๐ฉ๐ช
todix
2026-07-31 10:25:51
(4 minutes ago)
WebAttack or semilar from 20.52.217.208
Web App Attack
๐ฉ๐ช
maxpower
2026-07-31 10:23:55
(6 minutes ago)
(aggressive_scanner) REGOLA 9 - Aggressive Web Scanner 20.52.217.208 (DE/Germany/-): 1 in the last 3 ...
show more
(aggressive_scanner) REGOLA 9 - Aggressive Web Scanner 20.52.217.208 (DE/Germany/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 20.52.217.208 - - [31/Jul/2026:12:21:33 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 301 315 "-" "-" "-" host=falone.com
show less
Port Scan
๐ฉ๐ช
R.G.
2026-07-31 10:22:32
(8 minutes ago)
(ScanningForFiles) Scanning for files triggerd 20.52.217.208 (DE/Germany/-): 10 in the last 900 secs ...
show more
(ScanningForFiles) Scanning for files triggerd 20.52.217.208 (DE/Germany/-): 10 in the last 900 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ฎ๐ฉ
soc-yk
2026-07-31 10:18:13
(12 minutes ago)
Type: web_scanning
Risk: 100
Events: 31
Evidence:
- Automated hostile web probing detected
- Repeat ...
show more
Type: web_scanning
Risk: 100
Events: 31
Evidence:
- Automated hostile web probing detected
- Repeated web scanning activity observed
- Threat escalation behavior observed
show less
Web App Attack
๐ฌ๐ท
setupgr
2026-07-31 10:14:46
(15 minutes ago)
(mod_security) mod_security (id:1000001) triggered by 20.52.217.208 (DE/Germany/Hesse/Frankfurt am M ...
show more
(mod_security) mod_security (id:1000001) triggered by 20.52.217.208 (DE/Germany/Hesse/Frankfurt am Main/-/[AS8075 MICROSOFT-CORP-MSN-AS-BLOCK]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Fri Jul 31 13:14:43.313639 2026] [security2:error] [pid 384107:tid 384261] [client 20.52.217.208:14804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/wp-content/plugins/hellopress/wp_filemanager.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "103"] [id "1000001"] [msg "Bad file blocked: /wp-content/plugins/hellopress/wp_filemanager.php"] [severity "CRITICAL"] [tag "security"] [hostname "mail.endoscope.gr"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "amx1k7ieq8jM5RnEWY_q7QAAA0s"]
show less
Port Scan
๐บ๐ธ
antlac1
2026-07-31 10:11:57
(18 minutes ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ฉ๐ช
MarkGGN
2026-07-31 10:08:20
(22 minutes ago)
Web attack. 20.52.217.208 - - [31/Jul/2026:12:08:18 +0200] "GET /images.php HTTP/1.1" 404 27 "-" "-" ...
show more
Web attack. 20.52.217.208 - - [31/Jul/2026:12:08:18 +0200] "GET /images.php HTTP/1.1" 404 27 "-" "-"
20.52.217.208 - - [31/Jul/2026:12:08:19 +0200] "GET /.well-known/about.php HTTP/1.1" 404 27 "-" "-"
show less
Web App Attack
Anonymous
2026-07-31 10:07:05
(23 minutes ago)
Automated web scanner. Requested suspicious paths: /wp-content/plugins/hellopress/wp_filemanager.php ...
show more
Automated web scanner. Requested suspicious paths: /wp-content/plugins/hellopress/wp_filemanager.php | /this_is_a_new_hello_world.php | /3PJcpMFsD8B.php | //aa.php | /img.php | //av.php | /media.php | /err.php | /xa.php | /images.php | /gecko.php | /82.php. UTC: 2026-07-31 09:42:45.
show less
Web App Attack
๐ซ๐ท
masterguru
2026-07-31 10:05:56
(24 minutes ago)
Too much 404 requests in 1 minute. Operator GE matched 10 at IP:block_script. (46020-201)
Hacking
๐จ๐ฆ
TechnoSolutions CL
2026-07-31 10:04:18
(26 minutes ago)
20.52.217.208 - - [31/Jul/2026:09:59:28 +0000] "GET /wp-content/plugins/hellopress/wp_filemanager.ph ...
show more
20.52.217.208 - - [31/Jul/2026:09:59:28 +0000] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 405 150 "-" "-"
20.52.217.208 - - [31/Jul/2026:10:01:53 +0000] "GET /wp-content/uploads/ HTTP/1.1" 405 150 "-" "-"
20.52.217.208 - - [31/Jul/2026:10:01:53 +0000] "GET /wp-includes/Text/ HTTP/1.1" 405 150 "-" "-"
20.52.217.208 - - [31/Jul/2026:10:04:18 +0000] "GET /wp-admin/css/colors/modern/ HTTP/1.1" 405 150 "-" "-"
...
show less
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-07-31 10:02:47
(27 minutes ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
rh24
2026-07-31 10:00:08
(30 minutes ago)
Blacklisted for CAPTCHA_DOS_ALERT after 101 captcha requests
DDoS Attack
Web App Attack
๐ฉ๐ช
netclix.gr
2026-07-31 09:47:53
(42 minutes ago)
(aggressive_scan) Aggressive Web Exploit Scan 20.52.217.208 (DE/Germany/-): 5 in the last 4600 secs; ...
show more
(aggressive_scan) Aggressive Web Exploit Scan 20.52.217.208 (DE/Germany/-): 5 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 20.52.217.208 - - [31/Jul/2026:12:47:48 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 404 808 "-" "-"
20.52.217.208 - - [31/Jul/2026:12:47:48 +0300] "GET /this_is_a_new_hello_world.php HTTP/1.1" 404 808 "-" "-"
20.52.217.208 - - [31/Jul/2026:12:47:48 +0300] "GET /3PJcpMFsD8B.php HTTP/1.1" 404 808 "-" "-"
20.52.217.208 - - [31/Jul/2026:12:47:48 +0300] "GET /err.php HTTP/1.1" 404 808 "-" "-"
20.52.217.208 - - [31/Jul/2026:12:47:48 +0300] "GET /img.php HTTP/1.1" 404 808 "-" "-"
show less
Port Scan
๐บ๐ฆ
URAN Publishing Service
2026-07-31 09:39:41
(50 minutes ago)
20.52.217.208 - - [31/Jul/2026:12:39:38 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.ph ...
show more
20.52.217.208 - - [31/Jul/2026:12:39:38 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 404 251 "-" "-"
...
show less
Web App Attack
๐ฌ๐ง
Greg Poulson
2026-07-31 09:38:38
(51 minutes ago)
Our website was hit by this DDOS at a rate of 60 in 5 minutes.
DDoS Attack
Web Spam
Brute-Force