๐ฉ๐ช
yvoictra
2026-06-02 12:59:27
(2 days ago)
52.173.238.41 - - [02/Jun/2026:14:59:05 +0200] "GET /wp-content/themes/twenty/twenty.php HTTP/1.1" 4 ...
show more
52.173.238.41 - - [02/Jun/2026:14:59:05 +0200] "GET /wp-content/themes/twenty/twenty.php HTTP/1.1" 404 19 "-" "-"
52.173.238.41 - - [02/Jun/2026:14:59:05 +0200] "GET /wp-admin/images/cloud.php HTTP/1.1" 404 19 "-" "-"
52.173.238.41 - - [02/Jun/2026:14:59:05 +0200] "GET /wp-admin/css/about.php HTTP/1.1" 404 19 "-" "-"
52.173.238.41 - - [02/Jun/2026:14:59:06 +0200] "GET /wp-includes/customize/about.php HTTP/1.1" 404 19 "-" "-"
52.173.238.41 - - [02/Jun/2026:14:59:07 +0200] "GET /wp-includes/images/smilies/about.php HTTP/1.1" 404 19 "-" "-"
52.173.238.41 - - [02/Jun/2026:14:59:07 +0200] "GET /wp-includes/SimplePie/about.php HTTP/1.1" 404 19 "-" "-"
52.173.238.41 - - [02/Jun/2026:14:59:08 +0200] "GET /files.php HTTP/1.1" 404 19 "-" "-"
52.173.238.41 - - [02/Jun/2026:14:59:08 +0200] "GET /wp-includes/Text/index.php HTTP/1.1" 404 19 "-" "-"
52.173.238.41 - - [02/Jun/2026:14:59:08 +0200] "GET /wp-content/upgrade-temp-backup/about.php HTTP/1.1" 404 19 "-" "-"
52.173.238.41 - - [02/Jun/2026:14:
...
show less
Brute-Force
Web App Attack
๐ซ๐ฎ
stinpriza
2026-06-02 12:59:07
(2 days ago)
Web App Attack
Web App Attack
๐ช๐ธ
elcruzado.es
2026-06-02 12:58:22
(2 days ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 52.173.238.41 (US/United ...
show more
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 52.173.238.41 (US/United States/-)
show less
Port Scan
๐ช๐ธ
robotstxt
2026-06-02 12:57:27
(2 days ago)
52.173.238.41 - - [02/Jun/2026:12:57:03 +0000] "GET /wp-signup.php HTTP/1.1" 404 146 "-" "-" "-"
52. ...
show more
52.173.238.41 - - [02/Jun/2026:12:57:03 +0000] "GET /wp-signup.php HTTP/1.1" 404 146 "-" "-" "-"
52.173.238.41 - - [02/Jun/2026:12:57:15 +0000] "GET /wp-admin.php HTTP/1.1" 404 146 "-" "-" "-"
52.173.238.41 - - [02/Jun/2026:12:57:21 +0000] "GET /cgi-bin/xmrlpc.php HTTP/1.1" 404 146 "-" "-" "-"
52.173.238.41 - - [02/Jun/2026:12:57:26 +0000] "GET /cgi-bin/index.php HTTP/1.1" 404 146 "-" "-" "-"
52.173.238.41 - - [02/Jun/2026:12:57:27 +0000] "GET /wp-login.php HTTP/1.1" 404 146 "-" "-" "-"
...
show less
Bad Web Bot
๐ฉ๐ช
Petros Stefanakis
2026-06-02 12:49:28
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 52.173.238.41 (US/United States/-)
SQL Injection
๐ฉ๐ช
sdos.es
2026-06-02 12:47:49
(2 days ago)
"Restricted File Access Attempt - Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-con ...
show more
"Restricted File Access Attempt - Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-config.php"
show less
Web App Attack
๐บ๐ธ
masterguru
2026-06-02 12:45:42
(2 days ago)
Too much 404 requests in 1 hour. Operator GE matched 50 at IP:block_script. (4002-169)
Hacking
Web App Attack
๐ฉ๐ช
netclix.gr
2026-06-02 12:42:51
(2 days ago)
(aggressive_scan) Aggressive Web Exploit Scan 52.173.238.41 (US/United States/-): 5 in the last 4600 ...
show more
(aggressive_scan) Aggressive Web Exploit Scan 52.173.238.41 (US/United States/-): 5 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 52.173.238.41 - - [02/Jun/2026:15:41:44 +0300] "GET /.well-known/pki-validation/index.php HTTP/1.1" 404 146 "-" "-"
52.173.238.41 - - [02/Jun/2026:15:41:44 +0300] "GET /.well-known/acme-challenge/about.php HTTP/1.1" 404 146 "-" "-"
52.173.238.41 - - [02/Jun/2026:15:42:03 +0300] "GET /.well-known/acme-challenge/index.php HTTP/1.1" 404 146 "-" "-"
52.173.238.41 - - [02/Jun/2026:15:42:40 +0300] "GET /.well-known/pki-validation/xmrlpc.php HTTP/1.1" 404 146 "-" "-"
52.173.238.41 - - [02/Jun/2026:15:42:46 +0300] "GET /.well-known/pki-validation/about.php HTTP/1.1" 404 146 "-" "-"
show less
Port Scan
๐ฉ๐ช
dbmwebdesign
2026-06-02 12:40:28
(2 days ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐ฉ๐ช
ecs.ge
2026-06-02 12:39:00
(2 days ago)
Automatic Fail2Ban report from jail plesk-modsecurity: multiple matching events detected.
Web App Attack
Hacking
๐บ๐ธ
abenage
2026-06-02 12:35:33
(2 days ago)
52.173.238.41 - - [02/Jun/2026:06:35:32 -0600] "GET /wp-content/plugins/hellopress/wp_filemanager.ph ...
show more
52.173.238.41 - - [02/Jun/2026:06:35:32 -0600] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 404 162 "-" "-"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Operator873
2026-06-02 12:31:48
(2 days ago)
2026/06/02 06:06:06 [error] 2715722#0: *3588527 access forbidden by rule, client: 52.173.238.41, ser ...
show more
2026/06/02 06:06:06 [error] 2715722#0: *3588527 access forbidden by rule, client: 52.173.238.41, server: [OBFUSCATED], request: "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1", host: "cockpit.n5txl.com"
2026/06/02 06:06:06 [error] 2715722#0: *3588527 access forbidden by rule, client: 52.173.238.41, server: [OBFUSCATED], request: "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1", host: "cockpit.n5txl.com"
2026/06/02 07:31:36 [error] 2715722#0: *3591804 access forbidden by rule, client: 52.173.238.41, server: [OBFUSCATED], request: "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1", host: "pistar.n5txl.com"
2026/06/02 07:31:36 [error] 2715722#0: *3591804 access forbidden by rule, client: 52.173.238.41, server: [OBFUSCATED], request: "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1", host: "pistar.n5txl.com"
2026/06/02 07:31:46 [error] 2715722#0: *3591804 access forbidden by rule, client: 52.173.238.41, server: dns.8
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 12:29:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 52.173.238.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 52.173.238.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 08:29:42.557239 2026] [security2:error] [pid 4231:tid 4231] [client 52.173.238.41:8679] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.puckerbottombikinis.com"] [uri "/wp-config.php"] [unique_id "ah7Mtu36BzLSrmLzJWc5twAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
djboddington
2026-06-02 12:21:05
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-backdoors-attempts
Exploited Host
Hacking
Anonymous
2026-06-02 12:16:59
(2 days ago)
[ns65.kdns.gr] httpd-suspicious-path: sites=global; logs=/var/log/httpd/access_log; samples=/wp-cont ...
show more
[ns65.kdns.gr] httpd-suspicious-path: sites=global; logs=/var/log/httpd/access_log; samples=/wp-content/plugins/hellopress/wp_filemanager.php | /admin/controller/extension/extension/ultra.php | /wp-includes/about.php
show less
Hacking
Web App Attack