๐น๐ญ
MWA SOC
2026-05-05 00:57:54
(4 weeks ago)
Hacking
Anonymous
2026-05-05 00:56:15
(4 weeks ago)
host-ipset-guard auto-report; server=ssd5.kdns.gr; rule=httpd-suspicious-path; count=7/6; duration=7 ...
show more
host-ipset-guard auto-report; server=ssd5.kdns.gr; rule=httpd-suspicious-path; count=7/6; duration=72h; scope=ssd5.kdns.gr; country=US; sites=e-anastasiadis.gr; samples=/wk/index.php | /inputs.php | /ioxi-o.php
show less
Hacking
Web App Attack
๐น๐ท
Detmach
2026-05-05 00:27:48
(4 weeks ago)
Security attack detected. Multiple failed attempts from 52.165.198.204. IP banned for 1440 minutes a ...
show more
Security attack detected. Multiple failed attempts from 52.165.198.204. IP banned for 1440 minutes at 5.05.2026 03:26:52. Failed attempts: 1
show less
Brute-Force
Anonymous
2026-05-05 00:19:55
(4 weeks ago)
Brute forcing Wordpress login
Hacking
Web App Attack
Anonymous
2026-05-05 00:10:53
(4 weeks ago)
52.165.198.204 - - [05/May/2026:02:10:50 +0200] "GET /wp-content/uploads/index.php HTTP/1.1" 404 186 ...
show more
52.165.198.204 - - [05/May/2026:02:10:50 +0200] "GET /wp-content/uploads/index.php HTTP/1.1" 404 186 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
52.165.198.204 - - [05/May/2026:02:10:51 +0200] "GET /wp-content/themes/hideo/network.php HTTP/1.1" 404 186 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
52.165.198.204 - - [05/May/2026:02:10:52 +0200] "GET /wp-includes/ HTTP/1.1" 404 186 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
52.165.198.204 - - [05/May/2026:02:10:53 +0200] "GET /wp-includes/Requests/src/Response/about.php HTTP/1.1" 404 186 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
52.165.198.204 - - [05/May/2026:02:10:53 +0200] "GET /wp-includes/html-api/ HTTP/1.1" 404 186 "-" "Mozilla/5.0 (Window
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
deskpass.com
2026-05-05 00:03:17
(4 weeks ago)
GET /file.php
Web App Attack
๐ณ๐ด
doofy
2026-05-05 00:02:59
(4 weeks ago)
[Tue May 05 02:02:18.143828 2026] [access_compat:error] [pid 1340547:tid 1340643] [client 52.165.198 ...
show more
[Tue May 05 02:02:18.143828 2026] [access_compat:error] [pid 1340547:tid 1340643] [client 52.165.198.204:5910] AH01797: client denied by server configuration: /www/famjohnsen.no/wp-content/uploads/index.php
[Tue May 05 02:02:59.497572 2026] [access_compat:error] [pid 1340547:tid 1340627] [client 52.165.198.204:5910] AH01797: client denied by server configuration: /www/famjohnsen.no/wp-content/uploads/index.php
[Tue May 05 02:02:59.497572 2026] [access_compat:error] [pid 1340547:tid 1340627] [client 52.165.198.204:5910] AH01797: client denied by server configuration: /www/famjohnsen.no/wp-content/uploads/index.php
[Tue May 05 02:02:59.635059 2026] [access_compat:error] [pid 1340547:tid 1340580] [client 52.165.198.204:5910] AH01797: client denied by server configuration: /www/famjohnsen.no/wp-content/themes/admin.php
...
show less
Brute-Force
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-05 00:01:52
(4 weeks ago)
Attempted access to sensitive endpoint (/wp-content/uploads/index.php) detected. Automated scan or u ...
show more
Attempted access to sensitive endpoint (/wp-content/uploads/index.php) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐บ๐ธ
Epimetheus
2026-05-04 23:57:01
(4 weeks ago)
Unauthorized access attempts:
[GET] /wp-includes/images/
[GET] /wp-includes/PHPMailer/
[GET] /wp-ad ...
show more
Unauthorized access attempts:
[GET] /wp-includes/images/
[GET] /wp-includes/PHPMailer/
[GET] /wp-admin/images/
[GET] /classwithtostring.php
[GET] /wp-includes/Requests/src/Response/about.php
[GET] /an.php
[GET] /abc.php
[GET] /themes.php
[GET] /wp-conf.php
[GET] /wp-trackback.php
[GET] /abcd.php
[GET] /xmlrpc.php
[GET] /wp-content/uploads/index.php
[GET] /ws.php
[GET] /wp-admin/user/index.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
show less
Web App Attack
๐ฉ๐ช
igerman
2026-05-04 23:43:13
(4 weeks ago)
caddy probes: admin-panel: GET /admin.php(DROP), GET /adminfuns.php(DROP) | web: GET /404.php(DROP), ...
show more
caddy probes: admin-panel: GET /admin.php(DROP), GET /adminfuns.php(DROP) | web: GET /404.php(DROP), GET /abc.php(DROP), GET /abcd.php(DROP), GET /about.php(DROP), GET /an.php(DROP), GET /as.php(DROP), GET /cache.php(DROP), GET /file.php(DROP), GET /function/function.php(DROP), GET /index/function.php(DROP), GET /inputs.php(DROP), GET /ioxi-o.php(DROP), GET /randkeyword.PhP7(DROP), GET /rip.php(DROP), GET /themes.php(DROP), GET /wk/index.php(DROP), GET /ws.php(DROP) | wordpress: GET /wp-admin/user/index.php(DROP), GET /wp-conf.php(DROP), GET /wp-content/themes/hideo/network.php(DROP), GET /wp-content/uploads/index.php(DROP), GET /wp-login.php(DROP), GET /wp-trackback.php(DROP)
show less
Web App Attack
๐ฎ๐น
VHosting
2026-05-04 23:40:03
(4 weeks ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
Epimetheus
2026-05-04 23:38:59
(4 weeks ago)
Zombie network / Bot scanner detected:
[GET] /info.php
[GET] /uploads/
[GET] /wp-content/themes/ind ...
show more
Zombie network / Bot scanner detected:
[GET] /info.php
[GET] /uploads/
[GET] /wp-content/themes/index.php
[GET] /wp-includes/
[GET] /wp-login.php
[GET] /file.php
[GET] /defaults.php
[GET] /wp-trackback.php
[GET] /rip.php
[GET] /index/function.php
[GET] /admin.php
[GET] /ws.php
[GET] /ioxi-o.php
[GET] /wp-content/themes/hideo/network.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
show less
Bad Web Bot
Exploited Host
Web App Attack
๐ณ๐ฟ
Antinson
2026-05-04 23:32:30
(4 weeks ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
๐ต๐ฑ
strefapi_com
2026-05-04 23:01:10
(4 weeks ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
macrob
2026-05-04 22:38:58
(4 weeks ago)
2026/05/04 22:38:55 [error] 4025868#4025868: *201092147 access forbidden by rule, client: 52.165.198 ...
show more
2026/05/04 22:38:55 [error] 4025868#4025868: *201092147 access forbidden by rule, client: 52.165.198.204, server: binixo.co, request: "GET /admin.php HTTP/1.1", host: "binixo.co"
2026/05/04 22:38:55 [error] 4025868#4025868: *201092147 access forbidden by rule, client: 52.165.198.204, server: binixo.co, request: "GET /wp-content/uploads/index.php HTTP/1.1", host: "binixo.co"
2026/05/04 22:38:56 [error] 4025868#4025868: *201092147 access forbidden by rule, client: 52.165.198.204, server: binixo.co, request: "GET /wp-admin/user/index.php HTTP/1.1", host: "binixo.co"
...
show less
Web App Attack