Anonymous
2026-08-31 09:12:48
(1 day ago)
Attack detected: 187.75.112.116 [2026-08-31]
Categories: 21
--- wp2shell/batch exploit (6 hits) ---
...
show more
Attack detected: 187.75.112.116 [2026-08-31]
Categories: 21
--- wp2shell/batch exploit (6 hits) ---
187.75.112.116 - - [16/Aug/2026:08:40:58 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 4771 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36"
187.75.112.116 - - [16/Aug/2026:08:41:00 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 5234 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36"
187.75.112.116 - - [17/Aug/2026:05:17:48 +0000] "POST /wp-json/batch/v1 HTTP/1.1" 207 720 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36"
187.75.112.116 - - [17/Aug/2026:05:17:50 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 720 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36"
187.75.112.116 - - [17/Aug/2026:05:17:51 +0000] "POST /?rest_route=/batch/v
show less
Web App Attack
🇨🇭
SOC [GOLINE SA]
2026-08-20 00:04:14
(1 week ago)
FortiGate detected IPS attack from IPv4 address 187.75.112.116
Hacking
🇨🇭
SOC [GOLINE SA]
2026-08-18 23:03:38
(1 week ago)
FortiGate detected IPS attack from IPv4 address 187.75.112.116
Hacking
🇨🇭
SOC [GOLINE SA]
2026-08-17 23:03:34
(2 weeks ago)
FortiGate detected IPS attack from IPv4 address 187.75.112.116
Hacking
🇮🇹
mediarama.com
2026-08-17 02:04:44
(2 weeks ago)
Banned by Fail2Ban
Web App Attack
🇨🇭
SOC [GOLINE SA]
2026-08-16 22:11:13
(2 weeks ago)
FortiGate detected IPS attack from IPv4 address 187.75.112.116
Hacking
🇩🇪
FeG Deutschland
2026-08-16 20:21:24
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
🇦🇺
paulshipley.com.au
2026-08-16 14:30:37
(2 weeks ago)
[Mon Aug 17 00:30:36.566151 2026] [security2:error] [pid 879622] [client 187.75.112.116:26041] [clie ...
show more
[Mon Aug 17 00:30:36.566151 2026] [security2:error] [pid 879622] [client 187.75.112.116:26041] [client 187.75.112.116] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "furst.com.au"] [uri "/"] [unique_id "aoHJjGW7g5JyMEp7N1LIBAAAAAY"]
...
show less
Web App Attack
Anonymous
2026-08-16 09:07:14
(2 weeks ago)
Attack detected: 187.75.112.116 [2026-08-16]
Categories: 21
--- wp2shell/batch exploit (3 hits) ---
...
show more
Attack detected: 187.75.112.116 [2026-08-16]
Categories: 21
--- wp2shell/batch exploit (3 hits) ---
187.75.112.116 - - [16/Aug/2026:08:40:57 +0000] "POST /wp-json/batch/v1 HTTP/1.1" 207 4771 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36"
187.75.112.116 - - [16/Aug/2026:08:40:58 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 4771 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36"
187.75.112.116 - - [16/Aug/2026:08:41:00 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 5234 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36"
show less
Web App Attack
🇦🇺
paulshipley.com.au
2026-08-16 04:44:48
(2 weeks ago)
[Sun Aug 16 14:44:47.904816 2026] [security2:error] [pid 873198] [client 187.75.112.116:55720] [clie ...
show more
[Sun Aug 16 14:44:47.904816 2026] [security2:error] [pid 873198] [client 187.75.112.116:55720] [client 187.75.112.116] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "levellapromotions.com.au"] [uri "/"] [unique_id "aoFAP6kznuPED1FbSZbgAgAAAAs"]
...
show less
Web App Attack
🇩🇪
LRob
2026-08-16 00:58:13
(2 weeks ago)
Probing for known CVE exploits | req: /wp-json/batch/v1 | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x ...
show more
Probing for known CVE exploits | req: /wp-json/batch/v1 | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36
show less
Web App Attack
🇨🇭
SOC [GOLINE SA]
2026-08-15 22:04:28
(2 weeks ago)
FortiGate detected IPS attack from IPv4 address 187.75.112.116
Hacking
🇩🇪
FeG Deutschland
2026-08-15 18:47:06
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
Anonymous
2026-08-15 15:55:08
(2 weeks ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
🇮🇳
evicky2002
2026-08-15 07:06:21
(2 weeks ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH