๐ซ๐ฎ
bittiguru.fi
2026-10-03 23:36:19
(1 day ago)
158.173.36.12 - [04/Oct/2026:02:35:29 +0300] "POST /wp-login.php HTTP/1.1" 301 178 "http://www.kytaj ...
show more
158.173.36.12 - [04/Oct/2026:02:35:29 +0300] "POST /wp-login.php HTTP/1.1" 301 178 "http://www.kytaja.fi/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15) Gecko/20100101 Firefox/118.0.2" "-"
158.173.36.12 - [04/Oct/2026:02:35:42 +0300] "POST /wp-login.php HTTP/1.1" 301 178 "http://www.kytaja.fi/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.6045.159 Safari/537.36" "-"
158.173.36.12 - [04/Oct/2026:02:35:54 +0300] "POST /wp-login.php HTTP/1.1" 301 178 "http://www.kytaja.fi/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.5993.88 Safari/537.36" "-"
158.173.36.12 - [04/Oct/2026:02:36:06 +0300] "POST /wp-login.php HTTP/1.1" 301 178 "http://www.kytaja.fi/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:121.0) Gecko/20100101 Firefox/121.0" "-"
158.173.36.12 - [04/Oct/2026:02:36:18 +0300] "POST /wp-login.php HTTP/1.1" 301 178 "http://www.kytaja.fi/wp-login
...
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 06:52:49
(2 days ago)
(mod_security) mod_security (id:221260) triggered by 158.173.36.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:221260) triggered by 158.173.36.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 02:52:36.425418 2026] [security2:error] [pid 12492:tid 12492] [client 158.173.36.12:31993] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||www.tulsatvmemories.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tulsatvmemories.com"] [uri "/"] [unique_id "ar9UtKpVs3WyEJmoIa5zqQAAAAQ"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 05:54:16
(2 days ago)
(mod_security) mod_security (id:221260) triggered by 158.173.36.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:221260) triggered by 158.173.36.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 01:54:02.412222 2026] [security2:error] [pid 95733:tid 95733] [client 158.173.36.12:28249] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "80"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||www.oliverhardy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.oliverhardy.com"] [uri "/test.cgi"] [unique_id "ar9G-lMsiIFYb0-haiFHhgAAAAk"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 05:11:58
(2 days ago)
(mod_security) mod_security (id:221260) triggered by 158.173.36.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:221260) triggered by 158.173.36.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 01:11:52.592033 2026] [security2:error] [pid 21854:tid 21854] [client 158.173.36.12:61207] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "80"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||www.jellisonrepair.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jellisonrepair.com"] [uri "/test.cgi"] [unique_id "ar89GDq2drBtiIT87tia4QAAACk"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-09-26 21:14:18
(1 week ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐ฉ๐ช
filstal.org
2026-09-26 20:49:18
(1 week ago)
Bad bot activity detected (automated scraping/probing).
Bad Web Bot
Web App Attack
๐ฌ๐ง
abivia
2026-09-26 18:01:25
(1 week ago)
Abivia WAF trigger: Rule not-wp: WP probing on non-WP site uri: /wp-includes/core.php
Hacking
Web App Attack
๐จ๐ญ
zynex
2026-09-26 16:35:28
(1 week ago)
URL Probing: /wp-content/themes/fukasawa/inc/classes/403.php
Web App Attack
๐ฎ๐น
VHosting
2026-09-17 21:15:03
(2 weeks ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-17 18:14:18
(2 weeks ago)
158.173.36.12 - - [17/Sep/2026:15:13:26 -0300] "GET /wp-includes/core.php HTTP/2.0" 444 0 "http://to ...
show more
158.173.36.12 - - [17/Sep/2026:15:13:26 -0300] "GET /wp-includes/core.php HTTP/2.0" 444 0 "http://topvitrine.com.br/wp-includes/core.php" "Go-http-client/2.0"
158.173.36.12 - - [17/Sep/2026:15:13:26 -0300] "GET /wp-includes/core.php HTTP/2.0" 444 0 "http://topvitrine.com.br/wp-includes/core.php" "Go-http-client/2.0"
158.173.36.12 - - [17/Sep/2026:15:14:17 -0300] "GET /wp-content/themes/theme-check/theme-check.php HTTP/2.0" 444 0 "http://topvitrine.com.br/wp-content/themes/theme-check/theme-check.php" "Go-http-client/2.0"
...
show less
Port Scan
๐น๐ท
neron
2026-07-26 17:50:51
(2 months ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ซ๐ท
mrcrassi
2026-07-25 23:28:23
(2 months ago)
Triggered Cloudflare WAF (firewallManaged) from ES.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST met ...
show more
Triggered Cloudflare WAF (firewallManaged) from ES.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /
UA: Mozilla/5.0 (compatible; wp2shell-check/1.0)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
FeG Deutschland
2026-07-22 02:09:37
(2 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-07-22 01:55:20
(2 months ago)
Multiple, malicious web requests detected
Port Scan
Hacking
๐ฎ๐ฉ
soc-yk
2026-07-11 01:54:14
(2 months ago)
Type: web_scanning
Risk: 100
Events: 86
Evidence:
- Automated hostile web probing detected
- Repeat ...
show more
Type: web_scanning
Risk: 100
Events: 86
Evidence:
- Automated hostile web probing detected
- Repeated web scanning activity observed
- Multi-event operational persistence identified
- Threat escalation behavior observed
show less
Web App Attack