mawan
1 hour ago
Suspected of having performed illicit activity on AMS server.
Web App Attack
MarkGGN
11 hours ago
Webexploits. 148.72.14.61 - - [26/Jun/2022:02:14:45 +0200] "GET /wp-admin/user/wp-links.php HTTP/2.0 ... show more Webexploits. 148.72.14.61 - - [26/Jun/2022:02:14:45 +0200] "GET /wp-admin/user/wp-links.php HTTP/2.0" 404 548 "http://*/wp-admin/user/wp-links.php" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.99 Safari/533.4"
148.72.14.61 - - [26/Jun/2022:02:14:46 +0200] "GET /wp-admin/user/wp-links.php HTTP/2.0" 404 548 "http://*/wp-admin/user/wp-links.php" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.99 Safari/533.4" show less
Brute-Force
Bad Web Bot
Web App Attack
Createline
14 hours ago
148.72.14.61 - - [25/Jun/2022:23:11:49 +0200] "GET /eval.php HTTP/1.1" 301 243 "http://simplesite.co ... show more 148.72.14.61 - - [25/Jun/2022:23:11:49 +0200] "GET /eval.php HTTP/1.1" 301 243 "http://simplesite.com" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.99 Safari/533.4" 251 509 show less
Web App Attack
Anonymous
17 hours ago
Malicious activity detected
Hacking
Brute-Force
expandmade.com
17 hours ago
[nut] - trolling for installation vulnerabilities [25/Jun/2022:18:23:52 "GET /x.php"]
Web App Attack
Maykson
20 hours ago
148.72.14.61 - - [25/Jun/2022:12:10:55 -0300] "GET /x.php HTTP/1.1" 404 35422 "http://simplesite.com ... show more 148.72.14.61 - - [25/Jun/2022:12:10:55 -0300] "GET /x.php HTTP/1.1" 404 35422 "http://simplesite.com" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.99 Safari/533.4"
... show less
Exploited Host
Web App Attack
expandmade.com
22 hours ago
[exp] - trolling for installation vulnerabilities [25/Jun/2022:13:03:20 "GET /wp-content/themes/twen ... show more [exp] - trolling for installation vulnerabilities [25/Jun/2022:13:03:20 "GET /wp-content/themes/twentytwenty/content.php"] show less
Web App Attack
Anonymous
25 Jun 2022
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
Createline
24 Jun 2022
148.72.14.61 - - [24/Jun/2022:16:13:22 +0200] "GET /wp-config-sample.php HTTP/1.1" 301 250 "http://s ... show more 148.72.14.61 - - [24/Jun/2022:16:13:22 +0200] "GET /wp-config-sample.php HTTP/1.1" 301 250 "http://simplesite.com" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.99 Safari/533.4" 258 523 show less
Hacking
Web App Attack
Anonymous
24 Jun 2022
148.72.14.61 - - [12/Jun/2022:22:50:47 +0200] "GET /wp-content/plugins/press/wp-class.php HTTP/1.1" ... show more 148.72.14.61 - - [12/Jun/2022:22:50:47 +0200] "GET /wp-content/plugins/press/wp-class.php HTTP/1.1" 404 5828 "http://elomix.de/wp-content/plugins/press/wp-class.php" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.99 Safari/533.4"
148.72.14.61 - - [12/Jun/2022:22:50:50 +0200] "GET /wp-content/plugins/press/wp-class.php HTTP/1.1" 404 5828 "http://elomix.de/wp-content/plugins/press/wp-class.php" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.99 Safari/533.4"
148.72.14.61 - - [22/Jun/2022:02:32:51 +0200] "GET /wp-includes/blocks/cover/index.php HTTP/1.1" 404 4785 "http://elomix.de/wp-includes/blocks/cover/index.php" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.99 Safari/533.4"
148.72.14.61 - - [24/Jun/2022:15:04:24 +0200] "GET /wp-content/plugins/sid/wp-info.php HTTP/1.1" 404 5828 "http://elomix.de/wp-content/plugins/sid/wp-i
... show less
Hacking
Bad Web Bot
Maykson
24 Jun 2022
148.72.14.61 - - [24/Jun/2022:08:26:34 -0300] "GET /ups.php.suspected HTTP/1.1" 404 79721 "http://si ... show more 148.72.14.61 - - [24/Jun/2022:08:26:34 -0300] "GET /ups.php.suspected HTTP/1.1" 404 79721 "http://simplesite.com" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.99 Safari/533.4"
... show less
Exploited Host
Web App Attack
Anonymous
24 Jun 2022
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
expandmade.com
23 Jun 2022
[exp] - trolling for resource vulnerabilities [23/Jun/2022:14:33:18 "GET /wp-content/plugins/press/w ... show more [exp] - trolling for resource vulnerabilities [23/Jun/2022:14:33:18 "GET /wp-content/plugins/press/wp-class.php"] show less
Web App Attack
teskedsgumman.se
23 Jun 2022
Looking for: /wp-admin/css/colors/blue/index.php +/wp-admin/css/colors/ in wordpress:(
Port Scan
taivas.nl
23 Jun 2022
Many_bad_calls
Web App Attack