๐ง๐ท
Peregrine
2026-07-12 03:21:17
(1 week ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 64.89.162.167 172.71.95.45 - - [22/Jun/2026:17:32:2 ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 64.89.162.167 172.71.95.45 - - [22/Jun/2026:17:32:22 -0300] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 404 18193
show less
Bad Web Bot
๐บ๐ฆ
URAN Publishing Service
2026-07-12 02:18:43
(1 week ago)
64.89.162.167 - - [12/Jul/2026:05:18:43 +0300] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 4 ...
show more
64.89.162.167 - - [12/Jul/2026:05:18:43 +0300] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 404 765 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
64.89.162.167 - - [12/Jul/2026:05:18:43 +0300] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 404 709 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36"
...
show less
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-07-12 01:47:35
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Web App Attack
Bad Web Bot
๐ฏ๐ต
S.O.B.A. Dev.
2026-07-12 01:47:18
(1 week ago)
Web vulnerability scanning
Brute-Force
Web Spam
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-07-12 01:45:03
(1 week ago)
[ISILIA Protection v2.1] Tentative d'accรจs: /alfa_data/alfacgiapi/perl.alfa | Pays: NL | UA: Mozlila ...
show more
[ISILIA Protection v2.1] Tentative d'accรจs: /alfa_data/alfacgiapi/perl.alfa | Pays: NL | UA: Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) V
show less
Hacking
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-07-12 00:39:44
(1 week ago)
vulnerability scan
Web App Attack
๐ฉ๐ช
maxpower
2026-07-11 22:47:06
(1 week ago)
(backdoor_scan) REGOLA 7 - Backdoor Scan Attempt 64.89.162.167 (US/United States/-): 1 in the last 3 ...
show more
(backdoor_scan) REGOLA 7 - Backdoor Scan Attempt 64.89.162.167 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 64.89.162.167 - - [12/Jul/2026:00:47:03 +0200] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 404 55215 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" "64.89.162.167" host=www.cgilchieti.it
show less
Port Scan
๐บ๐ธ
helios.live
2026-07-11 22:27:38
(1 week ago)
2026/07/11 22:27:37 [error] 9817#9817: *1509430 FastCGI sent in stderr: "Primary script unknown" whi ...
show more
2026/07/11 22:27:37 [error] 9817#9817: *1509430 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 64.89.162.167, server: kocerroxy.com, request: "POST /wp-plain.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php8.4-fpm-betakocerroxycom.sock:", host: "kocerroxy.com", referrer: "www.google.com"
2026/07/11 22:27:38 [error] 9817#9817: *1509430 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 64.89.162.167, server: kocerroxy.com, request: "GET /wp-content/plugins/fix/up.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php8.4-fpm-betakocerroxycom.sock:", host: "kocerroxy.com"
2026/07/11 22:27:38 [error] 9817#9817: *1509430 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 64.89.162.167, server: kocerroxy.com, request: "GET /selqoukc.php?Fox=d3wL7 HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php8.4-fpm-betakocerroxycom.so
...
show less
Web App Attack
๐บ๐ธ
Major Hostility
2026-07-11 21:40:18
(1 week ago)
"POST /wp-plain.php HTTP/1.1" 404
"GET /wp-content/plugins/fix/up.php HTTP/1.1" 404
"POST /ALFA_DATA ...
show more
"POST /wp-plain.php HTTP/1.1" 404
"GET /wp-content/plugins/fix/up.php HTTP/1.1" 404
"POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 404
"GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 404
"POST /alfacgiapi/perl.alfa HTTP/1.1" 404
"GET /wp-content/plugins/apikey/apikey.php?test=hello HTTP/1.1" 404
"GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 404
"GET /scqtizgb.php?Fox=d3wL7 HTTP/1.1" 404
show less
Web App Attack
๐ฆ๐บ
clapper
2026-07-11 21:38:28
(1 week ago)
(mod_security) mod_security (id:980001) triggered by 64.89.162.167 (US/United States/-): 5 in the la ...
show more
(mod_security) mod_security (id:980001) triggered by 64.89.162.167 (US/United States/-): 5 in the last 600 secs; ID: rub
show less
Brute-Force
Bad Web Bot
๐ฒ๐พ
Rizzy
2026-07-11 21:35:01
(1 week ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
roxyapi
2026-07-11 21:17:40
(1 week ago)
Honeypot: automated vulnerability scan / web app attack. Last probe: GET /wp-content/themes/seotheme ...
show more
Honeypot: automated vulnerability scan / web app attack. Last probe: GET /wp-content/themes/seotheme/db.php
show less
Web App Attack
Bad Web Bot
๐ซ๐ท
dynamix
2026-07-11 18:29:32
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
macrob
2026-07-11 17:59:39
(1 week ago)
2026/07/11 17:59:38 [error] 2814253#2814253: *368322245 access forbidden by rule, client: 64.89.162. ...
show more
2026/07/11 17:59:38 [error] 2814253#2814253: *368322245 access forbidden by rule, client: 64.89.162.167, server: binixo.com.ar, request: "GET /wp-content/themes/seotheme/db.php?u HTTP/2.0", host: "binixo.com.ar", referrer: "www.google.com"
2026/07/11 17:59:38 [error] 2814253#2814253: *368322245 access forbidden by rule, client: 64.89.162.167, server: binixo.com.ar, request: "GET /wp-content/themes/seotheme/db.php?u HTTP/2.0", host: "binixo.com.ar", referrer: "www.google.com"
2026/07/11 17:59:38 [error] 2814253#2814253: *368322252 access forbidden by rule, client: 64.89.162.167, server: binixo.com.ar, request: "GET /wp-content/plugins/fix/up.php HTTP/2.0", host: "binixo.com.ar"
...
show less
Web App Attack
๐ฆ๐บ
clapper
2026-07-11 17:55:19
(1 week ago)
(mod_security) mod_security (id:980001) triggered by 64.89.162.167 (US/United States/-): 5 in the la ...
show more
(mod_security) mod_security (id:980001) triggered by 64.89.162.167 (US/United States/-): 5 in the last 3600 secs; ID: Clar
show less
Brute-Force
Bad Web Bot