Report for IP: 169.58.204.118

Threat LevelCRITICAL78/1002 rule types
19 incidents · 2 rule types · active attack detected · persistent 18-day campaign · seen 2h ago
PTR mail.halo-egroup.com
Org / ASN Contabo GmbH
Country 🇫🇷 France
City Lauterbourg, Grand Est
Timezone Europe/Paris

Attack Analysis

Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour — including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.
Webshell Upload Scan
This IP rapidly probed multiple non-existent PHP paths in under 60 seconds — a hallmark of automated webshell scanning tools hunting for previously uploaded backdoors or vulnerable file-upload endpoints. If successful, a webshell grants the attacker full remote code execution on the server.

Reports (19)

Date Severity Description
30 Sep 2026 - 00:05 high Web: Webshell scan — 3+ unknown PHP probes in 60s
29 Sep 2026 - 00:50 medium IDS: Suricata alert — ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt
27 Sep 2026 - 00:55 medium IDS: Suricata alert — ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt
26 Sep 2026 - 00:31 high Web: Webshell scan — 3+ unknown PHP probes in 60s
25 Sep 2026 - 00:53 high Web: Webshell scan — 3+ unknown PHP probes in 60s
24 Sep 2026 - 00:40 high Web: Webshell scan — 3+ unknown PHP probes in 60s
23 Sep 2026 - 00:26 medium IDS: Suricata alert — ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt
23 Sep 2026 - 00:21 high Web: Webshell scan — 3+ unknown PHP probes in 60s
22 Sep 2026 - 01:02 medium IDS: Suricata alert — ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt
22 Sep 2026 - 00:57 high Web: Webshell scan — 3+ unknown PHP probes in 60s
20 Sep 2026 - 00:51 high Web: Webshell scan — 3+ unknown PHP probes in 60s
19 Sep 2026 - 00:29 high Web: Webshell scan — 3+ unknown PHP probes in 60s
17 Sep 2026 - 00:42 high Web: Webshell scan — 3+ unknown PHP probes in 60s
16 Sep 2026 - 00:44 high Web: Webshell scan — 3+ unknown PHP probes in 60s
15 Sep 2026 - 00:18 high Web: Webshell scan — 3+ unknown PHP probes in 60s
14 Sep 2026 - 00:31 high Web: Webshell scan — 3+ unknown PHP probes in 60s
12 Sep 2026 - 01:13 medium IDS: Suricata alert — ET EXPLOIT Apache HTTP Server 2.4.49 - Path Traversal Attempt (CVE-2021-41773) M2
12 Sep 2026 - 01:13 high Web: Webshell scan — 3+ unknown PHP probes in 60s
12 Sep 2026 - 01:13 high IDS: Suricata alert