๐ง๐ฌ
HighWay
2026-07-30 13:46:10
(1 minute ago)
20.52.125.110 - - [30/Jul/2026:13:45:53 +0000] "GET /.tmb/LA.php HTTP/1.1" 404 4757 "-" "Mozilla/5.0 ...
show more
20.52.125.110 - - [30/Jul/2026:13:45:53 +0000] "GET /.tmb/LA.php HTTP/1.1" 404 4757 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
20.52.125.110 - - [30/Jul/2026:13:45:53 +0000] "GET /.tmb/admin.php HTTP/1.1" 404 770 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
20.52.125.110 - - [30/Jul/2026:13:45:53 +0000] "GET /.tmb/class_api.php HTTP/1.1" 404 770 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
20.52.125.110 - - [30/Jul/2026:13:45:53 +0000] "GET /.tmb/cpabpkyk.php HTTP/1.1" 404 770 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
20.52.125.110 - - [30/Jul/2026:13:45:53 +0000] "GET /.tmb/wp-login.php HTTP/1.1" 404 770 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chro
...
show less
Port Scan
Bad Web Bot
Anonymous
2026-07-30 13:45:48
(1 minute ago)
Aggressive web scan
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-07-30 13:39:57
(7 minutes ago)
{"level":"info","ts":1785416677.368567,"logger":"http.log.access.log0","msg":"handled request","requ ...
show more
{"level":"info","ts":1785416677.368567,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"20.52.125.110","remote_port":"15297","client_ip":"20.52.125.110","proto":"HTTP/1.1","method":"GET","host":"acfa.status.updown.io","uri":"/albin.php","headers":{"Sec-Fetch-Mode":["navigate"],"Sec-Fetch-User":["?1"],"Cache-Control":["max-age=0"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"],"Sec-Fetch-Site":["none"],"Connection":["keep-alive"],"Sec-Fetch-Dest":["document"],"Accept-Language":["en-US, en; q=0.9"],"Sec-Ch-Ua-Mobile":["?0"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Accept-Encoding":["gzip, deflate, br"],"Dnt":["1"],"Accept":["text/html, application/xhtml+xml, application/xml; q=0.9, image/webp, image/apng, */*; q=0.8, application/signed-exchange; v=b3; q=0.7"],"Sec-Ch-Ua":["\"Not_A Brand\";v=\"8\", \"Chromium\";v=\"120\", \"Google Chrome\";v=\"120\""],"Upgrade-Insecure-Requests":[
...
show less
DDoS Attack
Web App Attack
๐ฉ๐ช
AetherFox
2026-07-30 13:33:40
(13 minutes ago)
AetherFox VoidGuard detected: [Thu Jul 30 13:33:39.878934 2026] [authz_core:error] [pid 3424903:tid ...
show more
AetherFox VoidGuard detected: [Thu Jul 30 13:33:39.878934 2026] [authz_core:error] [pid 3424903:tid 3424919] [client 20.52.125.110:6401] AH01630: client denied by server configuration: proxy:https://[MASKED]/.tmb/LA.php
[Thu Jul 30 13:33:39.888651 2026] [authz_core:error] [pid 3424903:tid 3424906] [client 20.52.125.110:6401] AH01630: client denied by server configuration: proxy:https://[MASKED]/.tmb/admin.php
[Thu Jul 30 13:33:39.894221 2026] [authz_core:error] [pid 3424903:tid 3424924] [client 20.52.125.110:6401] AH01630: client denied by server configuration: proxy:https://[MASKED]/.tmb/class_api.php
[Thu Jul 30 13:33:39.900012 2026] [authz_core:error] [pid 3424903:tid 3424913] [client 20.52.125.110:6401] AH01630: client denied by server configuration: proxy:https://[MASKED]/.tmb/cpabpkyk.php
[Thu Jul 30 13:33:39.905469 2026] [authz_core:error] [pid 3424903:tid 3424910] [client 20.52.125.110:6401] AH01630: client denied by server configuration: proxy:h
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-07-30 13:30:11
(17 minutes ago)
Repeated probing for non-existent PHP exploit paths blocked by Fail2Ban
Web App Attack
๐ฑ๐น
Evag Touf
2026-07-30 13:29:33
(18 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 20.52.125.110 (DE/Germany/-)
SQL Injection
Anonymous
2026-07-30 13:29:04
(18 minutes ago)
Attempted known web exploits
Brute-Force
Web App Attack
๐ฉ๐ช
auridh
2026-07-30 13:21:54
(25 minutes ago)
Ip 20.52.125.110 performed 'crowdsecurity/http-wordpress-scan' (4 events over 2.293957894s) at 2026- ...
show more
Ip 20.52.125.110 performed 'crowdsecurity/http-wordpress-scan' (4 events over 2.293957894s) at 2026-07-30 13:01:57.410556502 +0000 UTC
show less
Web App Attack
๐ต๐ฑ
lns.bz
2026-07-30 13:13:02
(34 minutes ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
๐ฌ๐ท
setupgr
2026-07-30 13:12:49
(34 minutes ago)
(mod_security) mod_security (id:1000001) triggered by 20.52.125.110 (DE/Germany/Hesse/Frankfurt am M ...
show more
(mod_security) mod_security (id:1000001) triggered by 20.52.125.110 (DE/Germany/Hesse/Frankfurt am Main/-/[AS8075 MICROSOFT-CORP-MSN-AS-BLOCK]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Jul 30 16:12:44.625524 2026] [security2:error] [pid 153808:tid 154010] [client 20.52.125.110:4119] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/about.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "103"] [id "1000001"] [msg "Bad file blocked: /wp-content/plugins/about.php"] [severity "CRITICAL"] [tag "security"] [hostname "ns3.setworldup365.com"] [uri "/wp-content/plugins/about.php"] [unique_id "amtNzHdoiBjRqGJUANqI9QAAApM"]
show less
Port Scan
๐ฆ๐บ
QT
2026-07-30 13:04:43
(42 minutes ago)
Website hack attempted at 2026-07-30 23:04:37 +1000
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-07-30 13:01:22
(46 minutes ago)
Known malicious PHP file or CMS probe
Web App Attack
๐บ๐ธ
kosada.com
2026-07-30 12:59:05
(48 minutes ago)
Web vulnerability probing: /.well-known/acme-challenge/classsmtps.php
Web App Attack
๐ฉ๐ช
hchristo
2026-07-30 12:52:25
(55 minutes ago)
[Thu Jul 30 14:52:25.244686 2026] [proxy_fcgi:error] [pid 42064:tid 42375] [client 20.52.125.110:886 ...
show more
[Thu Jul 30 14:52:25.244686 2026] [proxy_fcgi:error] [pid 42064:tid 42375] [client 20.52.125.110:8865] AH01071: Got error 'Primary script unknown'
[Thu Jul 30 14:52:25.256131 2026] [proxy_fcgi:error] [pid 42064:tid 42379] [client 20.52.125.110:8865] AH01071: Got error 'Primary script unknown'
[Thu Jul 30 14:52:25.267308 2026] [proxy_fcgi:error] [pid 42064:tid 42378] [client 20.52.125.110:8865] AH01071: Got error 'Primary script unknown'
[Thu Jul 30 14:52:25.284810 2026] [proxy_fcgi:error] [pid 42064:tid 42329] [client 20.52.125.110:8865] AH01071: Got error 'Primary script unknown'
[Thu Jul 30 14:52:25.318499 2026] [proxy_fcgi:error] [pid 42064:tid 42370] [client 20.52.125.110:8865] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐ฉ๐ช
Ba-Yu
2026-07-30 12:51:25
(56 minutes ago)
WordPress bruteforce
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack