Anonymous
2026-05-28 09:32:42
(6 days ago)
FortiWeb WAF: 59 attacks detected. Threat Score: 6000. Types: GEO IP(30), Client Management(29). Ori ...
show more
FortiWeb WAF: 59 attacks detected. Threat Score: 6000. Types: GEO IP(30), Client Management(29). Origin: Singapore.
show less
Web App Attack
๐บ๐ธ
antlac1
2026-05-28 09:30:59
(6 days ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-28 09:24:14
(6 days ago)
52.237.118.111 - - [28/May/2026:12:24:10 +0300] "GET /wp-content/uploads/index.php HTTP/1.1" 404 785 ...
show more
52.237.118.111 - - [28/May/2026:12:24:10 +0300] "GET /wp-content/uploads/index.php HTTP/1.1" 404 785 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
52.237.118.111 - - [28/May/2026:12:24:13 +0300] "GET /wp-admin/user.php HTTP/1.1" 404 785 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ซ๐ท
Baking333
2026-05-28 09:06:53
(1 week ago)
[redacted] 52.237.118.111 - - [28/May/2026:10:06:46 +0100] "GET /[redacted] HTTP/1.1" 405 392 "-" "M ...
show more
[redacted] 52.237.118.111 - - [28/May/2026:10:06:46 +0100] "GET /[redacted] HTTP/1.1" 405 392 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" [redacted] 52.237.118.111 - - [28/May/2026:10:06:51 +0100] "GET /cgi-bin/ HTTP/1.1" 307 418 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Epimetheus
2026-05-28 08:52:59
(1 week ago)
Zombie network / Bot scanner detected:
[GET] /wp-content/admin.php
[GET] /wp-content/themes/admin.p ...
show more
Zombie network / Bot scanner detected:
[GET] /wp-content/admin.php
[GET] /wp-content/themes/admin.php
[GET] /classwithtostring.php
[GET] /wp-includes/images/
[GET] /wp-content/themes/index.php
[GET] /wp-content/plugins/WordPressCore/
[GET] /wp-includes/PHPMailer/
[GET] /wp-includes/Requests/src/Response/about.php
[GET] /wp-includes/html-api/
[GET] /defaults.php
[GET] /.well-known/
[GET] /info.php
[GET] /cgi-bin/
[GET] /wp-admin/css/colors/ectoplasm/
[GET] /wp-content/plugins/index.php
[GET] /wp-content/uploads/
[GET] /chosen.php
[GET] /wp-content/themes/hideo/network.php
[GET] /adminfuns.php
[GET] /about.php
[GET] /ws.php
[GET] /file.php
[GET] /an.php
[GET] /404.php
[GET] /class-t.api.php
[GET] /kbfr.php
[GET] /wp-admin/user.php
[GET] /abc.php
[GET] /wp-login.php
[GET] /xmlrpc.php
[GET] /goods.php
[GET] /as.php
[GET] /index/function.php
[GET] /wp-conf.php
[GET] /wp-good.php
[GET] /sf.php
[GET] /abcd.php
[GET] /autoload_classmap.php
[GET] /wp-trackback.php
[GET] /randkey
...(Truncated)
show less
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
AetherFox
2026-05-28 08:50:56
(1 week ago)
AetherFox VoidGuard detected: [Thu May 28 08:50:55.059651 2026] [authz_core:error] [pid 2035636:tid ...
show more
AetherFox VoidGuard detected: [Thu May 28 08:50:55.059651 2026] [authz_core:error] [pid 2035636:tid 2035666] [client 52.237.118.111:5592] AH01630: client denied by server configuration: proxy:https://[MASKED]/inputs.php
[Thu May 28 08:50:55.377881 2026] [authz_core:error] [pid 2035636:tid 2035643] [client 52.237.118.111:5592] AH01630: client denied by server configuration: proxy:https://[MASKED]/ioxi-o.php
[Thu May 28 08:50:55.537632 2026] [authz_core:error] [pid 2035636:tid 2035675] [client 52.237.118.111:5592] AH01630: client denied by server configuration: proxy:https://[MASKED]/function/function.php
[Thu May 28 08:50:55.697769 2026] [authz_core:error] [pid 2035636:tid 2035679] [client 52.237.118.111:5592] AH01630: client denied by server configuration: proxy:https://[MASKED]/rip.php
[Thu May 28 08:50:55.857922 2026] [authz_core:error] [pid 2035636:tid 2035667] [client 52.237.118.111:5592] AH01630: client denied by server configuration: proxy:https://
...
show less
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
soc-yk
2026-05-28 08:34:15
(1 week ago)
Type: suspicious_network_activity
Threat: suspicious_public_web_client
Risk: 68
Events: 2178
Eviden ...
show more
Type: suspicious_network_activity
Threat: suspicious_public_web_client
Risk: 68
Events: 2178
Evidence:
- Persistent suspicious network activity detected
- Repeated hostile operational behavior observed
- Multi-event operational persistence identified
show less
Port Scan
Hacking
๐ฎ๐ฉ
soc-yk
2026-05-28 08:10:13
(1 week ago)
Type: credential_attack
Threat: credential_spraying_actor
Risk: 68
Events: 198
Evidence:
- Repeated ...
show more
Type: credential_attack
Threat: credential_spraying_actor
Risk: 68
Events: 198
Evidence:
- Repeated authentication attack activity detected
- Credential abuse behavior observed
- Multi-event operational persistence identified
- Threat escalation behavior observed
show less
Brute-Force
SSH
๐ฉ๐ช
Melle
2026-05-28 08:06:16
(1 week ago)
Blocked by CrowdSec | Scenario: crowdsecurity/http-probing | 52.237.118.111 triggered 11 events | De ...
show more
Blocked by CrowdSec | Scenario: crowdsecurity/http-probing | 52.237.118.111 triggered 11 events | Detected: 2026-05-28T08:06:12.951823386Z
show less
Web App Attack
Hacking
๐ฌ๐ง
elleray
2026-05-28 07:21:32
(1 week ago)
WordPress auth intrusion Banned by Fail2Ban
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
mc4bbs
2026-05-28 07:18:35
(1 week ago)
Automated Apache detection on Windows host. 5 suspicious HTTP requests within 300 seconds. Examples: ...
show more
Automated Apache detection on Windows host. 5 suspicious HTTP requests within 300 seconds. Examples: GET /wp-admin/ -> 404 UA=""; GET /wp-content/admin.php -> 404 UA=""; GET /wp-content/themes/pridmag/il.php -> 404 UA=""; GET /wp-content/index.php -> 404 UA=""; GET /wp-admin/wp.php -> 404 UA=""
show less
Web App Attack
Hacking
๐ฆ๐บ
2000cn.com.au
2026-05-28 07:05:40
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฑ๐ป
garmtech.com
2026-05-28 06:45:45
(1 week ago)
Attempted access to sensitive endpoint (/wp-content/uploads/index.php) detected. Automated scan or u ...
show more
Attempted access to sensitive endpoint (/wp-content/uploads/index.php) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐บ๐ธ
vanguardm
2026-05-28 06:10:04
(1 week ago)
Automated report: 200 events detected. Types: web-attack
Web App Attack
๐บ๐ธ
brantknudson.org
2026-05-28 05:54:11
(1 week ago)
Request path 'GET /inputs.php HTTP/1.1'
Web App Attack
Hacking