Anonymous
2026-07-26 11:46:32
(4 hours ago)
Attack detected: 144.172.91.181 [2026-07-26]
Categories: 21
--- wp2shell/batch exploit (3 hits) ---
...
show more
Attack detected: 144.172.91.181 [2026-07-26]
Categories: 21
--- wp2shell/batch exploit (3 hits) ---
144.172.91.181 - - [26/Jul/2026:11:12:11 +0000] "POST /wp-json/batch/v1 HTTP/1.1" 207 4741 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36"
144.172.91.181 - - [26/Jul/2026:11:12:13 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 4741 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36"
144.172.91.181 - - [26/Jul/2026:11:12:14 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 5204 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฉ๐ช
Lino Project
2026-07-26 11:10:33
(5 hours ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-cve-probing
Hacking
๐ฉ๐ช
iNetWorker
2026-07-26 10:44:04
(5 hours ago)
trolling for resource vulnerabilities
Web App Attack
๐ญ๐บ
DumaNet
2026-07-26 10:17:00
(5 hours ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Jul 26. 11:23:46
Source IP: 144.17 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Jul 26. 11:23:46
Source IP: 144.172.91.181
Portion of the log(s):
144.172.91.181 - [26/Jul/2026:11:23:46 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 500 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-07-26 09:50:49
(6 hours ago)
144.172.91.181 - - [26/Jul/2026:12:50:48 +0300] "POST /wp-json/batch/v1 HTTP/1.1" 404 4704 "-" "Mozi ...
show more
144.172.91.181 - - [26/Jul/2026:12:50:48 +0300] "POST /wp-json/batch/v1 HTTP/1.1" 404 4704 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฉ๐ช
bescared
2026-07-26 09:37:00
(6 hours ago)
WAF (2) - Malicious activity detected: Form spam.
Web Spam
๐ฆ๐บ
paulshipley.com.au
2026-07-26 08:26:49
(7 hours ago)
[Sun Jul 26 18:26:49.095374 2026] [security2:error] [pid 900142] [client 144.172.91.181:54626] [clie ...
show more
[Sun Jul 26 18:26:49.095374 2026] [security2:error] [pid 900142] [client 144.172.91.181:54626] [client 144.172.91.181] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "valueaddedpromotions.com.au"] [uri "/"] [unique_id "amXEybzxrtdJhwDBirhkxAAAAAA"]
...
show less
Web App Attack
Anonymous
2026-07-26 06:54:21
(9 hours ago)
PSCSERV WPSCAN 144.172.91.181
Bad Web Bot
Web App Attack
๐ธ๐ฌ
anotherwatcher
2026-07-26 06:47:55
(9 hours ago)
bad bot
Bad Web Bot
๐ญ๐บ
bcsaba
2026-07-26 06:41:08
(9 hours ago)
Going for WP CVE-2026-63030
144.172.91.181 - - [26/Jul/2026:08:41:06 +0200] "POST /?rest_route=/batc ...
show more
Going for WP CVE-2026-63030
144.172.91.181 - - [26/Jul/2026:08:41:06 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36"
show less
Web App Attack
Anonymous
2026-07-26 06:21:27
(9 hours ago)
2026-07-26T08:21:26.839053+02:00 firewall[2561401]: CRITICAL: #3602896: WP vulnerability from 144.1 ...
show more
2026-07-26T08:21:26.839053+02:00 firewall[2561401]: CRITICAL: #3602896: WP vulnerability from 144.172.91.181 on www
show less
Web App Attack
๐ฉ๐ช
findlab
2026-07-26 06:20:03
(9 hours ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-26 06:04:22
(10 hours ago)
IM360 WAF: WordPress wp2shell REST batch endpoint before 7.0.2 or 6.9.5 (CVE-2026-63030) MV:12
Hacking
Anonymous
2026-07-26 05:27:48
(10 hours ago)
WordPress SQL Injection (CVE-2026-60137).
SQL Injection
๐บ๐ฆ
URAN Publishing Service
2026-07-26 05:08:31
(11 hours ago)
144.172.91.181 - - [26/Jul/2026:08:08:29 +0300] "POST /wp-json/batch/v1 HTTP/1.1" 404 4697 "-" "Mozi ...
show more
144.172.91.181 - - [26/Jul/2026:08:08:29 +0300] "POST /wp-json/batch/v1 HTTP/1.1" 404 4697 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36"
...
show less
Web App Attack