๐ซ๐ท
Octopuce
2026-08-25 20:04:23
(19 hours ago)
Aggressive web search of vulnerable pages: /wp-content/plugins/mm/mm.php /wp-content/plugins/Nxploit ...
show more
Aggressive web search of vulnerable pages: /wp-content/plugins/mm/mm.php /wp-content/plugins/Nxploited/Nx.php /wp-content/plugins/madmadxploits ...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-25 18:03:25
(21 hours ago)
[25/Aug/2026:21:03:25 +0300] -- 85.203.45.155 Ban reason: User-Agent Go-http-client
Bad Web Bot
Web App Attack
Anonymous
2026-08-25 17:54:44
(21 hours ago)
[ssd5.kdns.gr] httpd-shell-path-probe: sites=www.mdlab-ntua.gr; logs=/var/log/httpd/domains/mdlab-nt ...
show more
[ssd5.kdns.gr] httpd-shell-path-probe: sites=www.mdlab-ntua.gr; logs=/var/log/httpd/domains/mdlab-ntua.gr.log; samples=/wp-content/plugins/madmadxploits/up.php | /wp-content/plugins/bbpress/file5.php
show less
Hacking
Web App Attack
๐ซ๐ท
Octopuce
2026-07-07 02:53:41
(1 month ago)
Aggressive web search of vulnerable pages: /wp-content/themes/builder-and-developer/inc/tgm/error.ph ...
show more
Aggressive web search of vulnerable pages: /wp-content/themes/builder-and-developer/inc/tgm/error.php /wp-content/themes/theme-check/theme-chec ...
show less
Web App Attack
๐บ๐ธ
mnsf
2026-06-20 05:05:03
(2 months ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-06-16 11:41:37
(2 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-20 06:26:18
(4 months ago)
(mod_security) mod_security (id:234930) triggered by 85.203.45.155 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:234930) triggered by 85.203.45.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 20 02:26:11.128071 2026] [security2:error] [pid 2649897:tid 2649897] [client 85.203.45.155:26993] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||www.4115thewestford.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "www.4115thewestford.com"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "aeXHAzvN0NvN4_YcTJ43kwAAABI"], referer: http://4115thewestford.com/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-17 13:59:20
(4 months ago)
(mod_security) mod_security (id:234930) triggered by 85.203.45.155 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:234930) triggered by 85.203.45.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 17 09:59:16.947230 2026] [security2:error] [pid 1787225:tid 1787225] [client 85.203.45.155:22317] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||cephedanisman.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "cephedanisman.com"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "aeI8tD6dT5VSJDIhj6g7WgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-04-17 07:03:07
(4 months ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
๐ช๐ธ
masterguru
2026-04-17 05:10:25
(4 months ago)
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (110 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (1100000-122)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-14 12:57:02
(4 months ago)
(mod_security) mod_security (id:234930) triggered by 85.203.45.155 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:234930) triggered by 85.203.45.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 14 08:56:54.443323 2026] [security2:error] [pid 1241503:tid 1241532] [client 85.203.45.155:25765] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||executiveaccounting.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "executiveaccounting.net"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "ad45lrfKyEq9GXCibAWY6QAAANc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-13 21:02:11
(4 months ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐บ๐ธ
myagent.site
2026-04-13 01:29:41
(4 months ago)
Blocking for trying to access an exploit file: /alfa.php
Hacking
๐ฉ๐ช
netclix.gr
2026-04-12 21:21:07
(4 months ago)
(aggressive_scan) Aggressive Web Exploit Scan 85.203.45.155 (CH/Switzerland/-): 2 in the last 4600 s ...
show more
(aggressive_scan) Aggressive Web Exploit Scan 85.203.45.155 (CH/Switzerland/-): 2 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 85.203.45.155 - - [13/Apr/2026:00:21:04 +0300] "GET /wp-content/plugins/mrx404/upp.php HTTP/2.0" 404 808 "http://farmakeio1828.gr/wp-content/plugins/mrx404/upp.php" "Go-http-client/2.0"
85.203.45.155 - - [13/Apr/2026:00:21:04 +0300] "GET /wp-content/plugins/filester/assets/css/404.php HTTP/2.0" 404 808 "http://farmakeio1828.gr/wp-content/plugins/filester/assets/css/404.php" "Go-http-client/2.0"
show less
Port Scan
๐บ๐ธ
Penny Packer
2026-03-16 16:29:33
(5 months ago)
Fail2Ban apache-tripwires
Web App Attack