๐ฆ๐บ
weblite
2025-03-25 18:51:03
(1 year ago)
WP_EXPLOIT_PROBE WP_MALWARE_PROBE
Hacking
Web App Attack
Anonymous
2025-03-25 17:31:11
(1 year ago)
Inappropriate script execution attempts
Hacking
Brute-Force
๐บ๐ธ
ph
2025-03-25 16:59:53
(1 year ago)
Bad web bot attempting to run wp-content on non-WP site
Hacking
Bad Web Bot
Web App Attack
Anonymous
2025-03-25 15:19:33
(1 year ago)
Bot / scanning and/or hacking attempts: GET /wp-content/plugins/wp-login.php HTTP/1.1, GET /12wudscz ...
show more
Bot / scanning and/or hacking attempts: GET /wp-content/plugins/wp-login.php HTTP/1.1, GET /12wudscz.php HTTP/1.1, GET /wp-content/themes/wp-pridmag/admin.php HTTP/1.1, GET /wp-includes/Text/wp-conflg.php HTTP/1.1, GET /wp-includes/assets/index.php HTTP/1.1, GET /wp-content/plugins/background-image-cropper/plugins.php HT, GET /admin.php HTTP/1.1, GET /wp-content/uploads/autoload_classmap.php HTTP/1.1, GET /.well-known/pki-validation/parx.php HTTP/1.1, GET /wp-includes/css/dist/preferences/index.php HTTP/1.1
show less
Hacking
Web App Attack
Anonymous
2025-03-25 13:12:02
(1 year ago)
Malicious activity detected
Hacking
Web App Attack
๐จ๐ฆ
mitsurugi
2025-03-25 10:06:00
(1 year ago)
Probing for too many things.
Bad Web Bot
Web App Attack
Anonymous
2025-03-25 08:24:50
(1 year ago)
20.242.56.124 - - [25/Mar/2025:09:24:49 +0100] "GET /wp-content/plugins/hellopress/wp_filemanager.ph ...
show more
20.242.56.124 - - [25/Mar/2025:09:24:49 +0100] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 403 3779
...
show less
Web App Attack
๐ซ๐ท
dynamix
2025-03-25 02:34:46
(1 year ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-25 02:32:17
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 20.242.56.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 20.242.56.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 24 22:32:10.347558 2025] [security2:error] [pid 14689:tid 14689] [client 20.242.56.124:8423] [client 20.242.56.124] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||godscreationobservatory.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "godscreationobservatory.com"] [uri "/images/stories/admin-post.php"] [unique_id "Z-IVqh54aEf8CeI-GDDMogAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-25 01:44:05
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 20.242.56.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 20.242.56.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 24 21:42:31.790626 2025] [security2:error] [pid 22583:tid 22583] [client 20.242.56.124:1407] [client 20.242.56.124] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||abbeygardensllandudno.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "abbeygardensllandudno.com"] [uri "/images/stories/admin-post.php"] [unique_id "Z-IKBz_6pKVJpDuevbREXAAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2025-03-25 00:07:36
(1 year ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-03-25 00:01:12
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 20.242.56.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 20.242.56.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 24 20:01:05.459825 2025] [security2:error] [pid 15467:tid 15467] [client 20.242.56.124:14023] [client 20.242.56.124] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||springfieldtileexpert.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "springfieldtileexpert.com"] [uri "/images/stories/admin-post.php"] [unique_id "Z-HyQQMHtuSglNW1bfGwQgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2025-03-24 23:07:47
(1 year ago)
Wordpress hacking attempt
Web App Attack
๐ฉ๐ช
HERA - Operations
2025-03-24 22:43:44
(1 year ago)
bau-arge - searching for vulnerable scripts: wp_filemanager.php 2025/03/24 22:43:44
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2025-03-24 22:35:39
(1 year ago)
(WPLOGIN) WP Login Attack 20.242.56.124 (US/United States/-): 5 in the last 3600 secs; Ports: *; Dir ...
show more
(WPLOGIN) WP Login Attack 20.242.56.124 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack