π§πͺ
madeit
2026-09-24 03:10:33
(1 day ago)
Web App Attack
Anonymous
2026-09-07 07:50:05
(2 weeks ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
πΊπΈ
mawan
2026-08-10 12:11:02
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
πΊπΈ
ratcarcher-labs
2026-08-04 10:34:42
(1 month ago)
[Ratcarcher Labs/MutantShield honeypot CTI] actor=human vector=scanner_probe risk=70 attacks=4 depth ...
show more
[Ratcarcher Labs/MutantShield honeypot CTI] actor=human vector=scanner_probe risk=70 attacks=4 depth=1 node=node-ap-south canary=no human_score=65 agentic=15 cc=US asn=Cloudflare, Inc. | Data provided by Ratcarcher Labs Β· https://ratcarcher-labs.com Β· docs https://api.ratcarcher-labs.com/api/v1/public/docs
show less
Port Scan
Bad Web Bot
Anonymous
2026-08-01 18:33:53
(1 month ago)
172.69.58.252 - - [01/Aug/2026:20:33:49 +0200] "GET /wp-admin/js/ HTTP/1.1" 404 124 "-" "-"
172.69.5 ...
show more
172.69.58.252 - - [01/Aug/2026:20:33:49 +0200] "GET /wp-admin/js/ HTTP/1.1" 404 124 "-" "-"
172.69.58.252 - - [01/Aug/2026:20:33:49 +0200] "GET /wp-content/uploads/index.php HTTP/1.1" 404 124 "-" "-"
172.69.58.252 - - [01/Aug/2026:20:33:49 +0200] "GET /atex1.php HTTP/1.1" 404 124 "-" "-"
172.69.58.252 - - [01/Aug/2026:20:33:49 +0200] "GET /w.php HTTP/1.1" 404 124 "-" "-"
172.69.58.252 - - [01/Aug/2026:20:33:49 +0200] "GET /archive.php HTTP/1.1" 404 124 "-" "-"
172.69.58.252 - - [01/Aug/2026:20:33:49 +0200] "GET /bless.php HTTP/1.1" 404 124 "-" "-"
172.69.58.252 - - [01/Aug/2026:20:33:49 +0200] "GET /sagax1.php HTTP/1.1" 404 124 "-" "-"
172.69.58.252 - - [01/Aug/2026:20:33:50 +0200] "GET /wpc.php HTTP/1.1" 404 124 "-" "-"
172.69.58.252 - - [01/Aug/2026:20:33:50 +0200] "GET /fone1.php HTTP/1.1" 404 124 "-" "-"
172.69.58.252 - - [01/Aug/2026:20:33:50 +0200] "GET /ncx.php HTTP/1.1" 404 124 "-" "-"
172.69.58.252 - - [01/Aug/2026:20:33:50 +0200] "GET /wp-admin/js/index.php HTTP/1.1" 404 124
...
show less
Bad Web Bot
Web App Attack
π©πͺ
reznekcs
2026-07-18 05:02:56
(2 months ago)
Blocked by UFW firewall
Brute-Force
πΊπΈ
TPI-Abuse
2026-07-15 09:12:59
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.58.252 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.58.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 05:12:52.122926 2026] [security2:error] [pid 13986:tid 13986] [client 172.69.58.252:10939] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "graner.us"] [uri "/.env.local"] [unique_id "aldPFEEzM-1KjU_3vF3MugAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mawan
2026-07-11 05:54:44
(2 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
π―π΅
S.O.B.A. Dev.
2026-06-13 13:50:22
(3 months ago)
Persistent port scanning or vulnerability scanning
Port Scan
π³π±
wolfemium
2026-05-12 12:49:23
(4 months ago)
172.69.58.252 - - [12/May/2026:15:49:21 +0300] "GET /hypo.php HTTP/1.1" 502 150 "-" "-"
172.69.58.25 ...
show more
172.69.58.252 - - [12/May/2026:15:49:21 +0300] "GET /hypo.php HTTP/1.1" 502 150 "-" "-"
172.69.58.252 - - [12/May/2026:15:49:22 +0300] "GET /chosen.php HTTP/1.1" 502 150 "-" "-"
172.69.58.252 - - [12/May/2026:15:49:22 +0300] "GET /00.php HTTP/1.1" 502 150 "-" "-"
172.69.58.252 - - [12/May/2026:15:49:22 +0300] "GET /als.php HTTP/1.1" 502 150 "-" "-"
172.69.58.252 - - [12/May/2026:15:49:23 +0300] "GET /pol.php HTTP/1.1" 502 150 "-" "-"
172.69.58.252 - - [12/May/2026:15:49:23 +0300] "GET /ms-amdin.php HTTP/1.1" 502 150 "-" "-"
...
show less
DDoS Attack
π―π΅
S.O.B.A. Dev.
2026-01-03 10:23:46
(8 months ago)
Persistent port scanning or vulnerability scanning
Port Scan
π³π±
wolfemium
2025-12-01 10:23:39
(9 months ago)
172.69.58.252 - - [01/Dec/2025:12:23:25 +0200] "GET /check.php HTTP/2.0" 502 150 "-" "python-httpx/0 ...
show more
172.69.58.252 - - [01/Dec/2025:12:23:25 +0200] "GET /check.php HTTP/2.0" 502 150 "-" "python-httpx/0.28.1"
172.69.58.252 - - [01/Dec/2025:12:23:38 +0200] "GET /scripts/info.php HTTP/2.0" 502 150 "-" "python-httpx/0.28.1"
172.69.58.252 - - [01/Dec/2025:12:23:38 +0200] "GET /cgi-bin/phpinfo.php HTTP/2.0" 502 150 "-" "python-httpx/0.28.1"
172.69.58.252 - - [01/Dec/2025:12:23:38 +0200] "GET /cgi-bin/info.php HTTP/2.0" 502 150 "-" "python-httpx/0.28.1"
172.69.58.252 - - [01/Dec/2025:12:23:38 +0200] "GET /upload/phpinfo.php HTTP/2.0" 502 150 "-" "python-httpx/0.28.1"
172.69.58.252 - - [01/Dec/2025:12:23:39 +0200] "GET /upload/info.php HTTP/2.0" 502 150 "-" "python-httpx/0.28.1"
...
show less
DDoS Attack
πΊπΈ
mawan
2025-08-17 18:39:59
(1 year ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
Anonymous
2025-07-14 15:13:38
(1 year ago)
Aggressive web scan
Web App Attack
πΊπΈ
Heath Smith
2025-04-14 07:13:40
(1 year ago)
172.69.58.252 - - [14/Apr/2025:02:13:37 -0500] "GET /wp-admin/css/colors/blue/wp-login.php HTTP/1.1" ...
show more
172.69.58.252 - - [14/Apr/2025:02:13:37 -0500] "GET /wp-admin/css/colors/blue/wp-login.php HTTP/1.1" 404 456 "-" "-"
172.69.58.252 - - [14/Apr/2025:02:13:39 -0500] "GET /assets/images/wp-login.php HTTP/1.1" 404 456 "-" "-"
172.69.58.252 - - [14/Apr/2025:02:13:39 -0500] "GET /wp-content/languages/wp-login.php HTTP/1.1" 404 456 "-" "-"
...
show less
Brute-Force