๐ฉ๐ช
Vegascosmetics
2025-04-12 21:53:13
(1 year ago)
Kingcopy(AI-IDS): IP is wandering around the site and acting suspiciously.
Bad Web Bot
๐น๐ท
rtbh.com.tr
2025-04-12 20:06:03
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ฌ๐ง
openstrike.co.uk
2025-04-12 05:13:04
(1 year ago)
13 attacks on Alfa URLs:
GET /wp-includes/ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1
Hacking
๐บ๐ธ
octageeks.com
2025-04-12 04:06:43
(1 year ago)
Wordpress malicious attack:[octa404]
Web App Attack
๐น๐ท
rtbh.com.tr
2025-04-12 00:06:03
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ฉ๐ช
SpaceHost-Server
2025-04-11 22:30:06
(1 year ago)
Brute-Force
Web App Attack
๐ฉ๐ช
Vegascosmetics
2025-04-11 21:50:57
(1 year ago)
Kingcopy(AI-IDS):IP is Probing for Wordpress vulnerabilities WTF:Banned
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
AttackReport
2025-04-11 21:03:00
(1 year ago)
More than 500 invalid URL attacks.
DDoS Attack
๐น๐ท
rtbh.com.tr
2025-04-11 20:06:03
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
Anonymous
2025-04-11 13:06:04
(1 year ago)
35.178.5.253 - - [11/Apr/2025:15:05:59 +0200] "GET /sts.php HTTP/1.1" 404 4842 "-" "-"
35.178.5.253 ...
show more
35.178.5.253 - - [11/Apr/2025:15:05:59 +0200] "GET /sts.php HTTP/1.1" 404 4842 "-" "-"
35.178.5.253 - - [11/Apr/2025:15:05:59 +0200] "GET /wp-hoard.php HTTP/1.1" 404 305 "-" "-"
35.178.5.253 - - [11/Apr/2025:15:06:00 +0200] "GET /wp-l0gin.php HTTP/1.1" 404 305 "-" "-"
35.178.5.253 - - [11/Apr/2025:15:06:00 +0200] "GET /priv8.php HTTP/1.1" 404 305 "-" "-"
35.178.5.253 - - [11/Apr/2025:15:06:00 +0200] "GET /wp-post-editor.php HTTP/1.1" 404 305 "-" "-"
35.178.5.253 - - [11/Apr/2025:15:06:00 +0200] "GET /404.php HTTP/1.1" 404 305 "-" "-"
35.178.5.253 - - [11/Apr/2025:15:06:00 +0200] "GET /users.php HTTP/1.1" 404 305 "-" "-"
35.178.5.253 - - [11/Apr/2025:15:06:00 +0200] "GET /classwithtostring.php HTTP/1.1" 404 305 "-" "-"
35.178.5.253 - - [11/Apr/2025:15:06:00 +0200] "GET /wp-head.php HTTP/1.1" 404 305 "-" "-"
35.178.5.253 - - [11/Apr/2025:15:06:00 +0200] "GET /admin.php HTTP/1.1" 404 305 "-" "-"
35.178.5.253 - - [11/Apr/2025:15:06:00 +0200] "GET /about.php HTTP/1.1" 404 305 "-" "-"
35.178
...
show less
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-04-11 13:01:56
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 35.178.5.253 (ec2-35-178-5-253.eu-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 35.178.5.253 (ec2-35-178-5-253.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 11 09:01:50.228695 2025] [security2:error] [pid 1046117:tid 1046117] [client 35.178.5.253:62670] [client 35.178.5.253] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.eatthewrench.com"] [uri "/wp-includes/css/wp-config.php"] [unique_id "Z_kSvla2OB_ELsBRGgHH-QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-11 08:50:09
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 35.178.5.253 (ec2-35-178-5-253.eu-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 35.178.5.253 (ec2-35-178-5-253.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 11 04:50:04.340255 2025] [security2:error] [pid 147920:tid 147920] [client 35.178.5.253:57640] [client 35.178.5.253] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.webabri.com"] [uri "/wp-includes/css/wp-config.php"] [unique_id "Z_jXvOZR43mtzLzL2BtYTAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-11 08:17:54
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 35.178.5.253 (ec2-35-178-5-253.eu-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 35.178.5.253 (ec2-35-178-5-253.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 11 04:17:50.614472 2025] [security2:error] [pid 10595:tid 10595] [client 35.178.5.253:55994] [client 35.178.5.253] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "roguetechtalks.com"] [uri "/wp-includes/css/wp-config.php"] [unique_id "Z_jQLrlkraLr29_nW9--MQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2025-04-11 08:01:04
(1 year ago)
35.178.5.253 - - [11/Apr/2025:07:57:06 +0000] "GET /mailer.php HTTP/1.1" 404 64154 "-" rt="0.892" "- ...
show more
35.178.5.253 - - [11/Apr/2025:07:57:06 +0000] "GET /mailer.php HTTP/1.1" 404 64154 "-" rt="0.892" "-" "-" h="tuforodebolsa.com" sn="tuforodebolsa.com" ru="/mailer.php" u="/index.php" ucs="-" ua="unix:/var/run/php/tuforodebolsa82.sock" us="404" uct="0.000" urt="0.891"
35.178.5.253 - - [11/Apr/2025:07:57:35 +0000] "GET /wp-admin.php HTTP/1.1" 404 64154 "-" rt="2.256" "-" "-" h="tuforodebolsa.com" sn="tuforodebolsa.com" ru="/wp-admin.php" u="/index.php" ucs="-" ua="unix:/var/run/php/tuforodebolsa82.sock" us="404" uct="0.000" urt="2.256"
35.178.5.253 - - [11/Apr/2025:07:57:06 +0000] "GET /mailer.php HTTP/1.1" 404 64154 "-" "-" "-"
35.178.5.253 - - [11/Apr/2025:07:57:35 +0000] "GET /wp-admin.php HTTP/1.1" 404 64154 "-" "-" "-"
35.178.5.253 - - [11/Apr/2025:08:00:53 +0000] "GET /mailer1.php HTTP/1.1" 404 64154 "-" rt="0.687" "-" "-" h="tuforodebolsa.com" sn="tuforodebolsa.com" ru="/mailer1.php" u="/index.php" ucs="-" ua="unix:/var/run/php/tuforodebolsa82.sock" us="404" uct="0.000" urt="0.687
...
show less
Bad Web Bot
๐ฆ๐บ
clapper
2025-04-11 07:17:14
(1 year ago)
35.178.5.253 (GB/United Kingdom/ec2-35-178-5-253.eu-west-2.compute.amazonaws.com), more than 200 Apa ...
show more
35.178.5.253 (GB/United Kingdom/ec2-35-178-5-253.eu-west-2.compute.amazonaws.com), more than 200 Apache 404 hits in the last 3600 secs; ID: Dan
show less
Brute-Force
Bad Web Bot