| 2026-02-27 15:19 |
20.104.16.102 |
+3
|
Triton |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| webshell-high-confidence |
post-exploitation |
1 |
2026-02-27 15:19 |
| webshell-probe |
post-exploitation |
1 |
2026-02-27 15:18 |
| wp-sensitive-paths |
web-exploitation |
1 |
2026-02-27 15:18 |
|
| 2026-02-27 14:54 |
54.37.252.152 |
crowdsecurity/http-bad-user-agent |
Ares |
Fleet |
| 2026-02-27 14:38 |
91.224.92.164 |
suspicious-probe |
Zephyrus |
Fleet |
| 2026-02-27 14:24 |
34.158.168.101 |
protocol-mismatch |
Ares |
Fleet |
| 2026-02-27 14:09 |
176.65.148.19 |
crowdsecurity/http-open-proxy |
Ares |
Fleet |
| 2026-02-27 13:58 |
159.223.72.38 |
crowdsecurity/http-open-proxy |
Ares |
Fleet |
| 2026-02-27 13:47 |
13.71.191.191 |
+17
|
Triton |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| php-backdoor-generic |
web-exploitation |
1 |
2026-02-27 13:47 |
| webshell-high-confidence |
post-exploitation |
1 |
2026-02-27 13:47 |
| webshell-probe |
post-exploitation |
1 |
2026-02-27 13:47 |
| wp-sensitive-paths |
web-exploitation |
1 |
2026-02-27 13:47 |
| wp-obscure-nested-php |
web-exploitation |
1 |
2026-02-27 13:47 |
| wordpress-probe |
web-exploitation |
1 |
2026-02-27 13:47 |
| php-known-backdoor |
web-exploitation |
1 |
2026-02-27 13:47 |
| php-obscure-path-backdoor |
web-exploitation |
1 |
2026-02-27 13:47 |
| wp-nested-backdoor |
web-exploitation |
1 |
2026-02-27 13:47 |
| generic-backdoor-detection |
other |
1 |
2026-02-27 13:47 |
| wp-obscure-path-backdoor |
web-exploitation |
1 |
2026-02-27 13:47 |
| php-suspicious-name |
web-exploitation |
1 |
2026-02-27 13:47 |
| php-any-suspicious |
web-exploitation |
1 |
2026-02-27 13:47 |
| crowdsecurity/http-backdoors-attempts |
other |
1 |
2026-02-27 13:47 |
| crowdsecurity/http-crawl-non_statics |
other |
1 |
2026-02-27 13:47 |
| crowdsecurity/http-probing |
other |
1 |
2026-02-27 13:47 |
| crowdsecurity/http-wordpress-scan |
web-exploitation |
1 |
2026-02-27 13:47 |
|
| 2026-02-27 13:30 |
13.70.40.215 |
+6
|
Iris |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| wp-sensitive-paths |
web-exploitation |
1 |
2026-02-27 13:30 |
| wordpress-probe |
web-exploitation |
1 |
2026-02-27 13:30 |
| webshell-high-confidence |
post-exploitation |
1 |
2026-02-27 13:30 |
| crowdsecurity/http-admin-interface-probing |
reconnaissance |
1 |
2026-02-27 13:30 |
| generic-backdoor-detection |
other |
1 |
2026-02-27 13:30 |
| crowdsecurity/http-probing |
other |
1 |
2026-02-27 13:30 |
|
| 2026-02-27 13:03 |
74.248.138.165 |
+6
|
Triton |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| webshell-high-confidence |
post-exploitation |
1 |
2026-02-27 13:03 |
| webshell-probe |
post-exploitation |
1 |
2026-02-27 13:03 |
| wp-obscure-nested-php |
web-exploitation |
1 |
2026-02-27 13:03 |
| wordpress-probe |
web-exploitation |
1 |
2026-02-27 13:03 |
| wp-sensitive-paths |
web-exploitation |
1 |
2026-02-27 13:03 |
| crowdsecurity/http-probing |
other |
1 |
2026-02-27 13:03 |
|
| 2026-02-27 12:31 |
20.220.148.100 |
webshell-high-confidence |
Iris |
Fleet |
| 2026-02-27 12:16 |
89.42.231.182 |
crowdsecurity/http-cve-2021-41773 |
Ares |
Fleet |
| 2026-02-27 11:57 |
134.149.59.124 |
+3
|
Triton |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| webshell-high-confidence |
post-exploitation |
1 |
2026-02-27 11:57 |
| webshell-probe |
post-exploitation |
1 |
2026-02-27 11:57 |
| wp-sensitive-paths |
web-exploitation |
1 |
2026-02-27 11:57 |
|
| 2026-02-27 11:55 |
18.218.118.203 |
protocol-mismatch |
Ares |
Fleet |
| 2026-02-27 11:33 |
20.219.8.79 |
+12
|
Triton |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| wp-sensitive-paths |
web-exploitation |
1 |
2026-02-27 11:33 |
| wordpress-probe |
web-exploitation |
1 |
2026-02-27 11:33 |
| webshell-probe |
post-exploitation |
1 |
2026-02-27 11:33 |
| webshell-high-confidence |
post-exploitation |
1 |
2026-02-27 11:33 |
| php-obscure-path-backdoor |
web-exploitation |
1 |
2026-02-27 11:33 |
| wp-obscure-nested-php |
web-exploitation |
1 |
2026-02-27 11:33 |
| php-backdoor-generic |
web-exploitation |
1 |
2026-02-27 11:32 |
| crowdsecurity/http-backdoors-attempts |
other |
1 |
2026-02-27 11:32 |
| wp-obscure-path-backdoor |
web-exploitation |
1 |
2026-02-27 11:32 |
| wp-nested-backdoor |
web-exploitation |
1 |
2026-02-27 11:32 |
| crowdsecurity/http-probing |
other |
1 |
2026-02-27 11:32 |
| crowdsecurity/http-wordpress-scan |
web-exploitation |
1 |
2026-02-27 11:32 |
|
| 2026-02-27 11:07 |
167.94.138.46 |
protocol-mismatch |
Ares |
Fleet |
| 2026-02-27 11:04 |
35.199.161.192 |
+2
|
Zephyrus |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| wp-sensitive-paths |
web-exploitation |
1 |
2026-02-27 11:04 |
| wordpress-probe |
web-exploitation |
1 |
2026-02-27 11:04 |
|
| 2026-02-27 10:47 |
185.177.72.22 |
+3
|
Zephyrus |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| suspicious-probe |
reconnaissance |
1 |
2026-02-27 10:47 |
| webshell-high-confidence |
post-exploitation |
1 |
2026-02-27 10:47 |
| crowdsecurity/http-generic-bf |
other |
1 |
2026-02-27 10:47 |
|
| 2026-02-27 10:47 |
66.132.153.133 |
protocol-mismatch |
Ares |
Fleet |
| 2026-02-27 10:38 |
35.199.186.131 |
+3
|
Iris |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| wordpress-probe |
web-exploitation |
1 |
2026-02-27 10:38 |
| wp-sensitive-paths |
web-exploitation |
1 |
2026-02-27 10:38 |
| crowdsecurity/http-probing |
other |
1 |
2026-02-27 10:38 |
|
| 2026-02-27 10:09 |
141.98.11.23 |
+2
|
Iris |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| wp-sensitive-paths |
web-exploitation |
1 |
2026-02-27 10:09 |
| wordpress-probe |
web-exploitation |
1 |
2026-02-27 10:09 |
|
| 2026-02-27 09:11 |
34.172.31.150 |
+2
|
Zephyrus |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| wordpress-probe |
web-exploitation |
1 |
2026-02-27 09:11 |
| wp-sensitive-paths |
web-exploitation |
1 |
2026-02-27 09:11 |
|
| 2026-02-27 08:46 |
4.204.192.31 |
webshell-high-confidence |
Triton |
Fleet |
| 2026-02-27 08:01 |
104.28.246.117 |
+8
|
Triton |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| webshell-probe |
post-exploitation |
1 |
2026-02-27 08:01 |
| webshell-high-confidence |
post-exploitation |
1 |
2026-02-27 08:01 |
| php-backdoor-generic |
web-exploitation |
1 |
2026-02-27 08:01 |
| wp-sensitive-paths |
web-exploitation |
1 |
2026-02-27 08:01 |
| wp-nested-backdoor |
web-exploitation |
1 |
2026-02-27 08:01 |
| php-known-backdoor |
web-exploitation |
1 |
2026-02-27 08:01 |
| wp-obscure-nested-php |
web-exploitation |
1 |
2026-02-27 08:01 |
| wordpress-probe |
web-exploitation |
1 |
2026-02-27 08:01 |
|
| 2026-02-27 08:01 |
2a09:bac5:952f:3af::5e:3a |
+8
|
Triton |
Fleet |
| Scenario |
Category |
Hits |
Last Seen |
| webshell-high-confidence |
post-exploitation |
1 |
2026-02-27 08:01 |
| webshell-probe |
post-exploitation |
1 |
2026-02-27 08:01 |
| php-backdoor-generic |
web-exploitation |
1 |
2026-02-27 08:01 |
| wp-sensitive-paths |
web-exploitation |
1 |
2026-02-27 08:01 |
| php-known-backdoor |
web-exploitation |
1 |
2026-02-27 08:01 |
| wp-nested-backdoor |
web-exploitation |
1 |
2026-02-27 08:01 |
| wordpress-probe |
web-exploitation |
1 |
2026-02-27 08:01 |
| wp-obscure-nested-php |
web-exploitation |
1 |
2026-02-27 08:01 |
|
| 2026-02-27 07:38 |
66.132.153.126 |
crowdsecurity/http-bad-user-agent |
Ares |
Fleet |