Automated credential/webshell/config harvesting scanner targeting WordPress installations. Paths inc ...
show moreAutomated credential/webshell/config harvesting scanner targeting WordPress installations. Paths include wp-config, .env, .git/config, credentials.json, and webshell uploads. Part of ongoing coordinated attack campaign active since April 2026.
show less
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show moreInbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
{"level":"info","ts":1782427772.1163287,"logger":"http.log.access.log1","msg":"handled request","req ...
show more{"level":"info","ts":1782427772.1163287,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.133.240.167","remote_port":"43280","client_ip":"34.133.240.167","proto":"HTTP/1.1","method":"GET","host":"status.cointribute.dev","uri":"/api/configprops","headers":{"Accept-Encoding":["gzip"],"Connection":["close"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.143 YaBrowser/19.7.1.114 Yowser/2.5 Safari/537.36"],"Accept-Charset":["utf-8"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"status.cointribute.dev","ech":false}},"bytes_read":0,"user_id":"","duration":0.000108346,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1782427772.1188636,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.133.240.167","remote_port":"43284","client_ip":"34.133.240.16
...
show less