Automated WordPress reconnaissance and path fuzzing attack against richardsonserra.com on 2026-08-29 ...
show moreAutomated WordPress reconnaissance and path fuzzing attack against richardsonserra.com on 2026-08-29 (04:44 BRT). Automated scanner probing for /xmlrpc.php and wlwmanifest.xml across multiple subdirectories (/shop/, /wordpress/, /cms/, /test/, /wp/, /sito/, /2019/, /media/, /wp1/) to detect WordPress versions and prepare for exploitation. IP: 35.243.225.131 (Google LLC - AS396982).
show less
Automated high-speed web application scanning and cloud credential harvesting attack against richard ...
show moreAutomated high-speed web application scanning and cloud credential harvesting attack against richardsonserra.com on 2026-08-29 (19:04 BRT). 279 malicious requests blocked by Cloudflare WAF in 6 seconds. Target paths include GCP/Firebase credentials (/google-key.json, /gcp-sa.json, /firebase-adminsdk.json, /google-credentials.json), environment files (/.env.yaml, /.env.backup, /react/.env, /config/app/.env), Git config (/.git/config), and PHP info disclosure (/core/phpinfo.php, /wp-admin/phpinfo.php, /_profiler/phpinfo). Originating IP: 34.95.189.96 (Google LLC - AS396982).; โ/google-key.jsonโ
โ/firebase-adminsdk.jsonโ
โ/application_default_credentials.jsonโ
โ/google-credentials.jsonโ
โ/gcp-sa.jsonโ
show less
IP - IP 34.139.77.106; Blocked Requests: 317; Fully blocked by Cloudflare WAF; Date: 2026-08-29; UTC ...
show moreIP - IP 34.139.77.106; Blocked Requests: 317; Fully blocked by Cloudflare WAF; Date: 2026-08-29; UTC Time: 21:21;
High-severity automated attack blocked by the Cloudflare edge firewall. Attempts to access multiple credential and secret files, including service-account.json, gcp-service.json, gcp-key.json, keys/service-account.json, secrets.env, id_ed25519, host.key, auth.json, and account/_payload.json. Attempts to exploit debug frameworks and endpoints such as /telescope/requests (Laravel), /app_dev.php and /_profiler/open (Symfony), /wp-json and /wp-config.php.bak (WordPress), as well as /debug/pprof/cmdline (Go). The IP performed directory traversal attempts (/@fs/../.env, /@fs/.env) and API enumeration (/api/v1/env, /api/v2/settings, /api/openapi.json).
โ/telescope/requestsโ
โ/_profiler/openโ
โ/app_dev.phpโ
โ/api/v1/envโ
โ/config.json.jsโ
โ/@fs/../.envโ
โ/host.keyโ
โ/secrets.envโ
โ/id_ed25519โ
โ/service-account.jsonโ
โ/gcp-service.jsonโ
โ/keys/service-account.jsonโ
show less
IP address: 34.45.248.203; Blocked requests: 260;
Operating System: Linux (Shodan), Open port: 22 ( ...
show moreIP address: 34.45.248.203; Blocked requests: 260;
Operating System: Linux (Shodan), Open port: 22 (SSH),
Tags: cloud; Date: 2026-08-29; UTC Time: 18:47:44; Description: High-speed automated scanning/fuzzing attack against the web application, generating 260 malicious HTTP GET/POST requests within a span of just 21 seconds; Attack vectors:
* Credential & Cloud Key Harvesting: Active search for GCP service keys and credentials within .json and .env files in development/infrastructure directories.
* Information Disclosure / Diagnostic Probing: Fuzzing of over 20 paths containing diagnostic scripts (/phpinfo.php, /_profiler/phpinfo, /pinfo.php, /debug.php).
* Source Code Exposure (Git Leakage): Attempted arbitrary reading of version control configuration files (/.git/config).
* Path & Subdirectory Fuzzing: Probing of administrative routes, test environments, and microservices (/administrator/, /uat/, /microservice/, /gateway/, /webmail/).
show less
Attacker IP: 136.66.89.235; Blocked requests: 928; Fully blocked by Cloudflare WAF; Date: 2026-08-29 ...
show moreAttacker IP: 136.66.89.235; Blocked requests: 928; Fully blocked by Cloudflare WAF; Date: 2026-08-29; UTC Time: 12:15:38; Attack duration: 2 minutes; High-intensity scanning attack targeting credential exfiltration, internal system file reading, path traversal, and Vite/Node SSR exploitation via the /@fs/ prefix:
Use of encoded traversal to escape the project root:
/@fs/..%252f..%252f..%252f..%252f..%252froot/.env
/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ;
Attempts to read internal system files:
/@fs/etc/nginx/nginx.conf
/@fs/etc/apache2/apache2.conf
/@fs/proc/self/environ
/@fs/proc/self/cmdline
/@fs/etc/passwd
Attempts to access credentials from multiple providers:
/@fs/root/.aws/credentials
/@fs/home/ubuntu/.azure/credentials
/@fs/app/gcp-credentials.json
/@fs/root/.oci/config
/@fs/root/.ovh.conf
/@fs/root/.vultr-cli.yaml
/@fs/root/.config/gcloud/credentials.db
/@fs/home/ec2-user/.aws/config
show less
The IP address 52.202.49.233, belonging to Amazon AWS (AS14618), performed a series of automated req ...
show moreThe IP address 52.202.49.233, belonging to Amazon AWS (AS14618), performed a series of automated requests strongly indicating web application scanning and attempts to access secrets and credentials. The observed pattern corresponds to enumeration attacks and sensitive file discovery, with a high probability of originating from automated bots or scanning frameworks.
## 2. Date and Time
2026-08-29; 11:11:20 BRT
Blocked request: 57;
## 3. Attack Vectors and Traffic Samples
1. Sensitive File Enumeration
Attempts to access files that typically contain tokens, keys, credentials, and environment variables:
/.env
/.env.bak
/api/.env
/.docker/config.json
/.github/.env
/credentials.json
/serviceAccountKey.json
/.boto
2. Administrative Panel Scanning
Requests to common administrative endpoints:
/dashboard
/console
/panel
/account/login
3. Application Structure Reconnaissance
Access to directories and files typical of frameworks:
/api/
/dashboard
/console
show less
1. Incident Description
A high-intensity automated scanning campaign (involving vulnerability scann ...
show more1. Incident Description
A high-intensity automated scanning campaign (involving vulnerability scanning and brute-force attempts) was detected targeting the WordPress-based web infrastructure (`richardsonserra.com`). The hostile actor executed hundreds of malicious requests within a short timeframe, probing for common administrative paths and known plugin/theme vulnerabilities, as well as attempting to inject backdoors and web shells (such as WSO-type scripts). The traffic was successfully intercepted and blocked by mitigation mechanisms and the perimeter firewall, resulting in no impact on data or system integrity. Global SOC records indicate that the source IP is part of a large-scale, automated persistent threat infrastructure.
## 2. Date and Time
* **Start / Incident Monitoring Window:** August 28, 2026, at approximately 04:39 BRT.
* **Backdoor / Web Shell Scanning:**
* `GET /wso.php`
* `GET /files.php`
* `GET /classwithtostring.php`
* `GET /Sanskrit.php`
* **Intrusion Attempts on CMS Paths
show less
# Incident Report: Malicious IP Scanning and Automated Probing
## 1. Incident Overview
* **Attac ...
show more# Incident Report: Malicious IP Scanning and Automated Probing
## 1. Incident Overview
* **Attacker IP Address:** `34.139.4.186`
* **ASN & Provider:** `AS396982` - Google LLC (Google Cloud infrastructure)
* **Incident Window / Timestamp:** August 27, 2026, from 20:58:31 to 20:58:35 BRT
* **Total Requests Logged:** 330 requests within a 24-hour window (100% mitigated/blocked by edge security)
* **Threat Reputation Context:** Flagged globally across multiple threat intelligence platforms (VirusTotal, GreyNoise, Fortinet, and MalwareURL) as an active scanning and probing node.
## 2. Attack Vectors & Techniques (TTPs)
The source IP executed an automated, high-frequency brute-force reconnaissance and path traversal scan. The behavior mimics automated vulnerability scanners looking for exposed environment secrets, administrative backups, configuration files, and private keys.
show less
Malicious IP Profile: 185.177.72.67 Date: 2026-08-27; UTC Time: 06:51:20; Blocked Requests: 3.18k; B ...
show moreMalicious IP Profile: 185.177.72.67 Date: 2026-08-27; UTC Time: 06:51:20; Blocked Requests: 3.18k; Blocked by: Waf Cloudflare; IP 185.177.72.67 performed scans and attempted exploitation on multiple services (Docker, Kubernetes, Grafana, MLflow, WordPress, Next.js, Supabase, PHP Unit, etc.).
It also attempts to access sensitive credentials and configuration files (.env, AWS, GCP, Firebase, Mailgun, SES, Postmark).
Observed Behaviors & Attack Vectors:
- Vulnerability & Port Scanning: Active probing of Kubernetes endpoints (ports 10250, 10256), SSH (port 22), and NTP.
- Information Gathering / Credential Harvesting: Automated high-frequency requests targeting sensitive configuration files (.env, gcloud.json, firebase.json, db.sql) and API keys (AWS, SendGrid, Mailgun, Postmark, Stripe).
- Application Exploitation: Attempts to exploit RCE vectors via PHPUnit eval-stdin.php paths and vulnerable CMS plugins using automated tools (curl/8.7.1).
show less
Incident Summary:
On 2026-08-22 UTC Time:21:46:01, the IP address 52.141.19.25, belonging to AS8075 ...
show moreIncident Summary:
On 2026-08-22 UTC Time:21:46:01, the IP address 52.141.19.25, belonging to AS8075 (Microsoft Corporation) and geolocated in South Korea. Blocked by: WAF Cloudflare; Malicious automated vulnerability scanning (fuzzing/directory probing). The host issued 108 rapid HTTP GET requests in less than 15 seconds targeting non-existent PHP backdoors, webshells, and sensitive endpoints (e.g., /wp-0.php, /BDKR28WP.php, /zoo1.php, /new.php). All requests presented an empty User-Agent header and were dropped at the edge WAF layer. Likely compromised Azure instance operating as an automated scanner/botnet node.
[2026-08-22 18:46:00 BRT] Blocked IP: 52.141.19.25 | ASN: AS8075 | Country: KR | Method: GET | Path: /wp-0.php | Protocol: HTTP/1.1 | User-Agent: "" | Action: Blocked
[2026-08-22 18:46:00 BRT] Blocked IP: 52.141.19.25 | ASN: AS8075 | Country: KR | Method: GET | Path: /k.php | Protocol: HTTP/1.1 | User-Agent: "" | Action: Blocked
show less
IP - 34.252.74.149; Blocked requests: 188; Blocked by - Cloudflare WAF; UTC Time: 21:51:36; User-Age ...
show moreIP - 34.252.74.149; Blocked requests: 188; Blocked by - Cloudflare WAF; UTC Time: 21:51:36; User-Agent - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; Attack type: Automated attack blocked by Cloudflare WAF, characterized by an extensive search for environment information and "phpinfo.php" files scattered across dozens of subdirectories and alternative paths. Targeted exhaustive dictionary-style scan to locate the `phpinfo()` utility across multiple paths:`/phpinfo`, `/phpinfo.php`, `/_phpinfo.php`, `/old_phpinfo.php`, `/php-info.php`, `/phpversion.php`, `/info`, `/p.php`, `/debug.php`, `/test.php`. - Mapping of sensitive subdirectories: `/admin/phpinfo.php`, `/dev/phpinfo.php`, `/test/phpinfo.php`,`/tmp/phpinfo.php`, `/old/phpinfo.php`, `/public/phpinfo.php`, `/smtp/phpinfo.php`, `/webmail/phpinfo.php`, `/hosting/phpinfo.php`, `/cpanel/phpinfo.php`, `/mail/phpinfo.php`.
show less