๐น๐ท
ycoskun41
2026-08-28 19:39:19
(2 minutes ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-08-28 19:37:40
(4 minutes ago)
angleseaarthouse.com.au:443 52.138.0.157 - - [29/Aug/2026:05:37:38 +1000] "GET /admin.php HTTP/1.1" ...
show more
angleseaarthouse.com.au:443 52.138.0.157 - - [29/Aug/2026:05:37:38 +1000] "GET /admin.php HTTP/1.1" 404 71715 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
cwytech
2026-08-28 19:37:33
(4 minutes ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: crowdsecurity/http-backdoors-attempts.
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-08-28 19:37:00
(5 minutes ago)
2026/08/28 19:36:55 [error] 3672840#3672840: *531193881 access forbidden by rule, client: 52.138.0.1 ...
show more
2026/08/28 19:36:55 [error] 3672840#3672840: *531193881 access forbidden by rule, client: 52.138.0.157, server: binixo.mx, request: "GET /admin.php HTTP/1.1", host: "binixo.mx"
2026/08/28 19:36:58 [error] 3672840#3672840: *531193881 access forbidden by rule, client: 52.138.0.157, server: binixo.mx, request: "GET /xmlrpc.php HTTP/1.1", host: "binixo.mx"
2026/08/28 19:36:59 [error] 3672840#3672840: *531193881 access forbidden by rule, client: 52.138.0.157, server: binixo.mx, request: "GET /wp-admin.php HTTP/1.1", host: "binixo.mx"
...
show less
Web App Attack
๐ฎ๐น
Inartis
2026-08-28 19:36:56
(5 minutes ago)
52.138.0.157 - - [28/Aug/2026:21:36:52 +0200] "GET /setup-config.php HTTP/1.1" 404 41611 "-" "Mozill ...
show more
52.138.0.157 - - [28/Aug/2026:21:36:52 +0200] "GET /setup-config.php HTTP/1.1" 404 41611 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
52.138.0.157 - - [28/Aug/2026:21:36:52 +0200] "GET /setup.php HTTP/1.1" 404 41611 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
52.138.0.157 - - [28/Aug/2026:21:36:54 +0200] "GET /shell.php HTTP/1.1" 404 41611 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
mondor.ro
2026-08-28 19:33:02
(9 minutes ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, TEMPDENY 52.138.0.157, Reas ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, TEMPDENY 52.138.0.157, Reason:[52.138.0.157 (CA/Canada/-), more than 60 Apache 404 hits in the last 3600 secs]; Ports: 80,443; Direction: in; Trigger: LF_CLUSTER; Logs:
show less
Port Scan
๐ช๐ธ
netfactotum
2026-08-28 19:29:51
(12 minutes ago)
Hacking
Web App Attack
๐ซ๐ฎ
albionfreemarket.com
2026-08-28 19:29:02
(13 minutes ago)
52.138.0.157 - - [28/Aug/2026:19:29:00 +0000] "GET /autoload_classmap.php HTTP/2.0" 403 555 "-" "Moz ...
show more
52.138.0.157 - - [28/Aug/2026:19:29:00 +0000] "GET /autoload_classmap.php HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 0.000 "-" "CA"
52.138.0.157 - - [28/Aug/2026:19:29:00 +0000] "GET /classwithtostring.php HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 0.000 "-" "CA"
...
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-28 19:22:05
(20 minutes ago)
CloudLinux/Plesk alert - host=cloudlinux dominio=tubopress.it ip=52.138.0.157 richieste=235 rischio= ...
show more
CloudLinux/Plesk alert - host=cloudlinux dominio=tubopress.it ip=52.138.0.157 richieste=235 rischio=ALTO score=16 motivi=molte_richieste,molte_uri_uniche,molti_404,path_sospetti,poco_statico,dinamico cat_id=21,19 periodo=10min
show less
Web App Attack
Bad Web Bot
๐ต๐ฑ
strefapi_com
2026-08-28 19:20:37
(21 minutes ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
Anonymous
2026-08-28 19:18:12
(23 minutes ago)
52.138.0.157 - - [28/Aug/2026:21:18:12 +0200] "GET / HTTP/1.1" 404 56 "-" "Mozilla/5.0 (Windows NT 1 ...
show more
52.138.0.157 - - [28/Aug/2026:21:18:12 +0200] "GET / HTTP/1.1" 404 56 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฉ๐ฐ
donkzquixote
2026-08-28 19:18:05
(24 minutes ago)
Scan for exploitable WordPress files/information, or other brute force attempts.
Web App Attack
Brute-Force
๐ฉ๐ช
dbmwebdesign
2026-08-28 19:15:04
(27 minutes ago)
Repeated probing for non-existent PHP exploit paths blocked by Fail2Ban
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-28 19:10:49
(31 minutes ago)
[28/Aug/2026:22:10:49 +0300] -- 52.138.0.157 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-20 ...
show more
[28/Aug/2026:22:10:49 +0300] -- 52.138.0.157 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-2019.php HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Selckie
2026-08-28 19:10:24
(31 minutes ago)
fail2ban: NGINX unusual impact
Web App Attack