π©πͺ
LRob
2026-06-28 11:30:12
(2 months ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
ππΊ
bcsaba
2026-06-28 11:30:02
(2 months ago)
Looking for WP FILEMANAGER
52.141.57.167 - - [28/Jun/2026:13:29:59 +0200] "GET /wp-content/plugins/h ...
show more
Looking for WP FILEMANAGER
52.141.57.167 - - [28/Jun/2026:13:29:59 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 400 230 "-" "-"
show less
Web App Attack
π©πͺ
psauxit
2026-06-28 11:26:38
(2 months ago)
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrp ...
show more
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrpc_attack, wp-login brute force, excessive crawling/scraping
show less
Web App Attack
Hacking
Anonymous
2026-06-28 11:25:30
(2 months ago)
[Sun Jun 28 13:25:27.089660 2026] [proxy_fcgi:error] [pid 55603:tid 55645] [client 52.141.57.167:112 ...
show more
[Sun Jun 28 13:25:27.089660 2026] [proxy_fcgi:error] [pid 55603:tid 55645] [client 52.141.57.167:11241] AH01071: Got error 'Primary script unknown'
[Sun Jun 28 13:25:27.604050 2026] [proxy_fcgi:error] [pid 55603:tid 55644] [client 52.141.57.167:11241] AH01071: Got error 'Primary script unknown'
[Sun Jun 28 13:25:28.119597 2026] [proxy_fcgi:error] [pid 55603:tid 55642] [client 52.141.57.167:11241] AH01071: Got error 'Primary script unknown'
[Sun Jun 28 13:25:28.635322 2026] [proxy_fcgi:error] [pid 55603:tid 55649] [client 52.141.57.167:11241] AH01071: Got error 'Primary script unknown'
[Sun Jun 28 13:25:29.151092 2026] [proxy_fcgi:error] [pid 55603:tid 55650] [client 52.141.57.167:11241] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
πΊπΈ
Major Hostility
2026-06-28 11:25:27
(2 months ago)
"GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 404
"GET /this_is_a_new_hello_world ...
show more
"GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 404
"GET /this_is_a_new_hello_world.php HTTP/1.1" 404
"GET /x.php HTTP/1.1" 404
"GET /by.php HTTP/1.1" 404
"GET /cxs.php HTTP/1.1" 404
"GET /coffexium.php HTTP/1.1" 404
"GET /asdf.php HTTP/1.1" 404
"GET /red.php HTTP/1.1" 404
"GET /wp-admin/css/colors/coffee/wp-adochan.php HTTP/1.1" 404
"GET /footer.php HTTP/1.1" 404
"GET /images/ HTTP/1.1" 404
"GET /zoro.php HTTP/1.1" 404
"GET /wm.php HTTP/1.1" 404
"GET /bajah.php HTTP/1.1" 404
"GET /cream1.php HTTP/1.1" 404
"GET /lim.php HTTP/1.1" 404
"GET /heat3.php HTTP/1.1" 404
"GET /greap.php HTTP/1.1" 404
"GET /177.php HTTP/1.1" 404
"GET /199.php HTTP/1.1"
show less
Web App Attack
Anonymous
2026-06-28 11:25:04
(2 months ago)
IP banned by Fail2Ban
Brute-Force
SSH
π§πͺ
voormedia
2026-06-28 11:21:37
(2 months ago)
Accessed trap at '/admin.php'
Web App Attack
πΊπΈ
kosada.com
2026-06-28 11:21:17
(2 months ago)
Web vulnerability probing: /bajah.php
Web App Attack
π©πͺ
pscriptos
2026-06-28 11:20:21
(2 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-06-28 11:18:30
(2 months ago)
52.141.57.167 - - [28/Jun/2026:13:18:22 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.ph ...
show more
52.141.57.167 - - [28/Jun/2026:13:18:22 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 403 12583 "-" "-"
52.141.57.167 - - [28/Jun/2026:13:18:22 +0200] "GET /this_is_a_new_hello_world.php HTTP/1.1" 403 12583 "-" "-"
52.141.57.167 - - [28/Jun/2026:13:18:22 +0200] "GET /xyn.php HTTP/1.1" 403 12583 "-" "-"
52.141.57.167 - - [28/Jun/2026:13:18:23 +0200] "GET /5.php HTTP/1.1" 403 12583 "-" "-"
52.141.57.167 - - [28/Jun/2026:13:18:23 +0200] "GET /joomla.php HTTP/1.1" 403 12583 "-" "-"
52.141.57.167 - - [28/Jun/2026:13:18:23 +0200] "GET /w.php HTTP/1.1" 403 12583 "-" "-"
52.141.57.167 - - [28/Jun/2026:13:18:24 +0200] "GET /anisogamete.php HTTP/1.1" 403 12583 "-" "-"
52.141.57.167 - - [28/Jun/2026:13:18:24 +0200] "GET /as.php HTTP/1.1" 403 12583 "-" "-"
52.141.57.167 - - [28/Jun/2026:13:18:24 +0200] "GET /000.php HTTP/1.1" 403 12583 "-" "-"
52.141.57.167 - - [28/Jun/2026:13:18:25 +0200] "GET /hplfuns.php HTTP/1.1" 403 12583 "-" "-"
52.141.57.167 - - [28/Jun/2026:13:18:
...
show less
Bad Web Bot
Web App Attack
π¦πΉ
penguin-solutions.at
2026-06-28 11:16:21
(2 months ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
π§π¬
pa4080
2026-06-28 11:15:59
(2 months ago)
Detected by ModSecurity. Request URI: /wp-content/plugins/hellopress/wp_filemanager.php
Web App Attack
π«π·
masterguru
2026-06-28 11:15:29
(2 months ago)
Too much 404 requests in 1 minute. Operator GE matched 10 at IP:block_script. (46020-201)
Hacking
π©πͺ
Hary74656
2026-06-28 11:14:48
(2 months ago)
[Sun Jun 28 13:14:30.256355 2026] [core:info] [pid 167951:tid 168158] [client 52.141.57.167:60240] A ...
show more
[Sun Jun 28 13:14:30.256355 2026] [core:info] [pid 167951:tid 168158] [client 52.141.57.167:60240] AH00128: File does not exist: /home/harald/www/imagesearch/wp-content/admin.php
...
show less
Bad Web Bot
π¬π§
OptimusGO
2026-06-28 11:12:40
(2 months ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-28 12:12:40 UTC
Log evidence:
52.141.57.167 - - [28/Jun/2026:12:11:13 +0100] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 403 146 "-" "-"
52.141.57.167 - - [28/Jun/2026:12:11:14 +0100] "GET /this_is_a_new_hello_world.php HTTP/1.1" 403 146 "-" "-"
52.141.57.167 - - [28/Jun/2026:12:11:14 +0100] "GET /blurbs.php HTTP/1.1" 403 146 "-" "-"
show less
Port Scan
Brute-Force