N3ilawx
2025-06-25 06:08:15
(2 weeks ago)
Fail2Ban detect something wrong with this ip 52.178.220.114 - GET - 404 - [25/Jun/2025:06:08:13 +000 ... show more Fail2Ban detect something wrong with this ip 52.178.220.114 - GET - 404 - [25/Jun/2025:06:08:13 +0000]
52.178.220.114 - GET - 404 - [25/Jun/2025:06:08:13 +0000]
52.178.220.114 - GET - 404 - [25/Jun/2025:06:08:13 +0000]
52.178.220.114 - GET - 404 - [25/Jun/2025:06:08:14 +0000]
52.178.220.114 - GET - 404 - [25/Jun/2025:06:08:14 +0000]
52.178.220.114 - GET - 404 - [25/Jun/2025:06:08:14 +0000]
52.178.220.114 - GET - 404 - [25/Jun/2025:06:08:14 +0000]
52.178.220.114 - GET - 404 - [25/Jun/2025:06:08:14 +0000]
52.178.220.114 - GET - 404 - [25/Jun/2025:06:08:14 +0000]
52.178.220.114 - GET - 404 - [25/Jun/2025:06:08:14 +0000]
... show less
Brute-Force
Web App Attack
Anonymous
2025-06-25 05:50:38
(2 weeks ago)
52.178.220.114 - - [25/Jun/2025:07:50:37 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.p ... show more 52.178.220.114 - - [25/Jun/2025:07:50:37 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 404 492
52.178.220.114 - - [25/Jun/2025:07:50:37 +0200] "GET /wp-includes/pomo/mpvloi.php HTTP/1.1" 404 492
52.178.220.114 - - [25/Jun/2025:07:50:37 +0200] "GET /wp-admin/images/edit-tags.php HTTP/1.1" 404 492
52.178.220.114 - - [25/Jun/2025:07:50:37 +0200] "GET /wp-admin/includes/media.php.INFECTED.php HTTP/1.1" 404 492
52.178.220.114 - - [25/Jun/2025:07:50:37 +0200] "GET /wp-includes/block-bindings.php HTTP/1.1" 404 492
52.178.220.114 - - [25/Jun/2025:07:50:37 +0200] "GET /wp-admin/maint/wp-act.php HTTP/1.1" 404 492
52.178.220.114 - - [25/Jun/2025:07:50:37 +0200] "GET /wp-includes/class-json-ajax-session.php HTTP/1.1" 404 492
52.178.220.114 - - [25/Jun/2025:07:50:37 +0200] "GET /wp-includes/0.php HTTP/1.1" 404 492
52.178.220.114 - - [25/Jun/2025:07:50:38 +0200] "GET /wp-includes/about.php HTTP/1.1" 404 492
52.178.220.114 - - [25/Jun/2025:07:50:38 +0200] "GET /wp-admin/main
... show less
Web Spam
Web App Attack
sweplox.se
2025-06-25 03:24:40
(2 weeks ago)
52.178.220.114 - - [25/Jun/2025:03:24:39 +0000] "GET /wp-content/plugins/hellopress/wp_filemanager.p ... show more 52.178.220.114 - - [25/Jun/2025:03:24:39 +0000] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 301 162 "-" "-"
52.178.220.114 - - [25/Jun/2025:03:24:39 +0000] "GET /wp-includes/pomo/mpvloi.php HTTP/1.1" 301 162 "-" "-"
52.178.220.114 - - [25/Jun/2025:03:24:39 +0000] "GET /wp-admin/images/edit-tags.php HTTP/1.1" 301 162 "-" "-"
52.178.220.114 - - [25/Jun/2025:03:24:39 +0000] "GET /wp-admin/includes/media.php.INFECTED.php HTTP/1.1" 301 162 "-" "-"
52.178.220.114 - - [25/Jun/2025:03:24:39 +0000] "GET /wp-includes/block-bindings.php HTTP/1.1" 301 162 "-" "-"
52.178.220.114 - - [25/Jun/2025:03:24:39 +0000] "GET /wp-admin/css/colors/ectoplasm/str_shuffcle.php HTTP/1.1" 301 162 "-" "-"
... show less
Bad Web Bot
SSH
ecode hosting
2025-06-25 02:54:02
(2 weeks ago)
Domain : emrenakliye.com
Rule : config
2025-06-25 02:53:15 10.100.1.20 GET /wp-content/p ... show more Domain : emrenakliye.com
Rule : config
2025-06-25 02:53:15 10.100.1.20 GET /wp-content/plugins/hellopress/wp_filemanager.php - 443 - 52.178.220.114 HTTP/1.1 - - emrenakliye.com 404 0 2 12719 89 76 - - show less
Hacking
SQL Injection
dtorrer
2025-06-25 02:48:52
(2 weeks ago)
General vulnerability scan.
Port Scan
as211431.net
2025-06-25 01:56:50
(2 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from IE.
Action taken: BLOCK
Protocol: HTTP/1. ... show more Triggered Cloudflare WAF (firewallCustom) from IE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-content/about.php
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB show less
Bad Web Bot
Anonymous
2025-06-25 01:24:15
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
NyaljBe
2025-06-25 01:04:00
(2 weeks ago)
52.178.220.114 - - [24/Jun/2025:16:34:28 +0200] "GET /mah.php?p= HTTP/1.1" 404 153 "-" "-"
52 ... show more 52.178.220.114 - - [24/Jun/2025:16:34:28 +0200] "GET /mah.php?p= HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - - [24/Jun/2025:16:34:28 +0200] "GET /wp-admin/maint/maint.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - - [24/Jun/2025:16:34:28 +0200] "GET /img/wp-login.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - - [24/Jun/2025:16:34:28 +0200] "GET /moon.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - - [24/Jun/2025:16:34:28 +0200] "GET /radio.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - - [24/Jun/2025:16:34:28 +0200] "GET /dropdown.php?p= HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - - [24/Jun/2025:16:34:28 +0200] "GET /wp-content/languages/index.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - - [24/Jun/2025:16:34:28 +0200] "GET /.well-known/pki-validation/xp.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - - [24/Jun/2025:16:34:28 +0200] "GET /xleet.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - - [24/Jun/2025:16:34:28 +0200] "GET /.well-known/wp-login.php HTTP/1.1" 404 153 "-" "-" show less
Web App Attack
dynamix
2025-06-25 00:31:52
(2 weeks ago)
Multiple WAF Violations
Web App Attack
DumaNet
2025-06-24 23:36:00
(2 weeks ago)
WordPress plugin attack attempts.
Date: 2025 Jun 24. 18:54:12
Source IP: 52.178.220.11 ... show more WordPress plugin attack attempts.
Date: 2025 Jun 24. 18:54:12
Source IP: 52.178.220.114
Portion of the log(s):
52.178.220.114 - [24/Jun/2025:18:54:10 +0200] "GET /wp-content/uploads/admin.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:18:54:10 +0200] "GET /wp-includes/Text/Diff/Renderer/last.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:18:54:10 +0200] "GET /wp-admin/js/widgets/hYdXrMgTbH.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:18:54:10 +0200] "GET /wp-admin/images/wp-ksv1i.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:18:54:10 +0200] "GET /wp-admin/css/colors/dkSUq.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:18:54:10 +0200] "GET /images/test.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:18:54:10 +0200] "GET /wp-includes/pomo/yellow.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:18:54:10 +0200] "GET /wp-admin/includes/class-wp-media-list-table-ezd.php HTTP/1.1" 404 153 "-" "-" .... show less
Hacking
Web App Attack
DumaNet
2025-06-24 23:21:00
(2 weeks ago)
WordPress plugin attack attempts.
Date: 2025 Jun 24. 18:45:10
Source IP: 52.178.220.11 ... show more WordPress plugin attack attempts.
Date: 2025 Jun 24. 18:45:10
Source IP: 52.178.220.114
Portion of the log(s):
52.178.220.114 - [24/Jun/2025:18:45:08 +0200] "GET /wp-admin/maint/go.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:18:45:08 +0200] "GET /wp-includes/about.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:18:45:08 +0200] "GET /wp-admin/css/acces.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:18:45:08 +0200] "GET /wp-includes/0.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:18:45:08 +0200] "GET /wp-includes/class-json-ajax-session.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:18:45:08 +0200] "GET /files/css_compare.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:18:45:08 +0200] "GET /wp-includes/css/dist/niil.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:18:45:08 +0200] "GET /wp-admin/maint/wp-act.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:18:45:08 +0200] "GET /wp-admin/css/colors/ show less
Hacking
Web App Attack
DumaNet
2025-06-24 22:57:00
(2 weeks ago)
WordPress plugin attack attempts.
Date: 2025 Jun 24. 15:34:28
Source IP: 52.178.220.11 ... show more WordPress plugin attack attempts.
Date: 2025 Jun 24. 15:34:28
Source IP: 52.178.220.114
Portion of the log(s):
52.178.220.114 - [24/Jun/2025:15:34:28 +0200] "GET /ty.php?p= HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:15:34:28 +0200] "GET /admin.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:15:34:28 +0200] "GET /text.php?fm=true HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:15:34:28 +0200] "GET /wp-content/up HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:15:34:28 +0200] "GET /wp-admin/css/wp-damin.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:15:34:28 +0200] "GET /wp-includes/fonts/themes.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:15:34:28 +0200] "GET /uploads/phUploader.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:15:34:27 +0200] "GET /wp-includes/ID3/favicon.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:15:34:27 +0200] "GET /wp-admin/includes/rfzhh.php HTTP/1.1" 404 153 "-" "-" show less
Hacking
Web App Attack
DumaNet
2025-06-24 22:39:00
(2 weeks ago)
WordPress plugin attack attempts.
Date: 2025 Jun 24. 15:23:52
Source IP: 52.178.220.11 ... show more WordPress plugin attack attempts.
Date: 2025 Jun 24. 15:23:52
Source IP: 52.178.220.114
Portion of the log(s):
52.178.220.114 - [24/Jun/2025:15:23:52 +0200] "GET /wp-admin/maint/go.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:15:23:52 +0200] "GET /wp-includes/about.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:15:23:52 +0200] "GET /wp-admin/css/acces.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:15:23:52 +0200] "GET /wp-includes/0.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:15:23:51 +0200] "GET /wp-includes/class-json-ajax-session.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:15:23:51 +0200] "GET /files/css_compare.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:15:23:51 +0200] "GET /wp-includes/css/dist/niil.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:15:23:51 +0200] "GET /wp-admin/maint/wp-act.php HTTP/1.1" 404 153 "-" "-"
52.178.220.114 - [24/Jun/2025:15:23:51 +0200] "GET /wp-admin/css/colors/ show less
Hacking
Web App Attack
tentwentyfour
2025-06-24 20:37:24
(2 weeks ago)
Blocked for probing for web application vulnerabilities
Brute-Force
Web App Attack
thetomtaylor.co.uk
2025-06-24 20:33:52
(2 weeks ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer
... [wa01]
Bad Web Bot
Web App Attack