๐ฉ๐ช
netclix.gr
2026-08-28 07:15:21
(1 day ago)
(PERMBLOCK) 52.162.202.106 (US/United States/-) has had more than 2 temp blocks in the last 604800 s ...
show more
(PERMBLOCK) 52.162.202.106 (US/United States/-) has had more than 2 temp blocks in the last 604800 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
๐ฉ๐ช
london2038.com
2026-08-28 05:10:56
(1 day ago)
Probing for exploits
52.162.202.106 - - [28/Aug/2026:07:10:52 +0200] "GET /wp-admin/css/admin.php HT ...
show more
Probing for exploits
52.162.202.106 - - [28/Aug/2026:07:10:52 +0200] "GET /wp-admin/css/admin.php HTTP/1.1" 301 169 "-" "Go-http-client/1.1"
52.162.202.106 - - [28/Aug/2026:07:10:54 +0200] "GET /wp-includes/PHPMailer/reading.php HTTP/1.1" 301 169 "-" "Go-http-client/1.1"
show less
Hacking
Web App Attack
๐ญ๐บ
DumaNet
2026-08-28 04:38:00
(1 day ago)
WordPress (CMS) attack attempts.
Date: 2026 Aug 27. 18:16:51
Source IP: 52.162.202.106
Portion ...
show more
WordPress (CMS) attack attempts.
Date: 2026 Aug 27. 18:16:51
Source IP: 52.162.202.106
Portion of the log(s):
52.162.202.106 - [27/Aug/2026:18:16:51 +0200] "GET /abcd.php HTTP/1.1" 404 153 "http://[removed].org/abcd.php" "Go-http-client/2.0"
52.162.202.106 - [27/Aug/2026:18:16:51 +0200] "GET /wp-admin/css/goods.php HTTP/1.1" 404 153 "http://[removed].org/wp-admin/css/goods.php" "Go-http-client/2.0"
52.162.202.106 - [27/Aug/2026:18:16:51 +0200] "GET /blurbs.php HTTP/1.1" 404 153 "http://[removed].org/blurbs.php#888xyz999" "Go-http-client/2.0"
52.162.202.106 - [27/Aug/2026:18:16:50 +0200] "GET /wp-content/goods.php HTTP/1.1" 404 153 "http://[removed].org/wp-content/goods.php" "Go-http-client/2.0"
52.162.202.106 - [27/Aug/2026:18:16:50 +0200] "GET /bless.php HTTP/1.1" 404 153 "http://[removed].org/bless.php#888xyz999" "Go-http-client/2.0"
52.162.202.106 - [27/Aug/2026:18:16:50 +0200] "GET /gifclass.php HTTP/1.1" 404 153 "http://[removed].org/gifclass.php#888xyz999" "Go-http-client/2.0"
show less
Web App Attack
Hacking
๐ฉ๐ช
Viveronese
2026-08-28 00:32:19
(1 day ago)
HTTP vulnerability scanning
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-27 23:59:07
(1 day ago)
[DC: IP:151.1.252.27] ntopng alert: blacklisted_client_contact
Hacking
๐ซ๐ท
pm33
2026-08-27 23:39:36
(1 day ago)
Excessive crawling HTTP 404
Web App Attack
๐ซ๐ท
tecnicorioja
2026-08-27 22:01:26
(1 day ago)
wp-login attack [27/Aug/2026:17:04:52
Brute-Force
Web App Attack
๐ฉ๐ช
Lino Project
2026-08-27 19:57:41
(1 day ago)
52.162.202.106 - - [27/Aug/2026:21:57:37 +0200] "GET /000.php HTTP/2.0" 404 64426 "http://millelibri ...
show more
52.162.202.106 - - [27/Aug/2026:21:57:37 +0200] "GET /000.php HTTP/2.0" 404 64426 "http://millelibriperbambini.it/000.php" "Go-http-client/2.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 19:30:44
(1 day ago)
(apache-useragents) Failed apache-useragents trigger with match [Go-http-client/1.1] from 52.162.202 ...
show more
(apache-useragents) Failed apache-useragents trigger with match [Go-http-client/1.1] from 52.162.202.106 (US/United States/-): 5 in the last 300 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 52.162.202.106 - - [27/Aug/2026:21:30:35 +0200] "GET / HTTP/1.1" 301 471 "http://wowsmoothies.eu/000.php" "Go-http-client/1.1"
52.162.202.106 - - [27/Aug/2026:21:30:35 +0200] "GET / HTTP/2.0" 200 34291 "http://www.wowsmoothies.nl" "Go-http-client/2.0"
52.162.202.106 - - [27/Aug/2026:21:30:39 +0200] "GET / HTTP/1.1" 301 471 "http://wowsmoothies.eu/chosen.php?p=" "Go-http-client/1.1"
52.162.202.106 - - [27/Aug/2026:21:30:39 +0200] "GET / HTTP/2.0" 200 33998 "http://www.wowsmoothies.nl" "Go-http-client/2.0"
52.162.202.106 - - [27/Aug/2026:21:30:42 +0200] "GET / HTTP/1.1" 301 471 "http://wowsmoothies.eu/wp-admin/css/admin.php" "Go-http-client/1.1"
show less
Port Scan
๐ฉ๐ช
todix
2026-08-27 19:18:02
(1 day ago)
Web App Attack Exploid from 52.162.202.106
Web App Attack
Anonymous
2026-08-27 17:55:11
(1 day ago)
Bot / seems abusive / Apache connections: 41
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2026-08-27 17:22:31
(1 day ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐ซ๐ฎ
6kilowatti
2026-08-27 17:00:33
(1 day ago)
2026/08/27 20:00:32 [error] 1948775#1948775: *13380 FastCGI sent in stderr: "Primary script unknown" ...
show more
2026/08/27 20:00:32 [error] 1948775#1948775: *13380 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 52.162.202.106, server: 6kw.fi, request: "GET /000.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/6kw.fi.sock:", host: "6kw.fi"
2026/08/27 20:00:32 [error] 1948775#1948775: *13380 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 52.162.202.106, server: 6kw.fi, request: "GET /chosen.php?p= HTTP/1.1", upstream: "fastcgi://unix:/var/run/6kw.fi.sock:", host: "6kw.fi"
...
show less
Web App Attack
๐ฉ๐ช
LRob
2026-08-27 16:51:28
(1 day ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-admin/css/admin.php (+3 more) | 2026-08-27 16:51 UTC
show less
Hacking
Web App Attack
๐ฉ๐ช
psauxit
2026-08-27 13:26:36
(1 day ago)
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrp ...
show more
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrpc_attack, wp-login brute force, excessive crawling/scraping
show less
Web App Attack
Hacking