🇨🇭
Ribeye375
2026-09-14 06:25:00
(24 minutes ago)
HIPS nginx-anti-botnet - Block tcp/0:65535
Bad Web Bot
🇺🇸
dot.mg
2026-09-14 04:15:04
(2 hours ago)
Scan of vulnerable files
Web App Attack
🇩🇪
yvoictra
2026-09-14 02:55:21
(3 hours ago)
Bloqueado automáticamente por CrowdSec. Escenario: crowdsecurity/http-wordpress-scan
Web App Attack
🇩🇪
Herrminator
2026-09-13 20:24:19
(10 hours ago)
tjvps01.johler.de 185.92.25.20 - - [13/Sep/2026:22:24:16 +0200] "GET /000.php HTTP/1.1" 301 169 "-" ...
show more
tjvps01.johler.de 185.92.25.20 - - [13/Sep/2026:22:24:16 +0200] "GET /000.php HTTP/1.1" 301 169 "-" "Go-http-client/1.1" "-"
tjvps01.johler.de 185.92.25.20 - - [13/Sep/2026:22:24:16 +0200] "GET /chosen.php?p= HTTP/1.1" 301 169 "-" "Go-http-client/1.1" "-"
tjvps01.johler.de 185.92.25.20 - - [13/Sep/2026:22:24:17 +0200] "GET /wp-includes/hp2.php HTTP/1.1" 301 169 "-" "Go-http-client/1.1" "-"
tjvps01.johler.de 185.92.25.20 - - [13/Sep/2026:22:24:17 +0200] "GET /gifclass.php HTTP/1.1" 301 169 "-" "Go-http-client/1.1" "-"
tjvps01.johler.de 185.92.25.20 - - [13/Sep/2026:22:24:17 +0200] "GET /bless.php HTTP/1.1" 301 169 "-" "Go-http-client/1.1" "-"
tjvps01.johler.de 185.92.25.20 - - [13/Sep/2026:22:24:17 +0200] "GET /wp-content/goods.php HTTP/1.1" 301 169 "-" "Go-http-client/1.1" "-"
tjvps01.johler.de 185.92.25.20 - - [13/Sep/2026:22:24:17 +0200] "GET /blurbs.php HTTP/1.1" 301 169 "-" "Go-http-client/1.1" "-"
tjvps01.johler.de 185.92.25.20 - - [13/Sep/2026:22:24:17 +0200] "GET /wp-admin/css/g
...
show less
Brute-Force
Web App Attack
🇦🇺
A.i.D.A.N.N
2026-09-13 13:29:29
(17 hours ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web vulnerability scanning detected
Web App Attack
🇱🇻
garmtech.com
2026-09-13 09:19:48
(21 hours ago)
Attempted access to sensitive endpoint (//wp-content/plugins/fix//wp%20sittnegc.php) detected. Autom ...
show more
Attempted access to sensitive endpoint (//wp-content/plugins/fix//wp%20sittnegc.php) detected. Automated scan or unauthorized probing.
show less
Web App Attack
🇸🇮
administrator
2026-09-11 23:00:04
(2 days ago)
2026-09-06 00:25:03,178 fail2ban.actions [1054]: NOTICE [apache-badbots] Ban 185.92.25.20
20 ...
show more
2026-09-06 00:25:03,178 fail2ban.actions [1054]: NOTICE [apache-badbots] Ban 185.92.25.20
2026-09-06 00:25:03,178 fail2ban.actions [1054]: NOTICE [apache-badbots] Ban 185.92.25.20
2026-09-06 00:25:03,178 fail2ban.actions [1054]: NOTICE [apache-badbots] Ban 185.92.25.20
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
🇺🇸
wbsouza
2026-09-08 03:28:11
(6 days ago)
CrowdSec: infra/bad-path-probe — automated firewall drops on self-hosted IDS sensor
Hacking
🇩🇪
filstal.org
2026-09-07 19:00:17
(6 days ago)
Bad bot activity detected (automated scraping/probing).
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-09-07 10:50:13
(6 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-07 10:35:57
(6 days ago)
[site]:80 185.92.25.20 - - [07/Sep/2026:12:35:48 +0200] "GET /wp-content/plugins/index.php HTTP/1.1" ...
show more
[site]:80 185.92.25.20 - - [07/Sep/2026:12:35:48 +0200] "GET /wp-content/plugins/index.php HTTP/1.1" 404 441 "-" "Go-http-client/1.1"
[site]:80 185.92.25.20 - - [07/Sep/2026:12:35:48 +0200] "GET /wp-content/index.php HTTP/1.1" 404 441 "-" "Go-http-client/1.1"
[site]:80 185.92.25.20 - - [07/Sep/2026:12:35:48 +0200] "GET /wp-content/plugins/fix/000.php HTTP/1.1" 404 441 "-" "Go-http-client/1.1"
[site]:80 185.92.25.20 - - [07/Sep/2026:12:35:48 +0200] "GET /file.php HTTP/1.1" 404 439 "-" "Go-http-client/1.1"
[site]:80 185.92.25.20 - - [07/Sep/2026:12:35:48 +0200] "GET //wp-content/plugins/fix/up.php HTTP/1.1" 404 441 "-" "Go-http-client/1.1"
[site]:80 185.92.25.20 - - [07/Sep/2026:12:35:48 +0200] "GET //wp-content/plugins/fix/wp.php HTTP/1.1" 404 441 "-" "Go-http-client/1.1"
[site]:80 185.92.25.20 - - [07/Sep/2026:12:35:48 +0200] "GET /ioxi-o.php HTTP/1.1" 404 439 "-" "Go-http-client/1.1"
[site]:80 185.92.25.20 - - [07/Sep/2026:12:35:48 +0200] "GET /txets.php HTTP/1.1" 404 439 "-" "Go-http
show less
Web App Attack
Hacking
🇬🇷
setupgr
2026-09-07 04:44:27
(1 week ago)
(mod_security) mod_security (id:1000001) triggered by 185.92.25.20 (GB/United Kingdom/England/Slough ...
show more
(mod_security) mod_security (id:1000001) triggered by 185.92.25.20 (GB/United Kingdom/England/Slough/-/[AS206092 F.n.s. Holdings Limited]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Mon Sep 07 07:44:25.737316 2026] [security2:error] [pid 2882:tid 3037] [client 185.92.25.20:40603] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/000.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "103"] [id "1000001"] [msg "Bad file blocked: /wp-content/plugins/fix/000.php"] [severity "CRITICAL"] [tag "security"] [hostname "adoro.gr"] [uri "/wp-content/plugins/fix/000.php"] [unique_id "ap5BKaTc2pKyAOv5QuZfJQAAAo4"]
show less
Port Scan
🇸🇪
SkyDancer
2026-09-06 05:40:41
(1 week ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
🇬🇧
consul.to
2026-09-05 18:59:52
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
🇷🇴
clauss
2026-09-05 13:59:04
(1 week ago)
185.92.25.20 - - [05/Sep/2026:16:58:59 +0300] "GET /000.php HTTP/2.0" 404 1817 "http://eemusic.ro/00 ...
show more
185.92.25.20 - - [05/Sep/2026:16:58:59 +0300] "GET /000.php HTTP/2.0" 404 1817 "http://eemusic.ro/000.php" "Go-http-client/2.0"
185.92.25.20 - - [05/Sep/2026:16:59:04 +0300] "GET /bless.php HTTP/2.0" 404 1820 "http://eemusic.ro/bless.php#888xyz999" "Go-http-client/2.0"
...
show less
Web App Attack