๐ฌ๐ง
openstrike.co.uk
2026-07-06 05:15:09
(2 weeks ago)
99 attacks on PHP URLs:
GET /templates/beez/index.php HTTP/1.1
Web App Attack
๐ฌ๐ง
consul.to
2026-07-05 12:19:10
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
fazar
2026-07-05 10:04:00
(2 weeks ago)
crowdsecurity/http-admin-interface-probing on node: us01
Web App Attack
Hacking
๐บ๐ธ
Lee Daniel
2026-07-05 04:56:46
(2 weeks ago)
185.199.157.28 - - [05/Jul/2026:00:56:43 -0400] "GET /wp-content/themes/news-portal/error.php HTTP/1 ...
show more
185.199.157.28 - - [05/Jul/2026:00:56:43 -0400] "GET /wp-content/themes/news-portal/error.php HTTP/1.1" 404 30564 "http://portstcharles.com/wp-content/themes/news-portal/error.php" "Go-http-client/2.0"
185.199.157.28 - - [05/Jul/2026:00:56:43 -0400] "GET /wp-content/themes/fukasawa/inc/classes/403.php HTTP/1.1" 404 30697 "http://portstcharles.com/wp-content/themes/fukasawa/inc/classes/403.php" "Go-http-client/2.0"
185.199.157.28 - - [05/Jul/2026:00:56:44 -0400] "GET /wp-content/plugins/hello-plus/classes/ehp-sarang.php HTTP/1.1" 404 30712 "http://portstcharles.com/wp-content/plugins/hello-plus/classes/ehp-sarang.php" "Go-http-client/2.0"
185.199.157.28 - - [05/Jul/2026:00:56:45 -0400] "GET /wp-content/plugins/so-pinyin-slugs/inc/main_json.php HTTP/1.1" 404 30718 "http://portstcharles.com/wp-content/plugins/so-pinyin-slugs/inc/main_json.php" "Go-http-client/2.0"
185.199.157.28 - - [05/Jul/2026:00:56:45 -0400] "GET /wp-content/plugins/filester/assets/css/404.php HTTP/1.1" 404 30703 "http
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-05 02:27:14
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 24
Exploited Host
Web App Attack
๐ฉ๐ช
bescared
2026-06-04 19:40:00
(1 month ago)
WAF (2) - Malicious activity detected: URL probing.
Bad Web Bot
Web App Attack
Hacking
๐ฏ๐ต
SentinalX by uzumaru
2026-06-04 07:28:12
(1 month ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: api.deezer.com:443
show less
Open Proxy
Port Scan
๐ฏ๐ต
SentinalX by uzumaru
2026-06-01 07:50:12
(1 month ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: www.expressapisv2.net:443
show less
Open Proxy
Port Scan
๐ง๐ท
SOC PR
2026-05-12 12:32:17
(2 months ago)
IPS: WordPress File Manager Plugin Remote Code Execution (CVE-2020-25213).
Web App Attack
Anonymous
2026-05-12 11:56:05
(2 months ago)
(wp-php-upload-includes) Block attempt to access .php in uploads wordpress uploads or well-known 185 ...
show more
(wp-php-upload-includes) Block attempt to access .php in uploads wordpress uploads or well-known 185.199.157.28 (GB/United Kingdom/-)
show less
Brute-Force
๐ณ๐ฑ
Site.eu
2026-05-12 09:37:10
(2 months ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-05-05 15:33:40
(2 months ago)
<comment>
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-22 06:32:53
(3 months ago)
(mod_security) mod_security (id:234930) triggered by 185.199.157.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:234930) triggered by 185.199.157.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 02:32:47.345547 2026] [security2:error] [pid 2083210:tid 2083210] [client 185.199.157.28:56211] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||lenorasflowers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "lenorasflowers.com"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "aehrjyYqYb7BspiV5pWfnAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-04-21 12:52:21
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-21 11:31:00
(3 months ago)
(mod_security) mod_security (id:234930) triggered by 185.199.157.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:234930) triggered by 185.199.157.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 21 07:30:56.278073 2026] [security2:error] [pid 311404:tid 311415] [client 185.199.157.28:35125] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||econpage.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "econpage.com"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "aedf8FdJbGIJ-T7UYl3c3AAAAMg"]
show less
Brute-Force
Bad Web Bot
Web App Attack