๐ฉ๐ช
FeG Deutschland
2026-09-20 03:46:54
(9 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐ฎ๐น
Progetto1
2026-09-20 02:20:08
(11 hours ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
cwytech
2026-09-19 16:42:37
(21 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-login-lockdown-high.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-19 14:58:07
(22 hours ago)
[ti-11al] WordPress login brute-force: 4 suspicious requests detected by fail2ban jail apache-wordpr ...
show more
[ti-11al] WordPress login brute-force: 4 suspicious requests detected by fail2ban jail apache-wordpress. Example: 167.148.214.2 - - [19/Sep/2026:16:57:57 +0200] "POST /wp-login.php HTTP/1.1" 200 19278 "https://hess.nl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:138.0) Gecko/20100101 Firefox/138.0"
167.148.214.2 - - [19/Sep/2026:16:57:58 +0200] "POST /wp-login.php HTTP/1.1" 200 19278 "https://hess.nl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:138.0) Gecko/20100101 Firefox/138.0"
167.148.214.2 - - [19/Sep/2026:16:57:59 +0200] "POST /wp-login.php HTTP/1.1" 200 19279 "https://hess.nl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:138.0) Gecko/20100101 Firefox/138.0"
167.148.214.2 - - [19/Sep/2026:16:58:00 +0200] "POST /wp-login.php HTTP/1.1" 403 8004 "https://hess.nl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; W
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
MusicLibrary
2026-09-19 13:05:45
(1 day ago)
Probing foreign-stack admin panels / known exploit paths (Joomla, phpMyAdmin, phpunit, OWA, etc.)
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-19 06:00:05
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
helios.live
2026-09-18 23:08:45
(1 day ago)
2026/09/18 23:08:42 [error] 1369626#1369626: *3734008 FastCGI sent in stderr: "Primary script unknow ...
show more
2026/09/18 23:08:42 [error] 1369626#1369626: *3734008 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 167.148.214.2, server: kocerroxy.com, request: "GET /administrator/index.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php8.4-fpm-betakocerroxycom.sock:", host: "app.kocerroxy.com", referrer: "https://app.kocerroxy.com/administrator/"
167.148.214.2 - - [18/Sep/2026:23:08:42 +0000] "GET /administrator/index.php HTTP/1.1" 404 47 "https://app.kocerroxy.com/administrator/" "Mozilla/5.0 (Windows NT 17.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36"
2026/09/18 23:08:43 [error] 1369626#1369626: *3734008 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 167.148.214.2, server: kocerroxy.com, request: "GET /wp-login.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php8.4-fpm-betakocerroxycom.sock:", host: "app.kocerroxy.com"
167.148.214.2 - - [18/Sep/20
...
show less
Web App Attack
๐ฉ๐ช
LRob
2026-09-18 16:46:56
(1 day ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-login.php | 2026-09-18 16:46 UTC
show less
Hacking
Web App Attack
๐ฉ๐ช
LRob
2026-09-18 09:16:28
(2 days ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: /wp-login.php | 2026-09-18 09:16 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-18 09:06:55
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 167.148.214.2 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.148.214.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 05:06:48.411719 2026] [security2:error] [pid 8613:tid 8613] [client 167.148.214.2:55758] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||prcomputersolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "prcomputersolutions.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqz_KEDpUOUddAomozIeUwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-18 07:07:26
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐ฉ๐ช
EGP Abuse Dept
2026-09-18 05:38:43
(2 days ago)
Scanning for web/db/file exploits on www.moesson.com
SQL Injection
Bad Web Bot
Web App Attack
๐ฌ๐ง
SilverZippo
2026-09-18 04:22:00
(2 days ago)
Web App Attack
Web App Attack
๐ฎ๐ฉ
bps-statistics
2026-09-18 00:20:45
(2 days ago)
WP Login Scan Activities: "2026-09-18T07:20:45.354+07:00" "/wp-login.php" "167.148.214.2" "Mozilla/5 ...
show more
WP Login Scan Activities: "2026-09-18T07:20:45.354+07:00" "/wp-login.php" "167.148.214.2" "Mozilla/5.0 (Macintosh; Intel Mac OS X 15_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.3.0.2 Safari/537.36"
show less
Web App Attack
๐ฎ๐ฉ
xveil
2026-09-17 22:27:43
(2 days ago)
2026-09-18T05:27:41.108334 mail-honeypot postfix/submission/smtpd[27361]: warning: unknown[167.148.2 ...
show more
2026-09-18T05:27:41.108334 mail-honeypot postfix/submission/smtpd[27361]: warning: unknown[167.148.214.2]: SASL PLAIN authentication failed: authentication failure
...
show less
Brute-Force