๐ง๐ท
AC - Team
2022-11-24 22:55:50
(3 years ago)
34.66.33.58 - - [25/Nov/2022:00:55:46 -0300] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 404 304 ...
show more
34.66.33.58 - - [25/Nov/2022:00:55:46 -0300] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 404 30405 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Exploited Host
Web App Attack
๐ฉ๐ช
expandmade.com
2022-11-24 21:58:30
(3 years ago)
trolling for installation vulnerabilities [25/Nov/2022:02:58:30 "POST /wp-plain.php"]
Web App Attack
Anonymous
2022-11-24 21:37:46
(3 years ago)
Probing for vulnerable plugin directories and/or files
Hacking
Web App Attack
๐ณ๐ฑ
CryptoYakari
2022-11-24 14:28:58
(3 years ago)
34.66.33.58 - - [24/Nov/2022:22:28:47 +0300] "POST /wp-plain.php HTTP/1.0" 403 567 "www.google.com" ...
show more
34.66.33.58 - - [24/Nov/2022:22:28:47 +0300] "POST /wp-plain.php HTTP/1.0" 403 567 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
34.66.33.58 - - [24/Nov/2022:22:28:47 +0300] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.0" 403 568 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
34.66.33.58 - - [24/Nov/2022:22:28:47 +0300] "GET / HTTP/1.0" 403 568 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
๐ฉ๐ช
akcurate.de
2022-11-24 02:31:00
(3 years ago)
[Thu Nov 24 08:30:58.075643 2022] [proxy_fcgi:error] [pid 606632:tid 606784] [client 34.66.33.58:601 ...
show more
[Thu Nov 24 08:30:58.075643 2022] [proxy_fcgi:error] [pid 606632:tid 606784] [client 34.66.33.58:60139] AH01071: Got error 'Primary script unknown', referer: http://kirschmechanik.de//wp-2018.php
[Thu Nov 24 08:30:58.327794 2022] [proxy_fcgi:error] [pid 606632:tid 606776] [client 34.66.33.58:60139] AH01071: Got error 'Primary script unknown', referer: http://kirschmechanik.de//wp-2020.php
[Thu Nov 24 08:30:58.580125 2022] [proxy_fcgi:error] [pid 606632:tid 606789] [client 34.66.33.58:60139] AH01071: Got error 'Primary script unknown', referer: http://kirschmechanik.de//wp-2021.php
[Thu Nov 24 08:30:58.832816 2022] [proxy_fcgi:error] [pid 606632:tid 606798] [client 34.66.33.58:60139] AH01071: Got error 'Primary script unknown', referer: http://kirschmechanik.de//wp-2022.php
[Thu Nov 24 08:30:59.085734 2022] [proxy_fcgi:error] [pid 606632:tid 606792] [client 34.66.33.58:60139] AH01071: Got error 'Primary script unknown', referer: http://kirschmechanik.de//0z.php
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
lthde
2022-11-24 01:52:53
(3 years ago)
POST /index.php - BASE64-encoded injection - [POST:l = ZXJyb3JfcmVwb3J0aW5nKDApOyBlY2hvIHBocF91bmFtZ ...
show more
POST /index.php - BASE64-encoded injection - [POST:l = ZXJyb3JfcmVwb3J0aW5nKDApOyBlY2hvIHBocF91bmFtZSgpLiI8YnI+Ii5nZXRjd2QoKS4iPGJyPiI7IGlmKCRfR0VUWydGb3gnXSA9PSAnZDN3TDcnKXskc2F3MSA9ICRfRklMRVNbJ2ZpbGUnXVsndG1wX25hbWUnXTskc2F3MiA9ICRfRklMRVNbJ2Z...]
show less
Web App Attack
๐จ๐ฆ
mitsurugi
2022-11-23 08:33:25
(3 years ago)
Bad bot trolling for too many things.
Brute-Force
Web App Attack
๐ฉ๐ช
iNetWorker
2022-11-23 07:56:37
(3 years ago)
trolling for resource vulnerabilities
Web App Attack
๐ฉ๐ช
MarkGGN
2022-11-22 10:51:20
(3 years ago)
Webexploits. 34.66.33.58 - - [22/Nov/2022:16:51:19 +0100] "GET /wp-content/plugins/apikey/apikey.php ...
show more
Webexploits. 34.66.33.58 - - [22/Nov/2022:16:51:19 +0100] "GET /wp-content/plugins/apikey/apikey.php?test=hello HTTP/1.1" 404 548 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
34.66.33.58 - - [22/Nov/2022:16:51:20 +0100] "GET /wp-content/plugins/apikey/apikey.php.suspected?test=hello HTTP/1.1" 404 134822 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
AC - Team
2022-11-22 07:40:15
(3 years ago)
34.66.33.58 - - [22/Nov/2022:09:40:14 -0300] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 301 383 ...
show more
34.66.33.58 - - [22/Nov/2022:09:40:14 -0300] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 301 3836 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Exploited Host
Web App Attack
๐บ๐ธ
dtorrer
2022-11-21 22:30:04
(3 years ago)
This client attempted to login to an administrator account on a Website, or abused from another reso ...
show more
This client attempted to login to an administrator account on a Website, or abused from another resource.
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
tmiland
2022-11-21 21:27:11
(3 years ago)
(wordpress_404) WordPress Plugins Honeypot Trap 34.66.33.58 (US/United States/58.33.66.34.bc.googleu ...
show more
(wordpress_404) WordPress Plugins Honeypot Trap 34.66.33.58 (US/United States/58.33.66.34.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Blog Spam
Brute-Force
Web App Attack
Anonymous
2022-11-19 22:49:52
(3 years ago)
Malicious user-agents
Hacking
Brute-Force
Web App Attack
๐ซ๐ท
rellik
2022-11-19 19:43:00
(3 years ago)
Scanning CMS Criticals Files
Hacking
Web App Attack
๐ง๐ท
AC - Team
2022-11-19 16:39:16
(3 years ago)
34.66.33.58 - - [19/Nov/2022:18:38:56 -0300] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/2.0" 404 653 ...
show more
34.66.33.58 - - [19/Nov/2022:18:38:56 -0300] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/2.0" 404 6537 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Exploited Host
Web App Attack