๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-07-22 12:41:17
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-admin-interface-probing
Web App Attack
Hacking
๐บ๐ธ
WizardsToolkit
2026-07-22 01:36:03
(2 days ago)
attempted to access
Web App Attack
๐จ๐ญ
backslash
2026-06-30 02:33:01
(3 weeks ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ฆ๐บ
aranguren.org
2026-06-02 07:49:26
(1 month ago)
194.61.40.125 - - [02/Jun/2026:17:49:24 +1000] "GET /new.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (X11; ...
show more
194.61.40.125 - - [02/Jun/2026:17:49:24 +1000] "GET /new.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0"
194.61.40.125 - - [02/Jun/2026:17:49:24 +1000] "GET /wp-content/plugins/pwnd-1/admin.php HTTP/1.1" 404 994 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
194.61.40.125 - - [02/Jun/2026:17:49:24 +1000] "GET /wp-includes/defaults.php HTTP/1.1" 404 994 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0"
194.61.40.125 - - [02/Jun/2026:17:49:25 +1000] "GET /images/DJP9.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
194.61.40.125 - - [02/Jun/2026:17:49:25 +1000] "GET /wp-includes/customize/index.php HTTP/1.1" 404 994 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0"
194.61.40.125 - - [02/Jun/2026:17:49:
...
show less
Bad Web Bot
๐ฌ๐ง
consul.to
2026-05-30 12:33:42
(1 month ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
masterguru
2026-05-29 15:15:07
(1 month ago)
Too much 404 requests in 1 minute. Operator GE matched 10 at IP:block_script. (46020-193)
Hacking
Anonymous
2026-05-23 06:53:03
(2 months ago)
(wp-php-upload-includes) Block attempt to access .php in uploads wordpress uploads or well-known 194 ...
show more
(wp-php-upload-includes) Block attempt to access .php in uploads wordpress uploads or well-known 194.61.40.125 (IN/India/-)
show less
Brute-Force
๐ซ๐ท
masterguru
2026-05-17 13:26:06
(2 months ago)
Too much 404 requests in 1 minute. Operator GE matched 10 at IP:block_script. (46020-193)
Hacking
๐ณ๐ฑ
Site.eu
2026-05-16 18:45:44
(2 months ago)
Excessive 404/403 errors
Brute-Force
๐จ๐ฆ
Mediashaker
2026-05-15 17:47:13
(2 months ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 194.61.40.125 (IN/India/ ...
show more
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 194.61.40.125 (IN/India/-)
show less
Port Scan
๐บ๐ธ
1cyb3rpunk
2026-05-13 07:29:19
(2 months ago)
Honeypot interaction [HIGH]: php_webshell_probe โ kill-chain noneโexploit. Observed on sectrace.org ...
show more
Honeypot interaction [HIGH]: php_webshell_probe โ kill-chain noneโexploit. Observed on sectrace.org honeypot surface. Automated scanner/attacker activity.
show less
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 10:58:20
(2 months ago)
(mod_security) mod_security (id:240000) triggered by 194.61.40.125 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 194.61.40.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 06:58:17.228385 2026] [security2:error] [pid 10257:tid 10257] [client 194.61.40.125:47473] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||harmonyfactor.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "harmonyfactor.com"] [uri "/images/stories/themes.php"] [unique_id "agMHyc6BBPUKhyvDjVbrtQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Dolphi
2026-05-10 21:20:13
(2 months ago)
POST //xmlrpc.php
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-04-24 18:43:41
(3 months ago)
194.61.40.125 - - [24/Apr/2026:21:43:40 +0300] "GET /wp-content/themes/about.php HTTP/1.1" 404 706 " ...
show more
194.61.40.125 - - [24/Apr/2026:21:43:40 +0300] "GET /wp-content/themes/about.php HTTP/1.1" 404 706 "-" "Go-http-client/1.1"
194.61.40.125 - - [24/Apr/2026:21:43:41 +0300] "GET /wp-content/themes/index.php HTTP/1.1" 404 706 "-" "Go-http-client/1.1"
...
show less
Web App Attack
๐บ๐ธ
Major Hostility
2026-04-21 08:48:24
(3 months ago)
"GET /wp-includes/js/tinymce/skins/lightgray/about.php HTTP/1.1" 404
"GET /wp-admin/css/colors/coffe ...
show more
"GET /wp-includes/js/tinymce/skins/lightgray/about.php HTTP/1.1" 404
"GET /wp-admin/css/colors/coffee/autoload_classmap.php HTTP/1.1" 404
"GET /cgi-bin/index.php HTTP/1.1" 404
"GET /wp-includes/Text/autoload_classmap.php HTTP/1.1" 404
"GET /wp-includes/style-engine/about.php HTTP/1.1" 404
"GET /wp-includes/html-api/index.php HTTP/1.1" 404
"GET /wp-includes/block-supports/autoload_classmap.php HTTP/1.1" 404
"GET /wp-includes/style-engine/autoload_classmap.php HTTP/1.1" 404
"GET /file/function.php HTTP/1.1" 404
"GET /wp-admin/wp-login.php HTTP/1.1" 404
"GET /wp-includes/blocks/table/int/tmpl/index.php HTTP/1.1" 404
"GET /wp-includes/Text/index.php HTTP/1.1" 404
"GET /wp-content/autoload_classmap.php HTTP/1.1" 404
"GET %2
show less
Web App Attack