๐ฉ๐ช
burlacu.org
2026-09-16 07:39:03
(2 days ago)
Nginx multi-log analysis detected: wordpress_scan. Evidence: WordPress config access with 39 attempt ...
show more
Nginx multi-log analysis detected: wordpress_scan. Evidence: WordPress config access with 39 attempts. Blocked automatically.
show less
Web App Attack
Bad Web Bot
Anonymous
2026-09-16 05:51:43
(2 days ago)
Banned by Fail2Ban on server
Web App Attack
๐ซ๐ท
solution.it
2026-09-16 04:30:32
(2 days ago)
[Wed Sep 16 06:30:31.360305 2026] [php7:error] [pid 1764296:tid 1764296] [client 82.165.216.142:3639 ...
show more
[Wed Sep 16 06:30:31.360305 2026] [php7:error] [pid 1764296:tid 1764296] [client 82.165.216.142:36392] script '/var/www/html/blog.solution.it/phpinfo.php' not found or unable to stat
show less
Web App Attack
๐บ๐ธ
TAY
2026-09-16 03:48:31
(2 days ago)
82.165.216.142 - - [16/Sep/2026:11:48:15 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 46277 "-" "Moz ...
show more
82.165.216.142 - - [16/Sep/2026:11:48:15 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 46277 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
82.165.216.142 - - [16/Sep/2026:11:48:16 +0800] "GET /wp-config.php~ HTTP/1.1" 404 46349 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
82.165.216.142 - - [16/Sep/2026:11:48:17 +0800] "GET /wp-config.php.save HTTP/1.1" 404 46349 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
82.165.216.142 - - [16/Sep/2026:11:48:23 +0800] "GET /wp-config.php.old HTTP/1.1" 404 46349 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
82.165.216.142 - - [16/Sep/2026:11:48:24 +0800] "GET /wp-config.php.orig HTTP/1.1" 404 46277 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KH
...
show less
Brute-Force
๐ณ๐ฑ
Alt255
2026-09-16 02:41:41
(2 days ago)
[ti-tinov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 82 ...
show more
[ti-tinov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 82.165.216.142 - - \[16/Sep/2026:04:41:32 +0200\] "GET /wp-config.php.save HTTP/1.1" 301 5883 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-16 01:09:08
(2 days ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-197)
show less
Hacking
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
ger-stg-sifi1
2026-09-15 22:33:28
(2 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-15 22:07:28
(2 days ago)
Aggressive scanning resulting into 404
Bad Web Bot
๐บ๐ธ
VanKoh
2026-09-15 21:52:49
(2 days ago)
82.165.216.142 - - [15/Sep/2026:15:52:41 -0600] "GET /wp-config.php~ HTTP/1.1" 444 0 "-" "Mozilla/5. ...
show more
82.165.216.142 - - [15/Sep/2026:15:52:41 -0600] "GET /wp-config.php~ HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
82.165.216.142 - - [15/Sep/2026:15:52:47 -0600] "GET /wp-config.php.save HTTP/1.1" 404 58296 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
82.165.216.142 - - [15/Sep/2026:15:52:48 -0600] "GET /wp-config.php.old HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-15 21:50:17
(2 days ago)
cloudlinux2 fail2ban: 2026-09-15 23:29:58,756 fail2ban.filter [1908]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-15 23:29:58,756 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 82.165.216.142 - 2026-09-15 23:29:58cloudlinux2 fail2ban: 2026-09-15 23:29:58,738 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 82.165.216.142 - 2026-09-15 23:29:58cloudlinux2 fail2ban: 2026-09-15 23:29:59,039 fail2ban.actions [1908]: NOTICE [plesk-modsecurity] Ban 82.165.216.142cloudlinux2 fail2ban: 2026-09-15 23:29:59,045 fail2ban.filter [1908]: INFO [recidive] Found 82.165.216.142 - 2026-09-15 23:29:59cloudlinux2 fail2ban: 2026-09-15 23:29:58,747 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 82.165.216.142 - 2026-09-15 23:29:58cloudlinux2 fail2ban: 2026-09-15 23:30:35,221 fail2ban.filter [1908]: INFO [plesk-proftpd] Found 144.217.189.77 - 2026-09-15 23:30:35cloudlinux2 fail2ban: 2026-09-15 23:31:15,678 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 34.63.55.245 - 2026-09-15 23:31:15cloudlinux2 fail2ban: 2026-
show less
FTP Brute-Force
Anonymous
2026-09-15 18:46:24
(2 days ago)
TIPSDE WEBEXPLOIT 82.165.216.142 (ip82-165-216-142.pbiaas.com)
Web App Attack
๐ฌ๐ง
Apache
2026-09-15 17:09:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 82.165.216.142 (FR/France/ip82-165-216-142.pbia ...
show more
(mod_security) mod_security (id:210492) triggered by 82.165.216.142 (FR/France/ip82-165-216-142.pbiaas.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐บ๐ธ
TAY
2026-09-15 15:36:50
(2 days ago)
82.165.216.142 - - [15/Sep/2026:23:36:46 +0800] "GET /wp-config.php.bak HTTP/1.1" 301 6132 "-" "Mozi ...
show more
82.165.216.142 - - [15/Sep/2026:23:36:46 +0800] "GET /wp-config.php.bak HTTP/1.1" 301 6132 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
82.165.216.142 - - [15/Sep/2026:23:36:46 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 53473 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
82.165.216.142 - - [15/Sep/2026:23:36:47 +0800] "GET /wp-config.php~ HTTP/1.1" 301 6129 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
82.165.216.142 - - [15/Sep/2026:23:36:48 +0800] "GET /wp-config.php~ HTTP/1.1" 404 53495 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
82.165.216.142 - - [15/Sep/2026:23:36:49 +0800] "GET /wp-config.php.save HTTP/1.1" 301 6133 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, li
...
show less
Brute-Force
Anonymous
2026-09-15 15:28:02
(2 days ago)
WEB attack
Brute-Force