๐ท๐บ
185.125.219.13
18 Jan 2026
185.125.219.13 - - [18/Jan/2026:00:33:28 +0000] "GET / HTTP/1.1" 200 27 "https://webspamaddress.ua/s ...
show more
185.125.219.13 - - [18/Jan/2026:00:33:28 +0000] "GET / HTTP/1.1" 200 27 "https://webspamaddress.ua/store/category/foto-v-skli-na-pamiatnyk.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148"
show less
Web Spam
๐ท๐บ
185.105.116.12
18 Jan 2026
185.105.116.12 - - [18/Jan/2026:00:30:27 +0000] "GET / HTTP/1.1" 200 27 "fake referrer web spam" "Mo ...
show more
185.105.116.12 - - [18/Jan/2026:00:30:27 +0000] "GET / HTTP/1.1" 200 27 "fake referrer web spam" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.7204.97 Safari/537.36"
show less
Web Spam
๐ซ๐ท
185.177.72.16
17 Jan 2026
185.177.72.16 - - [17/Jan/2026:03:45:43 +0000] "GET /k8s-phpinfo HTTP/1.1" 404 1037 "-" "Mozilla/5.0 ...
show more
185.177.72.16 - - [17/Jan/2026:03:45:43 +0000] "GET /k8s-phpinfo HTTP/1.1" 404 1037 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
massive effort from this spammer over weeks to find exploits
show less
Hacking
Web App Attack
๐ฆ๐น
2a04:9546:1924:6701:6245:cbff:fe9e:20b3
16 Jan 2026
dozens of requests searching for atom feeds
Bad Web Bot
๐บ๐ธ
165.154.238.239
16 Jan 2026
165.154.238.239 - - [16/Jan/2026:13:54:52 +0000] "GET /kickstart.php HTTP/1.1" 301 286 "-" "Python-u ...
show more
165.154.238.239 - - [16/Jan/2026:13:54:52 +0000] "GET /kickstart.php HTTP/1.1" 301 286 "-" "Python-urllib/2.7"
joomal hach aatempt
show less
Web App Attack
๐บ๐ธ
20.65.219.43
16 Jan 2026
20.65.219.43 - - [16/Jan/2026:06:09:02 +0000] "GET /developmentserver/metadatauploader HTTP/1.1" 404 ...
show more
20.65.219.43 - - [16/Jan/2026:06:09:02 +0000] "GET /developmentserver/metadatauploader HTTP/1.1" 404 236 "-" "Mozilla/5.0 zgrab/0.x"
show less
Hacking
๐ฉ๐ช
159.195.68.135
16 Jan 2026
159.195.68.135 - - [16/Jan/2026:05:24:35 +0000] "GET /wp-includes/css/buttons.css HTTP/1.1" 301 303 ...
show more
159.195.68.135 - - [16/Jan/2026:05:24:35 +0000] "GET /wp-includes/css/buttons.css HTTP/1.1" 301 303 "-" "Go-http-client/1.1"
show less
Web App Attack
๐ท๐บ
172.68.10.119
16 Jan 2026
172.68.10.119 - - [16/Jan/2026:02:23:29 +0000] "GET /wp-admin/setup-config.php HTTP/1.1" 301 298 "-" ...
show more
172.68.10.119 - - [16/Jan/2026:02:23:29 +0000] "GET /wp-admin/setup-config.php HTTP/1.1" 301 298 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
I hate wordpress and providers who allow hackers to operate from their datacentres
show less
Web App Attack
๐บ๐ธ
148.153.56.58
16 Jan 2026
148.153.56.58 - - [16/Jan/2026:02:01:46 +0000] "GET /Za6l HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Macint ...
show more
148.153.56.58 - - [16/Jan/2026:02:01:46 +0000] "GET /Za6l HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0"
148.153.56.58 - - [16/Jan/2026:02:01:46 +0000] "GET /aab8 HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0"
attempts to find compromised machines
show less
Hacking
๐ฑ๐น
91.224.92.14
16 Jan 2026
91.224.92.14 - - [16/Jan/2026:00:27:13 +0000] "POST /goform/formJsonAjaxReq HTTP/1.1" 404 236 "Go-ht ...
show more
91.224.92.14 - - [16/Jan/2026:00:27:13 +0000] "POST /goform/formJsonAjaxReq HTTP/1.1" 404 236 "Go-http-client/1.1"
attempted goform hacks
show less
Web App Attack
๐บ๐ธ
216.73.216.129
15 Jan 2026
216.73.216.129 - - [15/Jan/2026:14:04:09 +0000] "GET /media/system/js/fields/validate.min.js HTTP/1. ...
show more
216.73.216.129 - - [15/Jan/2026:14:04:09 +0000] "GET /media/system/js/fields/validate.min.js HTTP/1.1" 200 8574 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
If this really is an AI bot, why is it requesting random system files?
show less
Hacking
Bad Web Bot
๐ท๐บ
95.26.9.231
15 Jan 2026
95.26.9.231 - - [15/Jan/2026:23:24:19 +0000] "GET /index.php/component/users
Attacking joomla inst ...
show more
95.26.9.231 - - [15/Jan/2026:23:24:19 +0000] "GET /index.php/component/users
Attacking joomla installations
show less
Web App Attack
๐ซ๐ท
185.177.72.13
15 Jan 2026
185.177.72.13 - - [15/Jan/2026:03:45:49 +0000] "GET / HTTP/1.1" 301 276 "-" "curl/8.7.1"
Web App Attack
๐จ๐ณ
101.251.219.13
14 Jan 2026
101.251.219.13 - - [14/Jan/2026:17:00:45 +0000] "POST /wsman HTTP/1.1" 404 236 "-" "Microsoft WinRM ...
show more
101.251.219.13 - - [14/Jan/2026:17:00:45 +0000] "POST /wsman HTTP/1.1" 404 236 "-" "Microsoft WinRM Client"
suspicious activity searching for windows remote management
show less
Hacking
๐บ๐ธ
135.119.239.48
14 Jan 2026
135.119.239.48 - - [14/Jan/2026:10:21:37 +0000] "GET /p.php HTTP/1.1" 404 16 "-" "-"
Hacking
Web App Attack
๐บ๐ธ
34.11.121.227
14 Jan 2026
34.11.121.227 - - [14/Jan/2026:15:42:53 +0000] "GET //wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 1 ...
show more
34.11.121.227 - - [14/Jan/2026:15:42:53 +0000] "GET //wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 1035 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
show less
Web App Attack
๐ณ๐ฑ
91.201.115.174
14 Jan 2026
exploit checks
Hacking
Web App Attack
๐บ๐ธ
20.221.69.50
14 Jan 2026
20.221.69.50 - - [14/Jan/2026:04:09:04 +0000] "GET /develepmentserver/metadatauploader HTTP/1.1" 404 ...
show more
20.221.69.50 - - [14/Jan/2026:04:09:04 +0000] "GET /develepmentserver/metadatauploader HTTP/1.1" 404 236 "-" "Mozilla/5.0 zgrab/0.x"
???
show less
Hacking
๐ณ๐ฑ
45.144.212.169
14 Jan 2026
45.144.212.169 - - [14/Jan/2026:00:35:34 +0000] "GET /.env HTTP/1.1" 404 236 "-" "-"
Hacking
Web App Attack
๐บ๐ธ
2a06:98c0:3600::103
14 Jan 2026
2a06:98c0:3600::103 - - [14/Jan/2026:03:01:59 +0000] "GET /wordpress/wp-admin/setup-config.php HTTP/ ...
show more
2a06:98c0:3600::103 - - [14/Jan/2026:03:01:59 +0000] "GET /wordpress/wp-admin/setup-config.php HTTP/1.1" 404 236 "-" "/wordpress/wp-admin/setup-config.php"
show less
Web App Attack
๐ฎ๐ณ
74.225.152.181
13 Jan 2026
74.225.152.181 - - [13/Jan/2026:20:46:38 +0000] "GET /wp-includes/fonts/index.php HTTP/1.1" 404 1035 ...
show more
74.225.152.181 - - [13/Jan/2026:20:46:38 +0000] "GET /wp-includes/fonts/index.php HTTP/1.1" 404 1035 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 13; SM-S908E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36"
+many thousands of other hits- disgusting
show less
Hacking
Web App Attack
๐ธ๐ฌ
161.118.206.181
13 Jan 2026
Remote File Inclusion (RFI) attack , old but still nasty.
Hacking
๐บ๐ธ
192.227.231.190
12 Jan 2026
192.227.231.190 - - [12/Jan/2026:18:16:56 +0000] "GET / HTTP/1.1" 200 827 "https://www.google.com/se ...
show more
192.227.231.190 - - [12/Jan/2026:18:16:56 +0000] "GET / HTTP/1.1" 200 827 "https://www.google.com/search?q=admin+panel" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
fraudulent user agent / referrer
show less
Hacking
Web App Attack
๐ฏ๐ต
4.189.120.245
12 Jan 2026
19.170.121.91,4.189.120.245 - - [12/Jan/2026:19:13:14 +0000] "GET /wp-includes/html-api/index.php HT ...
show more
19.170.121.91,4.189.120.245 - - [12/Jan/2026:19:13:14 +0000] "GET /wp-includes/html-api/index.php HTTP/1.1" 404 236 "https://duckduckgo.com/" "Mozilla/5.0 (Linux;
fraudulent agent / referrer
show less
Web App Attack
๐ฎ๐ณ
74.225.195.179
12 Jan 2026
112.64.191.197,74.225.195.179 - - [12/Jan/2026:14:56:29 +0000] "GET /black.php HTTP/1.1" 404 16 "htt ...
show more
112.64.191.197,74.225.195.179 - - [12/Jan/2026:14:56:29 +0000] "GET /black.php HTTP/1.1" 404 16 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36"
Fradulent user aget / referrer
show less
Hacking
Web App Attack