SoliWeb
07 Apr 2021
GET /wp-login.php
Brute-Force
Web App Attack
rakkor
31 Mar 2021
2020/12/28 17:59:28 [error] 17307#17307: *87606 FastCGI sent in stderr: "Primary script unknown" whi ... show more 2020/12/28 17:59:28 [error] 17307#17307: *87606 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 51.79.140.161, server: , request: "GET /wp-login.php HTTP/1.1", upstream: "fastcgi://unix:/run/php-fpm/php-fdf1d4a0-1ee6-4ddf-8a4a-bf7184d3fc60.sock:", host: "rakkor.uk" show less
Brute-Force
Web App Attack
rakkor
28 Mar 2021
2020/12/28 17:59:28 [error] 17307#17307: *87606 FastCGI sent in stderr: "Primary script unknown" whi ... show more 2020/12/28 17:59:28 [error] 17307#17307: *87606 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 51.79.140.161, server: , request: "GET /wp-login.php HTTP/1.1", upstream: "fastcgi://unix:/run/php-fpm/php-fdf1d4a0-1ee6-4ddf-8a4a-bf7184d3fc60.sock:", host: "rakkor.uk" show less
Brute-Force
Web App Attack
pusathosting.com
12 Mar 2021
pusattra 51.79.140.161 [04/Mar/2021:20:05:17 "-" "POST /wp-login.php 200 8366
51.79.140.161 [0 ... show more pusattra 51.79.140.161 [04/Mar/2021:20:05:17 "-" "POST /wp-login.php 200 8366
51.79.140.161 [04/Mar/2021:20:05:18 "-" "GET /wp-login.php 200 8366
51.79.140.161 [04/Mar/2021:20:05:18 "-" "POST /wp-login.php 200 8366 show less
Brute-Force
Web App Attack
computerdoc
11 Mar 2021
xmlrpc attack
DDoS Attack
Web App Attack
bsoft.de
11 Mar 2021
51.79.140.161 - - [11/Mar/2021:23:26:58 +0100] "GET /wp-login.php HTTP/1.1" 200 9260 "-" "Mozilla/5. ... show more 51.79.140.161 - - [11/Mar/2021:23:26:58 +0100] "GET /wp-login.php HTTP/1.1" 200 9260 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
51.79.140.161 - - [11/Mar/2021:23:27:01 +0100] "POST /wp-login.php HTTP/1.1" 200 9511 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
51.79.140.161 - - [11/Mar/2021:23:27:03 +0100] "POST /xmlrpc.php HTTP/1.1" 200 427 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" show less
Web App Attack
sololinux.es
11 Mar 2021
51.79.140.161 - - [11/Mar/2021:21:41:08 +0100] "POST /wp-login.php HTTP/1.0" 200 5078 "-" "Mozilla/5 ... show more 51.79.140.161 - - [11/Mar/2021:21:41:08 +0100] "POST /wp-login.php HTTP/1.0" 200 5078 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
... show less
Brute-Force
Web App Attack
emha.koeln
11 Mar 2021
v2202006123119120844 51.79.140.161 - - [11/Mar/2021:21:24:36 +0100] "POST /wp-login.php HTTP/1.1" 20 ... show more v2202006123119120844 51.79.140.161 - - [11/Mar/2021:21:24:36 +0100] "POST /wp-login.php HTTP/1.1" 200 - "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
v2202006123119120844 51.79.140.161 - - [11/Mar/2021:21:24:37 +0100] "POST /wp-login.php HTTP/1.1" 200 - "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
v2202006123119120844 51.79.140.161 - - [11/Mar/2021:21:24:39 +0100] "POST /wp-login.php HTTP/1.1" 200 - "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" show less
Brute-Force
Web App Attack
www.elinox.de
11 Mar 2021
11.03.2021 18:16:20 - Wordpress fail
Detected by ELinOX-ALM
Hacking
Web App Attack
bsoft.de
11 Mar 2021
51.79.140.161 - - [11/Mar/2021:09:27:51 +0100] "GET /wp-login.php HTTP/1.1" 200 9260 "-" "Mozilla/5. ... show more 51.79.140.161 - - [11/Mar/2021:09:27:51 +0100] "GET /wp-login.php HTTP/1.1" 200 9260 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
51.79.140.161 - - [11/Mar/2021:09:27:53 +0100] "POST /wp-login.php HTTP/1.1" 200 9511 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
51.79.140.161 - - [11/Mar/2021:09:27:55 +0100] "POST /xmlrpc.php HTTP/1.1" 200 427 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" show less
Web App Attack
pusathosting.com
11 Mar 2021
pusattra 51.79.140.161 [04/Mar/2021:20:05:17 "-" "POST /wp-login.php 200 8366
51.79.140.161 [0 ... show more pusattra 51.79.140.161 [04/Mar/2021:20:05:17 "-" "POST /wp-login.php 200 8366
51.79.140.161 [04/Mar/2021:20:05:18 "-" "GET /wp-login.php 200 8366
51.79.140.161 [04/Mar/2021:20:05:18 "-" "POST /wp-login.php 200 8366 show less
Brute-Force
Web App Attack
cerberusinformatica
10 Mar 2021
51.79.140.161 - - [11/Mar/2021:02:12:42 +0100] "POST /wp-login.php HTTP/1.1" 200 2186 "-" "Mozilla/5 ... show more 51.79.140.161 - - [11/Mar/2021:02:12:42 +0100] "POST /wp-login.php HTTP/1.1" 200 2186 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
51.79.140.161 - - [11/Mar/2021:02:12:45 +0100] "POST /wp-login.php HTTP/1.1" 200 2171 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
51.79.140.161 - - [11/Mar/2021:02:12:47 +0100] "POST /wp-login.php HTTP/1.1" 200 2171 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
... show less
Web App Attack
sdos.es
10 Mar 2021
"XSS Attack Detected via libinjection - Matched Data: XSS data found within ARGS_NAMES:<?xml version ... show more "XSS Attack Detected via libinjection - Matched Data: XSS data found within ARGS_NAMES:<?xml version: <?xml version" show less
Web App Attack
ManagedStack
09 Mar 2021
Unauthorized path/IP Access (full log not revealed as it contains sensitive data)
Hacking
Web App Attack
dwmp
09 Mar 2021
Url probing: /wp-login.php
Web App Attack