 months ago)
A web attack was detected from 130.33.66.108 (United States) against lifeofstu.co.uk (Wordpress,XMLR ...
show more
A web attack was detected from 130.33.66.108 (United States) against lifeofstu.co.uk (Wordpress,XMLRPC) over 9s.
show less
Web App Attack