๐ณ๐ฑ
wolfemium
2026-08-24 05:35:06
(4 days ago)
162.158.217.20 - - [24/Aug/2026:08:35:05 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.p ...
show more
162.158.217.20 - - [24/Aug/2026:08:35:05 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [24/Aug/2026:08:35:05 +0300] "GET /this_is_a_new_hello_world.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [24/Aug/2026:08:35:05 +0300] "GET /media.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [24/Aug/2026:08:35:05 +0300] "GET /classwithtostring.php?p= HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [24/Aug/2026:08:35:06 +0300] "GET /3PJcpMFsD8B.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [24/Aug/2026:08:35:06 +0300] "GET /5PJcpMFsD8B.php HTTP/1.1" 502 150 "-" "-"
...
show less
DDoS Attack
๐ซ๐ท
chengkev
2026-08-19 09:48:40
(1 week ago)
Esta IP fue detectada por CrowdSec, activando crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
deskpass.com
2026-08-09 21:40:24
(2 weeks ago)
GET /options.php
Web App Attack
๐ณ๐ฑ
wolfemium
2026-08-08 11:39:51
(2 weeks ago)
162.158.217.20 - - [08/Aug/2026:14:39:50 +0300] "GET /images.php HTTP/1.1" 502 150 "-" "-"
162.158.2 ...
show more
162.158.217.20 - - [08/Aug/2026:14:39:50 +0300] "GET /images.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [08/Aug/2026:14:39:50 +0300] "GET /222.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [08/Aug/2026:14:39:50 +0300] "GET /ops.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [08/Aug/2026:14:39:51 +0300] "GET /8.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [08/Aug/2026:14:39:51 +0300] "GET /coffexium.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [08/Aug/2026:14:39:51 +0300] "GET /1.php HTTP/1.1" 502 150 "-" "-"
...
show less
DDoS Attack
๐บ๐ธ
mawan
2026-08-06 21:59:26
(3 weeks ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ณ๐ฑ
wolfemium
2026-08-01 03:45:34
(3 weeks ago)
162.158.217.20 - - [01/Aug/2026:06:45:33 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.p ...
show more
162.158.217.20 - - [01/Aug/2026:06:45:33 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [01/Aug/2026:06:45:33 +0300] "GET /err.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [01/Aug/2026:06:45:33 +0300] "GET //aa.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [01/Aug/2026:06:45:33 +0300] "GET /xa.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [01/Aug/2026:06:45:34 +0300] "GET /images.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [01/Aug/2026:06:45:34 +0300] "GET /82.php HTTP/1.1" 502 150 "-" "-"
...
show less
DDoS Attack
Anonymous
2026-07-29 07:00:00
(4 weeks ago)
Apache probe; attempts=19; exact paths: /.env.backup | /.env.bak | /.env.dev | /.env.example | /.env ...
show more
Apache probe; attempts=19; exact paths: /.env.backup | /.env.bak | /.env.dev | /.env.example | /.env.local | /.env.old | /.env.php.bak | /.git-credentials | /.git/HEAD | /.git/config | /.hermes/.env | /.openclaw/.env | /admin/.env | /backend/.env | /config/.env | /config/.env.php | /core/.env | /public/.env | /web/.env
show less
Web App Attack
๐จ๐ญ
TheCoon
2026-07-28 22:30:01
(4 weeks ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐ฉ๐ช
ghostwarriors
2026-07-06 08:55:35
(1 month ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-03 02:22:00
(1 month ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wolfemium
2026-06-25 11:34:40
(2 months ago)
162.158.217.20 - - [25/Jun/2026:14:34:39 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.p ...
show more
162.158.217.20 - - [25/Jun/2026:14:34:39 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [25/Jun/2026:14:34:39 +0300] "GET /x.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [25/Jun/2026:14:34:39 +0300] "GET /adm1in.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [25/Jun/2026:14:34:39 +0300] "GET /bupa.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [25/Jun/2026:14:34:39 +0300] "GET /won.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [25/Jun/2026:14:34:39 +0300] "GET /xyn.php HTTP/1.1" 502 150 "-" "-"
...
show less
DDoS Attack
๐ฉ๐ช
ghostwarriors
2026-06-24 04:50:21
(2 months ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-06-10 13:18:42
(2 months ago)
Triggered Cloudflare WAF (firewallManaged) from CH.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from CH.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (iPhone; CPU iPhone OS 18_7 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.5 Mobile/15E148 Safari/604.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
AetherFox
2026-04-29 23:01:00
(3 months ago)
AetherFox VoidGuard detected: [Wed Apr 29 23:00:59.205587 2026] [authz_core:error] [pid 1519889:tid ...
show more
AetherFox VoidGuard detected: [Wed Apr 29 23:00:59.205587 2026] [authz_core:error] [pid 1519889:tid 1519928] [client 162.158.217.20:13608] AH01630: client denied by server configuration: proxy:https://[MASKED]/
[Wed Apr 29 23:00:59.294084 2026] [authz_core:error] [pid 1519889:tid 1519905] [client 162.158.217.20:13608] AH01630: client denied by server configuration: proxy:https://[MASKED]/.well-known/mcp/server-card.json
[Wed Apr 29 23:00:59.314057 2026] [authz_core:error] [pid 1519889:tid 1519917] [client 162.158.217.20:13608] AH01630: client denied by server configuration: proxy:https://[MASKED]/.well-known/mcp.json
[Wed Apr 29 23:00:59.342408 2026] [authz_core:error] [pid 1519889:tid 1519915] [client 162.158.217.20:13608] AH01630: client denied by server configuration: proxy:https://[MASKED]/.well-known/ucp
[Wed Apr 29 23:00:59.351142 2026] [authz_core:error] [pid 1519889:tid 1519896] [client 162.158.217.20:13609] AH01630: client denied by server confi
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wolfemium
2026-04-21 10:30:22
(4 months ago)
162.158.217.20 - - [21/Apr/2026:13:30:21 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.p ...
show more
162.158.217.20 - - [21/Apr/2026:13:30:21 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [21/Apr/2026:13:30:21 +0300] "GET /koiy.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [21/Apr/2026:13:30:21 +0300] "GET /jp.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [21/Apr/2026:13:30:21 +0300] "GET /aevly.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [21/Apr/2026:13:30:21 +0300] "GET /ta0ol.php HTTP/1.1" 502 150 "-" "-"
162.158.217.20 - - [21/Apr/2026:13:30:21 +0300] "GET /aligk.php HTTP/1.1" 502 150 "-" "-"
...
show less
DDoS Attack