πΊπΈ
raymarron.com
2025-06-16 00:02:33
(1 year ago)
/wp-admin/css/ (x2)
Web App Attack
π΅π±
nfsec.pl
2025-06-11 02:11:04
(1 year ago)
52.90.154.5 - - [11/Jun/2025:04:10:47 +0200] "GET /WP/ HTTP/1.1" 404 31200 "-" "python-requests/2.27 ...
show more
52.90.154.5 - - [11/Jun/2025:04:10:47 +0200] "GET /WP/ HTTP/1.1" 404 31200 "-" "python-requests/2.27.1"
52.90.154.5 - - [11/Jun/2025:04:10:49 +0200] "GET /bc/ HTTP/1.1" 404 31231 "-" "python-requests/2.27.1"
52.90.154.5 - - [11/Jun/2025:04:10:52 +0200] "GET /bk/ HTTP/1.1" 404 31275 "-" "python-requests/2.27.1"
52.90.154.5 - - [11/Jun/2025:04:10:56 +0200] "GET /db/ HTTP/1.1" 404 31213 "-" "python-requests/2.27.1"
52.90.154.5 - - [11/Jun/2025:04:11:03 +0200] "GET /js/ HTTP/1.1" 404 31317 "-" "python-requests/2.27.1"
...
show less
Exploited Host
Web App Attack
πΊπΈ
ersei.net
2025-06-10 20:55:55
(1 year ago)
Web app exploiting
Web App Attack
πͺπΈ
el-brujo
2025-06-10 17:54:43
(1 year ago)
Cloudflare WAF: Request Path: /wp-content/ALFA_DATA/alfacgiapi/ Request Query: Host: foro.elhacker. ...
show more
Cloudflare WAF: Request Path: /wp-content/ALFA_DATA/alfacgiapi/ Request Query: Host: foro.elhacker.net userAgent: python-requests/2.27.1 Action: log Source: firewallManaged ASN Description: AMAZON-AES Country: US Method: GET Timestamp: 2025-06-10T17:54:43Z ruleId: 9f35644b7f734c87a57cfd6d8b036974. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
πΊπΈ
kosada.com
2025-06-10 17:44:25
(1 year ago)
Web vulnerability probing
Web App Attack
Anonymous
2025-06-10 17:09:46
(1 year ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /wp-admin/js
Web App Attack
πΊπΈ
TPI-Abuse
2025-06-09 21:11:54
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 52.90.154.5 (ec2-52-90-154-5.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 52.90.154.5 (ec2-52-90-154-5.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 09 17:11:50.045382 2025] [security2:error] [pid 495679:tid 495679] [client 52.90.154.5:54322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rockpage.net"] [uri "/.env/"] [unique_id "aEdOFoaiV8CporRrezJfIgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TheMadBeaker
2025-06-09 19:24:57
(1 year ago)
Fail2Ban Ban Triggered
HTTP Exploit Attempt
Brute-Force
Web App Attack
πΊπΈ
masterguru
2025-06-09 17:13:19
(1 year ago)
BAD BOT - Detected and Blocked.. Matched phrase "python-requests" at REQUEST_HEADERS:User-Agent. (11 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "python-requests" at REQUEST_HEADERS:User-Agent. (1100000-124)
show less
Bad Web Bot
πΊπΈ
ipblock.com
2025-06-09 16:00:00
(1 year ago)
IPBlock protected site ID [3192-af][s=06].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
πͺπΈ
el-brujo
2025-06-09 12:38:13
(1 year ago)
Cloudflare WAF: Request Path: /wp-content/ALFA_DATA/alfacgiapi/ Request Query: Host: ns2.elhacker.n ...
show more
Cloudflare WAF: Request Path: /wp-content/ALFA_DATA/alfacgiapi/ Request Query: Host: ns2.elhacker.net userAgent: python-requests/2.27.1 Action: log Source: firewallManaged ASN Description: AMAZON-AES Country: US Method: GET Timestamp: 2025-06-09T12:38:13Z ruleId: 9f35644b7f734c87a57cfd6d8b036974. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
π³π±
CryptoYakari
2025-06-09 00:52:23
(1 year ago)
52.90.154.5 - - [09/Jun/2025:03:50:50 +0300] "GET /wp-admin/css/ HTTP/1.0" 404 7075 "binance.com" "M ...
show more
52.90.154.5 - - [09/Jun/2025:03:50:50 +0300] "GET /wp-admin/css/ HTTP/1.0" 404 7075 "binance.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36"
52.90.154.5 - - [09/Jun/2025:03:50:56 +0300] "GET /.well-known/ HTTP/1.0" 404 3510 "binance.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36"
52.90.154.5 - - [09/Jun/2025:03:51:53 +0300] "GET /sites/default/files/ HTTP/1.0" 404 3510 "binance.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36"
52.90.154.5 - - [09/Jun/2025:03:52:13 +0300] "GET /admin/controller/extension/extension/ HTTP/1.0" 404 3510 "binance.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36"
52.90.154.5 - - [09/Jun/2025:03:52:22 +0300] "GET /uploads/ HTTP/1.0" 404 3510 "binance.com" "Mozilla/5.0 (Win
...
show less
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
Anonymous
2025-06-08 22:45:13
(1 year ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /wp-admin/css
Web App Attack
π«π·
/dev/null
2025-06-08 18:20:27
(1 year ago)
CMS Bruteforce / WebApp Attack attempt
Hacking
Web App Attack
π³π±
i-turnradio.nl
2025-06-08 04:43:31
(1 year ago)
2025-06-08 @ 06:43:30 (CET) ~ Blocked based on risk assessment and prior abuse reports
Web App Attack