๐ณ๐ฑ
Alt255
2026-09-14 05:29:09
(1 day ago)
[ti-22al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-22al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 216.126.227.88 - - [14/Sep/2026:07:29:09 +0200] "GET /.git/HEAD HTTP/1.1" 404 12722 "https://nullauna.com/.git/HEAD" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-14 05:12:37
(1 day ago)
[14/Sep/2026:08:12:36 +0300] -- 216.126.227.88 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[14/Sep/2026:08:12:36 +0300] -- 216.126.227.88 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/HEAD HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-14 05:10:48
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/HEAD | 2026-09-14 05:10 UTC
show less
Hacking
Web App Attack
๐ง๐ช
voormedia
2026-09-14 05:09:35
(1 day ago)
Accessed trap at '/.git/HEAD'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 05:05:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 216.126.227.88 (88.227.126.216.static.cloudzy.c ...
show more
(mod_security) mod_security (id:210492) triggered by 216.126.227.88 (88.227.126.216.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 01:05:00.164082 2026] [security2:error] [pid 14273:tid 14273] [client 216.126.227.88:36516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eworld-media.com"] [uri "/.git/HEAD"] [unique_id "aqeAfI5RyD_HciN0fXPRuAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-14 04:27:01
(1 day ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 216.126.227.88 - - [14/Sep/2026:06:27:00 +0200] "GET /.git/HEAD HTTP/1.1" 404 72881 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-14 04:15:02
(1 day ago)
suspicious request in access.log
Web App Attack
๐ซ๐ฎ
6kilowatti
2026-09-14 04:10:42
(1 day ago)
216.126.227.88 - - [14/Sep/2026:07:10:41 +0300] "GET /.git/HEAD HTTP/1.1" 404 41 "-" "Mozilla/5.0 (W ...
show more
216.126.227.88 - - [14/Sep/2026:07:10:41 +0300] "GET /.git/HEAD HTTP/1.1" 404 41 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฆ๐บ
A.i.D.A.N.N
2026-09-14 02:57:39
(1 day ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web application attack detected
Web App Attack
Anonymous
2026-09-14 02:27:24
(1 day ago)
[ns67.kdns.gr] httpd-config-scan: sites=troupakisaccounting.gr; logs=/var/www/vhosts/system/troupaki ...
show more
[ns67.kdns.gr] httpd-config-scan: sites=troupakisaccounting.gr; logs=/var/www/vhosts/system/troupakisaccounting.gr/logs/access_ssl_log,/var/www/vhosts/troupakisaccounting.gr/logs/access_ssl_log; samples=/.git
show less
Hacking
Web App Attack
Anonymous
2026-09-06 02:17:13
(1 week ago)
Attack detected: 216.126.227.88 [2026-09-06]
Categories: 21
--- wp2shell/batch exploit (3 hits) ---
...
show more
Attack detected: 216.126.227.88 [2026-09-06]
Categories: 21
--- wp2shell/batch exploit (3 hits) ---
216.126.227.88 - - [22/Jul/2026:17:40:02 +0000] "POST /wp-json/batch/v1 HTTP/1.1" 207 4743 "-" "wp2shell"
216.126.227.88 - - [22/Jul/2026:17:40:05 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 4744 "-" "wp2shell"
216.126.227.88 - - [22/Jul/2026:17:40:08 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 500 6492 "-" "wp2shell"
show less
Web App Attack
Anonymous
2026-08-22 02:14:57
(3 weeks ago)
Attack detected: 216.126.227.88 [2026-08-22]
Categories: 21
--- wp2shell/batch exploit (3 hits) ---
...
show more
Attack detected: 216.126.227.88 [2026-08-22]
Categories: 21
--- wp2shell/batch exploit (3 hits) ---
216.126.227.88 - - [22/Jul/2026:17:40:02 +0000] "POST /wp-json/batch/v1 HTTP/1.1" 207 4743 "-" "wp2shell"
216.126.227.88 - - [22/Jul/2026:17:40:05 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 4744 "-" "wp2shell"
216.126.227.88 - - [22/Jul/2026:17:40:08 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 500 6492 "-" "wp2shell"
show less
Web App Attack
Anonymous
2026-08-07 02:02:06
(1 month ago)
Attack detected: 216.126.227.88 [2026-08-07]
Categories: 21
--- wp2shell/batch exploit (3 hits) ---
...
show more
Attack detected: 216.126.227.88 [2026-08-07]
Categories: 21
--- wp2shell/batch exploit (3 hits) ---
216.126.227.88 - - [22/Jul/2026:17:40:02 +0000] "POST /wp-json/batch/v1 HTTP/1.1" 207 4743 "-" "wp2shell"
216.126.227.88 - - [22/Jul/2026:17:40:05 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 4744 "-" "wp2shell"
216.126.227.88 - - [22/Jul/2026:17:40:08 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 500 6492 "-" "wp2shell"
show less
Web App Attack
๐ฉ๐ช
yitzhaq
2026-07-24 22:51:32
(1 month ago)
wp2shell unauthenticated WordPress RCE: CVE-2026-63030 (REST /wp-json/batch/v1 route confusion) chai ...
show more
wp2shell unauthenticated WordPress RCE: CVE-2026-63030 (REST /wp-json/batch/v1 route confusion) chained with CVE-2026-60137 (WP_Query SQLi). 1 successful HTTP 207 exploit POST(s) to /wp-json/batch/v1 (& /?rest_route=/batch/v1) against our WordPress hosts, 2026-07-22T16:33:02Z..2026-07-22T16:33:02Z UTC. Apache access-log evidence (our hostname/domains redacted):
216.126.227.88 - - [22/Jul/2026:18:33:02 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 230530 "-" "wp2shell"
show less
Hacking
Web App Attack
SQL Injection
Anonymous
2026-07-23 00:51:06
(1 month ago)
Attack detected: 216.126.227.88 [2026-07-23]
Categories: 21
--- wp2shell/batch exploit (3 hits) ---
...
show more
Attack detected: 216.126.227.88 [2026-07-23]
Categories: 21
--- wp2shell/batch exploit (3 hits) ---
216.126.227.88 - - [22/Jul/2026:17:40:02 +0000] "POST /wp-json/batch/v1 HTTP/1.1" 207 4743 "-" "wp2shell"
216.126.227.88 - - [22/Jul/2026:17:40:05 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 4744 "-" "wp2shell"
216.126.227.88 - - [22/Jul/2026:17:40:08 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 500 6492 "-" "wp2shell"
show less
Web App Attack