๐บ๐ธ
35.247.22.189
17 Dec 2025
35.247.22.189 - - [17/Dec/2025:17:05:58 +0000] "GET //website/wp-includes/wlwmanifest.xml HTTP/1.1" ...
show more
35.247.22.189 - - [17/Dec/2025:17:05:58 +0000] "GET //website/wp-includes/wlwmanifest.xml HTTP/1.1" 404 1372 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
show less
Web App Attack
๐ฎ๐ช
52.169.110.28
17 Dec 2025
52.169.110.28 - - [17/Dec/2025:16:50:58 +0000] "GET /amniotic.php HTTP/1.1" 301 285 "-" "-"
Web App Attack
๐ธ๐ฌ
4.193.198.5
17 Dec 2025
4.193.198.5 - - [17/Dec/2025:09:14:43 +0000] "GET /berlin.php HTTP/1.1" 404 16 "-" "-"
Hacking
Web App Attack
๐ซ๐ท
13.37.212.135
17 Dec 2025
Rapid fire automated bot vulnerability scan looking for
/apps: Checking for common web application ...
show more
Rapid fire automated bot vulnerability scan looking for
/apps: Checking for common web applications.
/api/action & /api/actions: Checking for API endpoints or specific frameworks (like CKAN).
/_next/data: Checking if your site is built with Next.js (a popular React framework).
show less
Hacking
Brute-Force
Web App Attack
๐ท๐บ
194.67.207.9
17 Dec 2025
194.67.207.9 - - [17/Dec/2025:02:43:50 +0000] "GET / HTTP/1.1" 200 27 "Possibly-Malicious-Referrer" ...
show more
194.67.207.9 - - [17/Dec/2025:02:43:50 +0000] "GET / HTTP/1.1" 200 27 "Possibly-Malicious-Referrer" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
Fake possibly malicious referrer
show less
Web Spam
๐ท๐บ
92.62.119.113
17 Dec 2025
92.62.119.113 - - [17/Dec/2025:02:02:05 +0000] "GET / HTTP/1.1" 200 27 "https://BAD-UA-REFERRER" "Mo ...
show more
92.62.119.113 - - [17/Dec/2025:02:02:05 +0000] "GET / HTTP/1.1" 200 27 "https://BAD-UA-REFERRER" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.7204.92 Safari/537.36"
show less
Web Spam
๐ท๐บ
185.5.249.185
17 Dec 2025
185.5.249.185 - - [17/Dec/2025:01:07:06 +0000]
Fake UA and Referrer - redacted in case the unique ...
show more
185.5.249.185 - - [17/Dec/2025:01:07:06 +0000]
Fake UA and Referrer - redacted in case the unique fatuous URL is naughty
show less
Web Spam
Hacking
๐ท๐บ
37.112.219.146
17 Dec 2025
37.112.219.146 - - [17/Dec/2025:00:30:48 +0000] "GET /component/users
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
172.71.148.115
16 Dec 2025
172.71.148.115 - - [16/Dec/2025:01:34:53 +0000] "GET /wp-admin/setup-config.php HTTP/1.1" 404 1035 " ...
show more
172.71.148.115 - - [16/Dec/2025:01:34:53 +0000] "GET /wp-admin/setup-config.php HTTP/1.1" 404 1035 "-" "http://xxxxxxxxxxxxx.xxx/wp-admin/setup-config.php"
show less
Web App Attack
๐ฉ๐ช
172.71.148.114
16 Dec 2025
172.71.148.114 - - [16/Dec/2025:01:34:52 +0000] "GET /wp-admin/setup-config.php HTTP/1.1" 301 258 "- ...
show more
172.71.148.114 - - [16/Dec/2025:01:34:52 +0000] "GET /wp-admin/setup-config.php HTTP/1.1" 301 258 "-" "http://xxxxxxxxxxxx.xxx/wp-admin/setup-config.php"
show less
Web App Attack
๐ท๐บ
172.68.10.118
16 Dec 2025
172.68.10.118 - - [16/Dec/2025:01:36:30 +0000] "GET /wordpress/wp-admin/setup-config.php HTTP/1.1" 4 ...
show more
172.68.10.118 - - [16/Dec/2025:01:36:30 +0000] "GET /wordpress/wp-admin/setup-config.php HTTP/1.1" 404 1035 "-" "https://xxxxxxxxxx.xxx/wordpress/wp-admin/setup-config.php"
show less
Web App Attack
๐บ๐ธ
34.82.12.177
15 Dec 2025
34.82.12.177 - - [15/Dec/2025:17:57:46 +0000] "HEAD /wp/ HTTP/1.1" 404 - "http://xxxxxxxxxxx.com/wp/ ...
show more
34.82.12.177 - - [15/Dec/2025:17:57:46 +0000] "HEAD /wp/ HTTP/1.1" 404 - "http://xxxxxxxxxxx.com/wp/" "Mozilla/5.0
show less
Web App Attack
๐ฎ๐ช
52.164.245.44
15 Dec 2025
52.164.245.44 - - [15/Dec/2025:21:41:22 +0000] "GET /wp-content/plugins/hellopress/wp_filemanager.ph ...
show more
52.164.245.44 - - [15/Dec/2025:21:41:22 +0000] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 301 272 "-" "-"
52.164.245.44 - - [15/Dec/2025:21:41:22 +0000] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 404 1372 "-" "-"
show less
Web App Attack
๐บ๐ธ
104.248.4.90
15 Dec 2025
104.248.4.90 - - [15/Dec/2025:08:53:02 +0000] "GET /+CSCOL+/Java.jar HTTP/1.1" 404 196
104.248.4.90 ...
show more
104.248.4.90 - - [15/Dec/2025:08:53:02 +0000] "GET /+CSCOL+/Java.jar HTTP/1.1" 404 196
104.248.4.90 - - [15/Dec/2025:08:53:03 +0000] "GET /+CSCOE+/logon_forms.js HTTP/1.1" 404 196
104.248.4.90 - - [15/Dec/2025:08:53:04 +0000] "GET /+CSCOL+/a1.jar HTTP/1.1" 404 196
104.248.4.90 - - [15/Dec/2025:08:53:04 +0000] "GET /+CSCOE+/transfer.js HTTP/1.1" 404 196
Naughty scans
show less
Port Scan
๐ฌ๐ง
34.142.114.141
15 Dec 2025
Scan on 443 by 34.142.114.141 - - [15/Dec/2025:08:26:52 +0000] "OPTIONS / HTTP/1.0" 200 -
Port Scan
๐บ๐ธ
67.82.221.97
15 Dec 2025
67.82.221.97 - - [15/Dec/2025:12:50:38 +0000] "GET /.env HTTP/1.1" 404 1035 "-" "Mozilla/5.0 (Window ...
show more
67.82.221.97 - - [15/Dec/2025:12:50:38 +0000] "GET /.env HTTP/1.1" 404 1035 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
Odd attack, all athe the same time from 6 ips
show less
Hacking
Exploited Host
๐บ๐ธ
170.203.123.250
15 Dec 2025
170.203.123.250 - - [15/Dec/2025:12:50:38 +0000] "GET /backend/.env HTTP/1.1" 404 1035 "-" "Mozilla/ ...
show more
170.203.123.250 - - [15/Dec/2025:12:50:38 +0000] "GET /backend/.env HTTP/1.1" 404 1035 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
part of attack with 5 other ips
show less
Hacking
Exploited Host
๐บ๐ธ
162.81.109.75
15 Dec 2025
162.81.109.75 - - [15/Dec/2025:12:50:38 +0000] "GET /backend/.env HTTP/1.1" 301 245 "-" "Mozilla/5.0 ...
show more
162.81.109.75 - - [15/Dec/2025:12:50:38 +0000] "GET /backend/.env HTTP/1.1" 301 245 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
Part of co-rodinated attack all at this time stamp along with 5 other ips
show less
Hacking
Exploited Host
๐บ๐ธ
172.58.240.240
15 Dec 2025
172.58.240.240 - - [15/Dec/2025:12:50:38 +0000] "GET /api/.env HTTP/1.1" 404 1035 "-" "Mozilla/5.0 ( ...
show more
172.58.240.240 - - [15/Dec/2025:12:50:38 +0000] "GET /api/.env HTTP/1.1" 404 1035 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
appears to be part of botnet
show less
Hacking
Exploited Host
๐บ๐ธ
142.173.7.190
15 Dec 2025
142.173.7.190 - - [15/Dec/2025:12:50:38 +0000] "GET /.env HTTP/1.1" 301 237 "-" "Mozilla/5.0 (Window ...
show more
142.173.7.190 - - [15/Dec/2025:12:50:38 +0000] "GET /.env HTTP/1.1" 301 237 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
show less
Hacking
Exploited Host
๐บ๐ธ
23.150.196.146
15 Dec 2025
23.150.196.146 - - [15/Dec/2025:12:50:38 +0000] "GET /app/.env HTTP/1.1" 301 241 "-" "Mozilla/5.0 (W ...
show more
23.150.196.146 - - [15/Dec/2025:12:50:38 +0000] "GET /app/.env HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
show less
Hacking
Exploited Host
๐บ๐ธ
72.85.166.130
15 Dec 2025
72.85.166.130 - - [15/Dec/2025:12:50:38 +0000] "GET /api/.env HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Wi ...
show more
72.85.166.130 - - [15/Dec/2025:12:50:38 +0000] "GET /api/.env HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
Possibly Bot / Exploited host
show less
Hacking
Exploited Host
๐ธ๐ช
104.23.221.223
15 Dec 2025
104.23.221.223 - - [15/Dec/2025:07:05:59 +0000] "GET /wordpress/wp-admin/setup-config.php HTTP/1.1" ...
show more
104.23.221.223 - - [15/Dec/2025:07:05:59 +0000] "GET /wordpress/wp-admin/setup-config.php HTTP/1.1" 404 1372 "-" "https://attacked-site/wordpress/wp-admin/setup-config.php"
show less
Web App Attack
๐ฌ๐ง
185.192.70.107
14 Dec 2025
185.192.70.107 - - [14/Dec/2025:06:27:15 +0000] "GET /wp-includes/IXR/class-IXR-cilent.php HTTP/1.1" ...
show more
185.192.70.107 - - [14/Dec/2025:06:27:15 +0000] "GET /wp-includes/IXR/class-IXR-cilent.php HTTP/1.1" 301 269 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0"
show less
Web App Attack
๐ฌ๐ง
185.192.70.103
14 Dec 2025
185.192.70.103 - - [14/Dec/2025:06:26:28 +0000] "GET /wp-content/themes/twentytwentytwo/waf_defender ...
show more
185.192.70.103 - - [14/Dec/2025:06:26:28 +0000] "GET /wp-content/themes/twentytwentytwo/waf_defender.php HTTP/1.1" 301 283 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0"
show less
Web App Attack