Villanelle
14 Nov 2022
GET /wp-content/themes/seotheme/mar.php HTTP/1.1, GET /wp-includes/wp-class.php HTTP/1.1, GET /wp-ad ... show more GET /wp-content/themes/seotheme/mar.php HTTP/1.1, GET /wp-includes/wp-class.php HTTP/1.1, GET /wp-admin/shell20211028.php HTTP/1.1, ET /wp-content/wso.php HTTP/1.1 www.google.com Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36 show less
Hacking
Web App Attack
mawan
13 Nov 2022
Suspected of having performed illicit activity on AMS server.
Web App Attack
eminovic.ba
13 Nov 2022
BRUTE FORCE: Excessive 404 hits
...
Hacking
Brute-Force
Web App Attack
0xffffffff
13 Nov 2022
[2022-11-14 03:53:47.992162] [authz_core:error] [pid 3513602:tid 139986274342656] [client 5.75.164.2 ... show more [2022-11-14 03:53:47.992162] [authz_core:error] [pid 3513602:tid 139986274342656] [client 5.75.164.241:0] AH01630: client denied by server configuration: /home*public_html/wp-content/themes/seotheme, referer www.google.com , error_notes:wp-exploit:subdir-php , URI:'/wp-content/themes/seotheme/mar.php' show less
Bad Web Bot
Web App Attack
Anonymous
13 Nov 2022
5.75.164.241 - - [13/Nov/2022:23:54:00 +0100] "GET /wp-content/themes/seotheme/mar.php HTTP/1.1" 404 ... show more 5.75.164.241 - - [13/Nov/2022:23:54:00 +0100] "GET /wp-content/themes/seotheme/mar.php HTTP/1.1" 404 5913 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
5.75.164.241 - - [13/Nov/2022:23:54:04 +0100] "GET /wp-content/themes/seotheme/mar.php HTTP/1.1" 404 5913 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
5.75.164.241 - - [13/Nov/2022:23:54:10 +0100] "GET /wp-includes/wp-class.php HTTP/1.1" 404 4870 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
5.75.164.241 - - [13/Nov/2022:23:54:13 +0100] "GET /wp-includes/wp-class.php HTTP/1.1" 404 4870 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) Ap
... show less
Hacking
Bad Web Bot
netfactotum
13 Nov 2022
Hacking
Bad Web Bot
Exploited Host
Web App Attack
webbfabriken
13 Nov 2022
Attack reported by Webbfabiken Security API - WFSecAPI
Brute-Force
MortimerCat
13 Nov 2022
Attempting to find insecure Wordpress folders
Web App Attack
Hirte
13 Nov 2022
PHI: Web Attack GET /wp-content/themes/seotheme/mar.php
Web Spam
Hacking
Bad Web Bot
Web App Attack
jasperedv.de
13 Nov 2022
Apache Login - Brutforcing
Brute-Force
Web App Attack
Villanelle
13 Nov 2022
GET /wp-content/themes/seotheme/mar.php HTTP/1.1, GET /wp-content/wso.php HTTP/1.1 www.google.co ... show more GET /wp-content/themes/seotheme/mar.php HTTP/1.1, GET /wp-content/wso.php HTTP/1.1 www.google.com Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36 show less
Hacking
Web App Attack
eminovic.ba
12 Nov 2022
BRUTE FORCE: Excessive 404 hits
...
Hacking
Brute-Force
Web App Attack
plzenskypruvodce.cz
12 Nov 2022
[Sat Nov 12 20:12:56.378441 2022] [authz_core:error] [pid 887293:tid 140262550529792] [client 5.75.1 ... show more [Sat Nov 12 20:12:56.378441 2022] [authz_core:error] [pid 887293:tid 140262550529792] [client 5.75.164.241:51866] AH01630: client denied by server configuration: /var/www/lubosluka.com/www/wp-content/wso.php, referer: www.google.com
[Sat Nov 12 20:12:59.928968 2022] [authz_core:error] [pid 887293:tid 140262424639232] [client 5.75.164.241:53884] AH01630: client denied by server configuration: /var/www/lubosluka.com/www/wp-content/wso.php, referer: www.google.com
... show less
Web App Attack
expandmade.com
12 Nov 2022
trolling for installation vulnerabilities [12/Nov/2022:17:08:31 "GET /wp-content/themes/seotheme/mar ... show more trolling for installation vulnerabilities [12/Nov/2022:17:08:31 "GET /wp-content/themes/seotheme/mar.php"] show less
Web App Attack
0xffffffff
12 Nov 2022
[2022-11-12 17:54:00.388753] [authz_core:error] [pid 2615666:tid 139986442262272] [client 5.75.164.2 ... show more [2022-11-12 17:54:00.388753] [authz_core:error] [pid 2615666:tid 139986442262272] [client 5.75.164.241:0] AH01630: client denied by server configuration: /home*public_html/wp-content/themes/seotheme, referer www.google.com , error_notes:wp-exploit:subdir-php , URI:'/wp-content/themes/seotheme/mar.php'
[2022-11-12 17:54:05.651005] [authz_core:error] [pid 2860761:tid 139986274342656] [client 5.75.164.241:0] AH01630: client denied by server configuration: /home*public_html/wp-content/themes/seotheme, referer www.google.com , error_notes:wp-exploit:subdir-php , URI:'/wp-content/themes/seotheme/mar.php'
[2022-11-12 17:54:05.651005] [authz_core:error] [pid 2860761:tid 139986274342656] [client 5.75.164.241:0] AH01630: client denied by server configuration: /home*public_html/wp-content/themes/seotheme, referer www.google.com , error_notes:wp-exploit:subdir-php , URI:'/wp-content/themes/seotheme/mar.php' show less
Bad Web Bot
Web App Attack