| 2026-03-07 08:55 |
185.242.226.15 |
protocol-mismatch |
Ares |
Fleet |
| 2026-03-07 08:11 |
45.148.10.64 |
+4
|
Multiple (2) |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| suspicious-probe |
reconnaissance |
1 |
2026-03-07 08:11 |
| crowdsecurity/http-sensitive-files |
other |
1 |
2026-03-07 08:11 |
| crowdsecurity/http-probing |
other |
1 |
2026-03-06 12:47 |
| crowdsecurity/http-admin-interface-probing |
reconnaissance |
1 |
2026-03-06 12:47 |
|
| 2026-03-07 07:22 |
167.94.138.160 |
crowdsecurity/http-bad-user-agent |
Triton |
Fleet |
| 2026-03-07 07:13 |
185.177.72.52 |
+3
|
Zephyrus |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| suspicious-probe |
reconnaissance |
1 |
2026-03-07 07:13 |
| mgmt-path-probe |
reconnaissance |
1 |
2026-03-07 07:13 |
| crowdsecurity/http-sensitive-files |
other |
1 |
2026-03-07 07:13 |
|
| 2026-03-07 06:35 |
104.28.214.114 |
+8
|
Triton |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| webshell-high-confidence |
post-exploitation |
1 |
2026-03-07 06:35 |
| wp-nested-backdoor |
web-exploitation |
1 |
2026-03-07 06:35 |
| php-known-backdoor |
web-exploitation |
1 |
2026-03-07 06:35 |
| wp-obscure-nested-php |
web-exploitation |
1 |
2026-03-07 06:35 |
| wordpress-probe |
web-exploitation |
1 |
2026-03-07 06:35 |
| wp-sensitive-paths |
web-exploitation |
1 |
2026-03-07 06:35 |
| webshell-probe |
post-exploitation |
1 |
2026-03-07 06:35 |
| php-backdoor-generic |
web-exploitation |
1 |
2026-03-07 06:35 |
|
| 2026-03-07 06:34 |
2a09:bac1:7680:780::5e:41 |
+11
|
Triton |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| php-backdoor-generic |
web-exploitation |
1 |
2026-03-07 06:34 |
| webshell-high-confidence |
post-exploitation |
1 |
2026-03-07 06:34 |
| wp-sensitive-paths |
web-exploitation |
1 |
2026-03-07 06:34 |
| wp-nested-backdoor |
web-exploitation |
1 |
2026-03-07 06:34 |
| wp-obscure-nested-php |
web-exploitation |
1 |
2026-03-07 06:34 |
| wordpress-probe |
web-exploitation |
1 |
2026-03-07 06:34 |
| webshell-probe |
post-exploitation |
1 |
2026-03-07 06:34 |
| php-known-backdoor |
web-exploitation |
1 |
2026-03-07 06:34 |
| php-obscure-path-backdoor |
web-exploitation |
1 |
2026-03-07 06:34 |
| generic-backdoor-detection |
other |
1 |
2026-03-07 06:34 |
| wp-obscure-path-backdoor |
web-exploitation |
1 |
2026-03-07 06:34 |
|
| 2026-03-07 06:06 |
141.98.11.23 |
+2
|
Iris |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| wp-sensitive-paths |
web-exploitation |
1 |
2026-03-07 06:06 |
| wordpress-probe |
web-exploitation |
1 |
2026-03-07 06:06 |
|
| 2026-03-07 05:57 |
4.204.200.32 |
+17
|
Multiple (2) |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| wp-nested-backdoor |
web-exploitation |
1 |
2026-03-07 05:57 |
| wp-obscure-nested-php |
web-exploitation |
1 |
2026-03-07 05:57 |
| webshell-probe |
post-exploitation |
1 |
2026-03-07 05:57 |
| webshell-high-confidence |
post-exploitation |
1 |
2026-03-07 05:57 |
| php-obscure-path-backdoor |
web-exploitation |
1 |
2026-03-07 05:57 |
| wp-sensitive-paths |
web-exploitation |
1 |
2026-03-07 05:57 |
| wordpress-probe |
web-exploitation |
1 |
2026-03-07 05:57 |
| wp-obscure-path-backdoor |
web-exploitation |
1 |
2026-03-07 05:57 |
| php-backdoor-generic |
web-exploitation |
1 |
2026-03-07 05:57 |
| php-known-backdoor |
web-exploitation |
1 |
2026-03-07 05:57 |
| generic-backdoor-detection |
other |
1 |
2026-03-07 05:57 |
| php-suspicious-name |
web-exploitation |
1 |
2026-03-07 05:57 |
| php-any-suspicious |
web-exploitation |
1 |
2026-03-07 05:57 |
| crowdsecurity/http-crawl-non_statics |
other |
1 |
2026-03-07 05:57 |
| crowdsecurity/http-probing |
other |
1 |
2026-03-07 05:57 |
| crowdsecurity/http-wordpress-scan |
web-exploitation |
1 |
2026-03-07 05:57 |
| mgmt-path-probe |
reconnaissance |
1 |
2026-03-06 12:25 |
|
| 2026-03-07 05:43 |
94.26.106.204 |
webshell-high-confidence |
Iris |
Fleet |
| 2026-03-07 05:39 |
51.68.111.240 |
crowdsecurity/http-bad-user-agent |
Triton |
Fleet |
| 2026-03-07 05:39 |
51.68.111.208 |
crowdsecurity/http-bad-user-agent |
Triton |
Fleet |
| 2026-03-07 05:20 |
185.177.72.13 |
+4
|
Zephyrus |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| suspicious-probe |
reconnaissance |
1 |
2026-03-07 05:20 |
| mgmt-path-probe |
reconnaissance |
1 |
2026-03-07 05:19 |
| crowdsecurity/http-crawl-non_statics |
other |
1 |
2026-03-07 05:19 |
| crowdsecurity/http-sensitive-files |
other |
1 |
2026-03-07 05:19 |
|
| 2026-03-07 04:49 |
51.68.111.244 |
crowdsecurity/http-bad-user-agent |
Iris |
Fleet |
| 2026-03-07 04:04 |
89.191.226.14 |
crowdsecurity/http-cve-2021-41773 |
Ares |
Fleet |
| 2026-03-07 03:58 |
45.149.173.209 |
+2
|
Zephyrus |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| wp-sensitive-paths |
web-exploitation |
1 |
2026-03-07 03:58 |
| wordpress-probe |
web-exploitation |
1 |
2026-03-07 03:58 |
|
| 2026-03-07 02:22 |
52.209.68.175 |
crowdsecurity/http-bad-user-agent |
Triton |
Fleet |
| 2026-03-07 02:19 |
185.93.89.110 |
suspicious-probe |
Zephyrus |
Fleet |
| 2026-03-07 02:01 |
51.68.111.242 |
crowdsecurity/http-bad-user-agent |
Triton |
Fleet |
| 2026-03-07 01:41 |
194.26.192.152 |
+3
|
Iris |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| wp-sensitive-paths |
web-exploitation |
1 |
2026-03-07 01:41 |
| wordpress-probe |
web-exploitation |
1 |
2026-03-07 01:41 |
| crowdsecurity/http-probing |
other |
1 |
2026-03-07 01:41 |
|
| 2026-03-07 00:29 |
167.94.138.192 |
protocol-mismatch |
Ares |
Fleet |
| 2026-03-06 23:01 |
61.245.11.87 |
crowdsecurity/http-cve-2021-41773 |
Ares |
Fleet |
| 2026-03-06 22:33 |
40.115.138.121 |
+10
|
Triton |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| webshell-high-confidence |
post-exploitation |
1 |
2026-03-06 22:33 |
| webshell-probe |
post-exploitation |
1 |
2026-03-06 22:33 |
| wp-obscure-nested-php |
web-exploitation |
1 |
2026-03-06 22:33 |
| wordpress-probe |
web-exploitation |
1 |
2026-03-06 22:33 |
| wp-sensitive-paths |
web-exploitation |
1 |
2026-03-06 22:33 |
| generic-backdoor-detection |
other |
1 |
2026-03-05 13:46 |
| wp-nested-backdoor |
web-exploitation |
1 |
2026-03-04 03:45 |
| php-backdoor-generic |
web-exploitation |
1 |
2026-03-04 03:45 |
| php-suspicious-name |
web-exploitation |
1 |
2026-03-04 03:45 |
| php-any-suspicious |
web-exploitation |
1 |
2026-03-04 03:45 |
|
| 2026-03-06 22:17 |
176.65.148.19 |
crowdsecurity/http-open-proxy |
Ares |
Fleet |
| 2026-03-06 20:54 |
162.142.125.216 |
protocol-mismatch |
Ares |
Fleet |
| 2026-03-06 20:53 |
208.84.101.66 |
+2
|
Argus |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| wp-sensitive-paths |
web-exploitation |
1 |
2026-03-06 20:53 |
| wordpress-probe |
web-exploitation |
1 |
2026-03-06 20:53 |
|