๐ฎ๐ณ
evicky2002
2026-06-23 05:52:11
(2 months ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
nyt
2026-05-08 20:41:33
(3 months ago)
Hacking, Web App Attack, suspicious: Known Backdoor Name
Hacking
Web App Attack
๐ซ๐ฎ
6kilowatti
2026-05-08 12:05:47
(3 months ago)
2026/05/08 15:05:47 [error] 1354151#1354151: *220385 FastCGI sent in stderr: "Primary script unknown ...
show more
2026/05/08 15:05:47 [error] 1354151#1354151: *220385 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 2.58.56.197, server: oh6ah.fi, request: "GET /txets.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/oh6ah.fi.sock:", host: "oh6ah.fi"
2026/05/08 15:05:47 [error] 1354151#1354151: *220387 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 2.58.56.197, server: oh6ah.fi, request: "GET /wp-content/txets.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/oh6ah.fi.sock:", host: "oh6ah.fi"
...
show less
Web App Attack
๐ฉ๐ช
raph
2026-05-08 11:11:50
(3 months ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-05-08 05:16:01
(3 months ago)
2.58.56.197 - - [08/May/2026:06:15:59 +0100] "GET /txets.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Win ...
show more
2.58.56.197 - - [08/May/2026:06:15:59 +0100] "GET /txets.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
2.58.56.197 - - [08/May/2026:06:15:59 +0100] "GET /wp-content/txets.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
2.58.56.197 - - [08/May/2026:06:15:59 +0100] "GET /wp-includes/widgets/txets.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
...
show less
Hacking
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-05-08 04:39:14
(3 months ago)
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 197.56.58.2.rbl.malware ...
show more
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 197.56.58.2.rbl.malware.expert succeeded at REQUEST_HEADERS:x-forwarded-for. (1001000-mnz6-3)
show less
Hacking
๐ฌ๐ง
consul.to
2026-05-07 15:26:34
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-07 12:43:29
(3 months ago)
2.58.56.197 - - [07/May/2026:15:43:28 +0300] "GET /wp-includes/blocks/post-template/txets.php HTTP/1 ...
show more
2.58.56.197 - - [07/May/2026:15:43:28 +0300] "GET /wp-includes/blocks/post-template/txets.php HTTP/1.1" 404 762 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
...
show less
Web App Attack
๐ซ๐ท
conseilgouz
2026-05-07 12:31:08
(3 months ago)
sae-7 : Trying access unauthorized files/dir=>/wp-content/txets.php
Hacking
๐บ๐ฆ
URAN Publishing Service
2026-05-07 10:43:28
(3 months ago)
2.58.56.197 - - [07/May/2026:13:43:27 +0300] "GET /wp-content/txets.php HTTP/1.1" 404 765 "-" "Mozil ...
show more
2.58.56.197 - - [07/May/2026:13:43:27 +0300] "GET /wp-content/txets.php HTTP/1.1" 404 765 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
nyt
2026-05-07 07:01:47
(3 months ago)
Hacking, Web App Attack, suspicious: Known Backdoor Name
Hacking
Web App Attack
Anonymous
2026-05-07 06:48:23
(3 months ago)
[Thu May 07 01:48:19.570720 2026] [proxy_fcgi:error] [pid 1122241:tid 1122241] [client 2.58.56.197:5 ...
show more
[Thu May 07 01:48:19.570720 2026] [proxy_fcgi:error] [pid 1122241:tid 1122241] [client 2.58.56.197:50573] AH01071: Got error 'Primary script unknown'
[Thu May 07 01:48:19.829212 2026] [proxy_fcgi:error] [pid 1124470:tid 1124470] [client 2.58.56.197:56962] AH01071: Got error 'Primary script unknown'
[Thu May 07 01:48:20.025652 2026] [proxy_fcgi:error] [pid 1139834:tid 1139834] [client 2.58.56.197:53195] AH01071: Got error 'Primary script unknown'
...
show less
Web App Attack
๐บ๐ธ
Epimetheus
2026-05-06 12:26:42
(3 months ago)
Unauthorized access attempts:
[GET] /schallfuns.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) ...
show more
Unauthorized access attempts:
[GET] /schallfuns.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-06 10:55:48
(3 months ago)
2.58.56.197 - - [06/May/2026:13:55:47 +0300] "GET /wp-content/txets.php HTTP/1.1" 404 764 "-" "Mozil ...
show more
2.58.56.197 - - [06/May/2026:13:55:47 +0300] "GET /wp-content/txets.php HTTP/1.1" 404 764 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
2.58.56.197 - - [06/May/2026:13:55:47 +0300] "GET /wp-includes/widgets/txets.php HTTP/1.1" 404 764 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
rdpguard.com
2026-05-06 10:31:40
(3 months ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force