Nginx security traffic

Scanner / hacking report

historysearch.co.uk · 20 Aug 2026 00:02 +0000 – 03 Sep 2026 08:54 +0000
130,414
Scanner requests
1,284
Scanner fingerprints
5,776
Suspicious paths
82.3%
Share of parsed traffic

Top attack / scan paths

PathRequests
/1,192
/wp-content/plugins/hellopress/wp_filemanager.php868
/this_is_a_new_hello_world.php797
/.env595
/1.php501
/222.php476
/wp-admin/install.php466
/3PJcpMFsD8B.php434
/4PJcpMFsD8B.php434
/classwithtostring.php424
/simple.php423
/chosen.php410
/ops.php408
/images.php400
/dex.php369
/media.php365
/BDKR28WP.php347
/wp-content/themes/index.php296
/8.php279
/index.php244
/makeasmtp.php226
/wp-login.php225
/coffexium.php225
/wp-includes/wlwmanifest.xml223
/file1221.php217
/.git/config209
/82.php202
/100.php199
/adminner.php192
/155.php189
/wp-admin/js/index.php184
/11.php166
/133.php163
/alfa.php160
/33.php155
/504.php146
/wp-admin/css/colors/modern/134
/wp-includes/index.php134
/gecko-new.php133
/12.php130
/403.php130
/wp-admin/css/colors/sunrise/129
/7.php129
/wp-admin/css/index.php126
/2.php125
/666.php122
/wp-includes/ID3/about.php121
/wp-admin/setup-config.php121
/000.php114
/wp-mails.php108

Scanner status codes

StatusRequests
20058,360
30149,535
40418,135
4052,216
400641
206194
3049
4993

Detection reasons

exploit-path probe1,519
automation/blank user-agent1,321
high 4xx/5xx ratio68
wide path scan41
high-rate error scan40
automation user-agent with errors10

Top scanner fingerprints

Fingerprints are one-way hashes; raw IP addresses are not shown.

FingerprintRequestsReasonUser agent
26103ff6bbcd4e424b1bb23d7,691exploit-path probe-
dbd6c3d77e8293a030b5a3386,675exploit-path probe-
14adae902a1a3cbfb2e202d16,351exploit-path probe; wide path scan-
dde9289d37daea3208d4ec5c6,044exploit-path probe-
d6b4895f7deae400061a9ec15,120exploit-path probe-
63a76c2124a416c320999cbf4,608exploit-path probe-
cbe59aa64f5d15fd2a87a9464,417exploit-path probe-
7cca4e78087883c31a68b61e4,056exploit-path probe-
b48cc65be701385d25cb24c83,956exploit-path probe-
a154d73022183104be7a25b83,394exploit-path probe-
6baa284b999b228a7e5b60cf3,134exploit-path probecurl/8.7.1
3e00e1e7969f2d5b3d722cf82,775exploit-path probe-
8412b901ba1049c0ab1c99ed2,202exploit-path probe-
551e305e48b619e54a297ae22,108exploit-path probe-
69d9bde361d092ad9816f3a31,971exploit-path probe-
70fb1a951e0304b3a30daed11,882exploit-path probe-
7b074bb43f67fed438cf882b1,626exploit-path probe-
9ed8b27251135f0a24db67ec1,439exploit-path probe-
de4d6b31b2294e17dd50a2591,424exploit-path probe-
e05cb455c856629f0df7b2ea1,364exploit-path probe-
8c39f8186173e0bff685c79d1,192exploit-path probe-
fe9716d69ef0b37ead5d6fe41,184exploit-path probe-
c964fbde8ab4483a1eb1af0b1,064exploit-path probe-
8efc1409233ca79f6495cdba952exploit-path probe-
a46543dbac54222bc74a63e6922exploit-path probe-
084cad96dc870a3d931d6447884exploit-path probe-
d097aa36ae2d8a360ed01af9852exploit-path probe; wide path scan-
ddeb7bb4ad28e8114d566209794exploit-path probe-
45a398fc1aee63b6cde4207f756exploit-path probe; high 4xx/5xx ratio; wide path scan-
b30ad4d05c23b296609c7ca6726exploit-path probe; wide path scan-
4728d54be46e70ccc0f57f6a724exploit-path probe-
0cca55baca1efe35a2f02e63691automation user-agent with errors; exploit-path probe; high 4xx/5xx ratio; high-rate error scan; wide path scancurl/8.7.1
bf03fdc64062021860c6890e686high 4xx/5xx ratio; high-rate error scan; wide path scanMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
6e516428a56ed318919e44b3672exploit-path probe-
9a7aa85911bd88eb830a0f69670exploit-path probe-
22f8ff0eff3f49047f7dded9654exploit-path probe; high 4xx/5xx ratio; wide path scan-
feeccff67c93485969094f93608exploit-path probe-
905852b439308b8b7450455b608exploit-path probe-
fae161311cfc27ba57e53ff2563exploit-path probe; high 4xx/5xx ratio; wide path scan-
7dfa72bf92a400f007454d18551exploit-path probe-
22cd9570cacab1977991f4c5540exploit-path probe-
5bf4ae0fcd413925a23cee4c532exploit-path probe-
ed454b0a1685bd2e964403fd518exploit-path probe-
e3c0f2b77879f1a2226d6455515exploit-path probe-
c2061e092cd7788a911ecb32505exploit-path probeMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
44893ac4eaf02232ed71eee1501exploit-path probe; high 4xx/5xx ratio; wide path scan-
3dcfb04cee51d97eabd17240500exploit-path probeMozilla/5.0
c8218898fe1784740f57cfc2495exploit-path probe-
7f29955f9ee575bffc3e6570464exploit-path probe-
80451726ad7a517b17e85840462exploit-path probeMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Edg/149.0.0.0

Interpretation

Requests for WordPress plugin files, random PHP shells, .env, phpMyAdmin, PHPUnit, backup archives and similar paths are classified as exploit scanning. Behavioural rules also classify clients that generate many failed requests across many paths in a short period. This is an analytics classifier, not an intrusion-detection system.

Back to clean visitor report