๐ฉ๐ช
Ba-Yu
2026-07-28 09:23:06
(8 minutes ago)
WordPress hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-07-28 09:15:10
(16 minutes ago)
[Tue Jul 28 10:15:08.674766 2026] [proxy_fcgi:error] [pid 2296122:tid 139826410022464] [client 135.1 ...
show more
[Tue Jul 28 10:15:08.674766 2026] [proxy_fcgi:error] [pid 2296122:tid 139826410022464] [client 135.119.63.61:27567] AH01071: Got error 'Primary script unknown'
[Tue Jul 28 10:15:08.807783 2026] [proxy_fcgi:error] [pid 2296122:tid 139826552632896] [client 135.119.63.61:27567] AH01071: Got error 'Primary script unknown'
[Tue Jul 28 10:15:08.941655 2026] [proxy_fcgi:error] [pid 2296122:tid 139825478891072] [client 135.119.63.61:27567] AH01071: Got error 'Primary script unknown'
[Tue Jul 28 10:15:09.339167 2026] [proxy_fcgi:error] [pid 2296122:tid 139826393237056] [client 135.119.63.61:27567] AH01071: Got error 'Primary script unknown'
[Tue Jul 28 10:15:09.535994 2026] [proxy_fcgi:error] [pid 2296122:tid 139826418415168] [client 135.119.63.61:27567] AH01071: Got error 'Primary script unknown'
...
show less
Web App Attack
๐ฌ๐ง
Smish
2026-07-28 09:10:14
(21 minutes ago)
HONEYPOT HIT --> Fail2ban time=1785229813 log=2026-07-28T10:10:13+01:00 ip=135.119.63.61 host=in01.b ...
show more
HONEYPOT HIT --> Fail2ban time=1785229813 log=2026-07-28T10:10:13+01:00 ip=135.119.63.61 host=in01.bya.ac method=GET uri="/admin.php" status=404 ua="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" ref="-" rid=4ae84e0600034bcf58028c2e79248a03
show less
Web App Attack
Anonymous
2026-07-28 09:05:22
(26 minutes ago)
135.119.63.61 - - [28/Jul/2026:11:04:57 +0200] "GET /content.php HTTP/1.1" 404 34180
135.119.63.61 - ...
show more
135.119.63.61 - - [28/Jul/2026:11:04:57 +0200] "GET /content.php HTTP/1.1" 404 34180
135.119.63.61 - - [28/Jul/2026:11:04:59 +0200] "GET /cream1.php HTTP/1.1" 404 29076
135.119.63.61 - - [28/Jul/2026:11:05:06 +0200] "GET /ctex1.php HTTP/1.1" 404 29077
135.119.63.61 - - [28/Jul/2026:11:05:07 +0200] "GET /database.php HTTP/1.1" 404 29076
135.119.63.61 - - [28/Jul/2026:11:05:09 +0200] "GET /db.php HTTP/1.1" 404 29077
135.119.63.61 - - [28/Jul/2026:11:05:11 +0200] "GET /deepseek_d.php HTTP/1.1" 404 29077
135.119.63.61 - - [28/Jul/2026:11:05:13 +0200] "GET /default.php HTTP/1.1" 404 29077
135.119.63.61 - - [28/Jul/2026:11:05:14 +0200] "GET /diagnostic.php HTTP/1.1" 404 29076
135.119.63.61 - - [28/Jul/2026:11:05:16 +0200] "GET /doc.php HTTP/1.1" 404 29076
135.119.63.61 - - [28/Jul/2026:11:05:18 +0200] "GET /dropdown.php HTTP/1.1" 404 29077
...
show less
Web Spam
Web App Attack
๐ฉ๐ช
patrisei
2026-07-28 09:00:28
(31 minutes ago)
You are now banned for 10 years by Schiffdorf-West Patrol. Trigger: crowdsecurity/http-probing
Port Scan
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-28 08:57:28
(34 minutes ago)
Attempted access to sensitive endpoint (/wp-content/themes/haha.php) detected. Automated scan or una ...
show more
Attempted access to sensitive endpoint (/wp-content/themes/haha.php) detected. Automated scan or unauthorized probing.
show less
Web App Attack
Anonymous
2026-07-28 08:56:12
(35 minutes ago)
2026/07/28 05:56:10 [error] 1688181#1688181: *7522 limiting requests, excess: 20.340 by zone "genera ...
show more
2026/07/28 05:56:10 [error] 1688181#1688181: *7522 limiting requests, excess: 20.340 by zone "general", client: 135.119.63.61, server: topvitrine.com.br, request: "GET /img/class-wp-http-client.php HTTP/1.1", host: "www.topvitrine.com.br"
2026/07/28 05:56:10 [error] 1688181#1688181: *7522 limiting requests, excess: 20.500 by zone "general", client: 135.119.63.61, server: topvitrine.com.br, request: "GET /inc.php HTTP/1.1", host: "www.topvitrine.com.br"
2026/07/28 05:56:10 [error] 1688181#1688181: *7522 limiting requests, excess: 20.110 by zone "general", client: 135.119.63.61, server: topvitrine.com.br, request: "GET /index.php HTTP/1.1", host: "www.topvitrine.com.br"
2026/07/28 05:56:11 [error] 1688181#1688181: *7522 limiting requests, excess: 20.310 by zone "general", client: 135.119.63.61, server: topvitrine.com.br, request: "GET /index4.php HTTP/1.1", host: "www.topvitrine.com.br"
2026/07/28 05:56:11 [error] 1688181#1688181: *7522 limiting requests, excess: 20.090 by zone "general"
...
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
๐ซ๐ฎ
as211431.net
2026-07-28 08:49:23
(42 minutes ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /k.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
helios.live
2026-07-28 08:46:47
(44 minutes ago)
2026/07/28 08:46:46 [error] 2319766#2319766: *2992448 FastCGI sent in stderr: "Primary script unknow ...
show more
2026/07/28 08:46:46 [error] 2319766#2319766: *2992448 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 135.119.63.61, server: kocerroxy.com, request: "GET /content.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php8.4-fpm-betakocerroxycom.sock:", host: "kocerroxy.com"
135.119.63.61 - - [28/Jul/2026:08:46:46 +0000] "GET /content.php HTTP/1.1" 404 47 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
2026/07/28 08:46:46 [error] 2319766#2319766: *2992448 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 135.119.63.61, server: kocerroxy.com, request: "GET /cream1.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php8.4-fpm-betakocerroxycom.sock:", host: "kocerroxy.com"
135.119.63.61 - - [28/Jul/2026:08:46:46 +0000] "GET /cream1.php HTTP/1.1" 404 47 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537
...
show less
Web App Attack
Anonymous
2026-07-28 08:45:52
(45 minutes ago)
$f2bV_matches
Brute-Force
๐ฉ๐ช
macrob
2026-07-28 08:42:07
(49 minutes ago)
2026/07/28 08:42:02 [error] 657080#657080: *419867678 access forbidden by rule, client: 135.119.63.6 ...
show more
2026/07/28 08:42:02 [error] 657080#657080: *419867678 access forbidden by rule, client: 135.119.63.61, server: binixo.com.ua, request: "GET /install.php HTTP/1.1", host: "binixo.com.ua"
2026/07/28 08:42:06 [error] 657080#657080: *419867678 access forbidden by rule, client: 135.119.63.61, server: binixo.com.ua, request: "GET /modules/mod_simplefileuploadv1.3/elements/ HTTP/1.1", host: "binixo.com.ua"
2026/07/28 08:42:06 [error] 657080#657080: *419867678 access forbidden by rule, client: 135.119.63.61, server: binixo.com.ua, request: "GET /modules/mod_simplefileuploadv1.3/elements/i8hqok6nr.php HTTP/1.1", host: "binixo.com.ua"
...
show less
Web App Attack
๐ฎ๐น
madaello
2026-07-28 08:39:13
(52 minutes ago)
135.119.63.61 - - [28/Jul/2026:10:39:12 +0200] "GET /content.php HTTP/1.1" 404 4228 "-" "Mozilla/5.0 ...
show more
135.119.63.61 - - [28/Jul/2026:10:39:12 +0200] "GET /content.php HTTP/1.1" 404 4228 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
135.119.63.61 - - [28/Jul/2026:10:39:12 +0200] "GET /cream1.php HTTP/1.1" 404 267 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
135.119.63.61 - - [28/Jul/2026:10:39:12 +0200] "GET /css.php HTTP/1.1" 404 267 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
135.119.63.61 - - [28/Jul/2026:10:39:13 +0200] "GET /css/class-wp-http-client.php HTTP/1.1" 404 267 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
135.119.63.61 - - [28/Jul/2026:10:39:13 +0200] "GET /css/index.php HTTP/1.1" 404 267 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0
...
show less
Port Scan
๐ณ๐ฑ
Mangelot Hosting
2026-07-28 08:38:51
(52 minutes ago)
(upload_shell) srv101 PHP Shell Upload 135.119.63.61 (US/United States/-): 1 in the last 3600 secs; ...
show more
(upload_shell) srv101 PHP Shell Upload 135.119.63.61 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ฉ๐ช
pscriptos
2026-07-28 08:34:50
(56 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
๐ฌ๐ท
setupgr
2026-07-28 08:28:54
(1 hour ago)
(mod_security) mod_security (id:1000001) triggered by 135.119.63.61 (US/United States/Iowa/Des Moine ...
show more
(mod_security) mod_security (id:1000001) triggered by 135.119.63.61 (US/United States/Iowa/Des Moines/-/[AS8075 MICROSOFT-CORP-MSN-AS-BLOCK]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Tue Jul 28 11:28:52.025184 2026] [security2:error] [pid 2546:tid 2740] [client 135.119.63.61:9106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/db.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "103"] [id "1000001"] [msg "Bad file blocked: /db.php"] [severity "CRITICAL"] [tag "security"] [hostname "ns2.setworldup365.com"] [uri "/db.php"] [unique_id "amhoRKnpoa7bJCge9uCiZgAAAVY"]
show less
Port Scan