๐ฎ๐ฉ
sockominfo
2026-07-21 23:00:53
(1 day ago)
Suspicious user agent detected python-requests/2.34.2. Threat Score: 3.7/10 (LOW). Confidence: 30%. ...
show more
Suspicious user agent detected python-requests/2.34.2. Threat Score: 3.7/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-07-21 22:00:53
(1 day ago)
Suspicious user agent detected python-requests/2.34.2. Threat Score: 3.8/10 (LOW). Confidence: 30%. ...
show more
Suspicious user agent detected python-requests/2.34.2. Threat Score: 3.8/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-07-21 21:00:09
(1 day ago)
Suspicious user agent detected python-requests/2.34.2. Threat Score: 0/10 (INFORMATIONAL). Reported ...
show more
Suspicious user agent detected python-requests/2.34.2. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-07-20 22:15:43
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
Baking333
2026-07-20 12:45:09
(3 days ago)
[redacted] 158.173.210.80 - - [20/Jul/2026:13:45:07 +0100] "GET /wp-content/plugins/pwnd/[redacted] ...
show more
[redacted] 158.173.210.80 - - [20/Jul/2026:13:45:07 +0100] "GET /wp-content/plugins/pwnd/[redacted] HTTP/1.1" 302 6742 0/69162 "http://[redacted]/wp-content/plugins/pwnd/[redacted]" "Go-http-client/1.1" [redacted] 158.173.210.80 - - [20/Jul/2026:13:45:07 +0100] "GET / HTTP/1.1" 200 10667 0/125075 "https://[redacted]/wp-content/plugins/pwnd/[redacted]" "Go-http-client/1.1"
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-16 10:14:22
(1 week ago)
Excessive 404/403 errors
Brute-Force
๐ฌ๐ท
setupgr
2026-07-16 05:22:44
(1 week ago)
(mod_security) mod_security (id:1000001) triggered by 158.173.210.80 (ES/Spain/Valencia/Valencia/-/[ ...
show more
(mod_security) mod_security (id:1000001) triggered by 158.173.210.80 (ES/Spain/Valencia/Valencia/-/[AS58065 PACKETEXCHANGE]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Jul 16 08:22:43.527477 2026] [security2:error] [pid 323747:tid 323864] [client 158.173.210.80:52637] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/db.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "103"] [id "1000001"] [msg "Bad file blocked: /wp-content/themes/pridmag/db.php"] [severity "CRITICAL"] [tag "security"] [hostname "asteriassantorini.com"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "alhqo4-4CH8uYeLocipMDwAABQU"]
show less
Port Scan
๐ง๐ท
Halux
2026-07-16 03:38:59
(1 week ago)
158.173.210.80 Probing protected path or service
Web App Attack
๐บ๐ธ
wteiken
2026-07-15 14:17:04
(1 week ago)
www.teiken.org:443 158.173.210.80:30381 - - [15/Jul/2026:10:16:59 -0400] "GET /wp-content/plugins/se ...
show more
www.teiken.org:443 158.173.210.80:30381 - - [15/Jul/2026:10:16:59 -0400] "GET /wp-content/plugins/semrush/x.php HTTP/1.1" 404 4282 "http://teiken.org/wp-content/plugins/semrush/x.php" "Go-http-client/1.1"
www.teiken.org:443 158.173.210.80:30381 - - [15/Jul/2026:10:16:59 -0400] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 404 571 "http://teiken.org/wp-content/plugins/fix/up.php" "Go-http-client/1.1"
www.teiken.org:443 158.173.210.80:30381 - - [15/Jul/2026:10:17:00 -0400] "GET /wp-content/plugins/wpcall-button/button-image.php HTTP/1.1" 404 571 "http://teiken.org/wp-content/plugins/wpcall-button/button-image.php" "Go-http-client/1.1"
www.teiken.org:443 158.173.210.80:30381 - - [15/Jul/2026:10:17:01 -0400] "GET /wp-content/plugins/index.php HTTP/1.1" 404 571 "http://teiken.org/wp-content/plugins/index.php" "Go-http-client/1.1"
www.teiken.org:443 158.173.210.80:30381 - - [15/Jul/2026:10:17:01 -0400] "GET /wp-content/plugins/advanced-llms-txt-generator/assets/css/css_json.php HTTP/1.1" 404
...
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-07-15 14:10:34
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-07-13 22:38:32
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-wordpress-scan
Web App Attack
Hacking
๐ฟ๐ฆ
conure
2026-07-13 22:36:15
(1 week ago)
csagent: score 15.2: php 404 x3, 404 noise floor x3, webshell name x1; 1 domain(s) in 0s
Web App Attack
๐ฌ๐ง
consul.to
2026-07-13 19:37:39
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-13 19:27:04
(1 week ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
raph
2026-07-10 18:20:44
(1 week ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack