Anonymous
2026-08-10 18:05:25
(1 week ago)
Attack detected: 85.215.116.63 [2026-08-10]
Categories: 21
--- wp2shell/batch exploit (9 hits) ---
8 ...
show more
Attack detected: 85.215.116.63 [2026-08-10]
Categories: 21
--- wp2shell/batch exploit (9 hits) ---
85.215.116.63 - - [26/Jul/2026:17:20:20 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 4744 "-" "wp2shell"
85.215.116.63 - - [26/Jul/2026:17:20:21 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 500 6491 "-" "wp2shell"
85.215.116.63 - - [27/Jul/2026:08:21:41 +0000] "POST /wp-json/batch/v1 HTTP/1.1" 207 4741 "-" "wp2shell"
85.215.116.63 - - [27/Jul/2026:08:21:42 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 4742 "-" "wp2shell"
85.215.116.63 - - [27/Jul/2026:08:21:44 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 5204 "-" "wp2shell"
show less
Web App Attack
๐ธ๐ช
pentesting.se
2026-08-06 15:48:56
(2 weeks ago)
Automated WordPress 'wp2shell' core-RCE exploitation. ~55 POST /?rest_route=/batch/v1 (HTTP 207), Us ...
show more
Automated WordPress 'wp2shell' core-RCE exploitation. ~55 POST /?rest_route=/batch/v1 (HTTP 207), User-Agent 'wp2shell'.
show less
Web App Attack
Hacking
๐ช๐ธ
Gem
2026-07-31 22:23:53
(3 weeks ago)
Unauthorized web scan.
Web App Attack
Anonymous
2026-07-29 10:01:01
(3 weeks ago)
...
Web App Attack
๐ฉ๐ช
LRob
2026-07-29 09:59:50
(3 weeks ago)
CrowdSec: crowdsecurity/http-cve-probing | req: /wp-json/batch/v1 | UA: wp2shell
Web App Attack
๐จ๐ฆ
1gz
2026-07-29 09:27:34
(3 weeks ago)
Triggered Cloudflare WAF (firewallManaged) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST met ...
show more
Triggered Cloudflare WAF (firewallManaged) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /
UA: wp2shell
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
yvoictra
2026-07-29 08:42:08
(3 weeks ago)
Bloqueado automรกticamente por CrowdSec. Escenario: crowdsecurity/http-cve-probing
Web App Attack
๐ต๐ฑ
mscode.pl
2026-07-29 07:54:22
(3 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 8560 (IONOS SE)
Protocol ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 8560 (IONOS SE)
Protocol: HTTP/1.1 (GET method)
Zone: mscode.pl
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0
show less
Bad Web Bot
๐ฆ๐บ
paulshipley.com.au
2026-07-29 06:24:32
(3 weeks ago)
[Wed Jul 29 16:24:31.845092 2026] [security2:error] [pid 362082] [client 85.215.116.63:61237] [clien ...
show more
[Wed Jul 29 16:24:31.845092 2026] [security2:error] [pid 362082] [client 85.215.116.63:61237] [client 85.215.116.63] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.info"] [uri "/"] [unique_id "ammcn1hRY1ljvJVbyI3ofwAAAAE"]
...
show less
Web App Attack
๐ซ๐ฎ
[email protected]
2026-07-29 05:57:05
(3 weeks ago)
Attack attempt against Interwebbi servers; (WPNINJA) Ninja Firewall attack on sommerakademie-kinderb ...
show more
Attack attempt against Interwebbi servers; (WPNINJA) Ninja Firewall attack on sommerakademie-kinderbesserverstehen.de (WP vulnerability) 85.215.116.63 (DE/Germany/-): 1 in the last 3600 secs (CF_ENABLE); IP: 85.215.116.63; Ports: *; Direction: 0; Trigger: LF_CUSTOMTRIGGER;
show less
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-07-29 05:26:07
(3 weeks ago)
[Wed Jul 29 15:26:06.343901 2026] [security2:error] [pid 350591] [client 85.215.116.63:65283] [clien ...
show more
[Wed Jul 29 15:26:06.343901 2026] [security2:error] [pid 350591] [client 85.215.116.63:65283] [client 85.215.116.63] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "levellapromotions.com.au"] [uri "/"] [unique_id "ammO7rTu0GoyDOeUJgSpswAAAAE"]
...
show less
Web App Attack
๐ฎ๐ฉ
helouism
2026-07-29 04:45:29
(3 weeks ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /wp-json/batch/v1 via ru ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /wp-json/batch/v1 via rule: /wp-json
show less
Web App Attack
Bad Web Bot
๐ฆ๐บ
paulshipley.com.au
2026-07-29 03:42:37
(3 weeks ago)
[Wed Jul 29 13:42:36.788646 2026] [security2:error] [pid 303166] [client 85.215.116.63:54783] [clien ...
show more
[Wed Jul 29 13:42:36.788646 2026] [security2:error] [pid 303166] [client 85.215.116.63:54783] [client 85.215.116.63] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "levellapromotions.co.nz"] [uri "/"] [unique_id "aml2rNtLF9Q6DHxiqDk2iAAAAAY"]
...
show less
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-07-29 01:23:41
(3 weeks ago)
[Wed Jul 29 11:23:40.386516 2026] [security2:error] [pid 344743] [client 85.215.116.63:56198] [clien ...
show more
[Wed Jul 29 11:23:40.386516 2026] [security2:error] [pid 344743] [client 85.215.116.63:56198] [client 85.215.116.63] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "shotbysuzanne.com.au"] [uri "/"] [unique_id "amlWHD4e8uJgNentW0U6QAAAAAk"]
...
show less
Web App Attack
๐จ๐ญ
SOC [GOLINE SA]
2026-07-29 00:04:25
(3 weeks ago)
FortiGate detected IPS attack from IPv4 address 85.215.116.63
Hacking