Path traversal, and API probes, all returning 403/404.
Target: HTTP 80/443.tech - GET /.env, /.env?i ...
show morePath traversal, and API probes, all returning 403/404.
Target: HTTP 80/443.tech - GET /.env, /.env?import&url&inline, //.env, static//.env, /userfiles/x?path=../../../../proc/self/environ, /id_rsa, /localhost.key, /api/graphql, /api/templates/preview
Seen: 2026-09-16 13:05 EDT
- 13:05:19 - GET /userfiles/x?path=../../../../proc/self/environ HTTP/2.0 returned 403
- 13:05:28 - GET //.env HTTP/2.0 returned 403
- 13:05:26 - GET /.zshrc HTTP/2.0 returned 403
- 13:05:00 - POST /api/graphql HTTP/2.0 returned 404
Categories: Web App Attack, Bad Web Bot
show less
All returning 403/404.
Target: HTTP 80/443.tech - GET /.env, /.well-known/jwks.json, /api/health, /a ...
show moreAll returning 403/404.
Target: HTTP 80/443.tech - GET /.env, /.well-known/jwks.json, /api/health, /api/config, /serviceAccountKey.json, /serverless.yaml, /docker-compose.yml, /api/v1/validate/code
Seen: 2026-09-16 13:12-13:13 EDT
- 13:13:01 - POST /mcp HTTP/1.1 returned 404
- 13:13:14 - GET /docker-compose.yml HTTP/2.0 returned 404
Categories: Web App Attack, Bad Web Bot
show less
.key files, and API probes, all returning 403/404.
Target: HTTP 80/443.tech - GET /.env, /.env.stage ...
show more.key files, and API probes, all returning 403/404.
Target: HTTP 80/443.tech - GET /.env, /.env.stage, /.env.old, /dashboard/.env, /conf/.env, /localhost.key, /id_rsa, /Dockerfile, /actuator, /phpinfo.php, /credentials.json
Seen: 2026-09-16 13:08-13:09 EDT
- 13:08:24 - GET /.env.stage HTTP/2.0 returned 403
- 13:08:31 - GET /id_rsa HTTP/1.1 returned 404
- 13:08:47 - GET /Dockerfile HTTP/1.1 returned 404
- 13:08:39 - POST /api/designer/v1/file-content HTTP/1.1 returned 404
Categories: Web App Attack, Bad Web Bot
show less
Path traversal (/proc/self/environ), and API endpoint discovery, all returning 403/404.
Target: HTTP ...
show morePath traversal (/proc/self/environ), and API endpoint discovery, all returning 403/404.
Target: HTTP 80/443.tech - GET /.env, /.env.save, /etc/.env, /.aws/config, /userfiles/x?path=../../../../proc/self/environ, /swagger.json, /api/graphql, /api/config, id_rsa, id_ed25519, server.key, credent...
Seen: 2026-09-16 13:27-13:28 EDT
- 13:28:06 - GET /userfiles/x?path=../../../../proc/self/environ HTTP/2.0 returned 403
- 13:28:08 - GET /.env HTTP/2.0 returned 403
- 13:28:10 - GET /etc/.env HTTP/2.0 returned 403
- 13:27:54 - GET /.env.production?import&raw HTTP/2.0 returned 403
Categories: Web App Attack, Bad Web Bot
show less
Path traversal, and API probes, all returning 403/404.
Target: HTTP 80/443.tech - GET /.env, /.env.p ...
show morePath traversal, and API probes, all returning 403/404.
Target: HTTP 80/443.tech - GET /.env, /.env.production, /static/../.env, /userfiles/x?path=../../../../proc/self/environ, /api/fs/exec, /id_rsa, /id_ed25519, /server.key, /api/v1/models
Seen: 2026-09-16 13:23-13:24 EDT
- 13:24:16 - GET /userfiles/x?path=../../../../proc/self/environ HTTP/1.1 returned 403
- 13:24:02 - GET /.env.production?raw HTTP/2.0 returned 403
- 13:24:18 - GET /id_ed25519 HTTP/2.0 returned 404
- 13:24:06 - POST /api/fs/exec HTTP/2.0 returned 404
Categories: Web App Attack, Bad Web Bot
show less
Rapid web shell scanning with ~30+ requests to random .php paths on WordPress site, all returned 404 ...
show moreRapid web shell scanning with ~30+ requests to random .php paths on WordPress site, all returned 404.
Target: HTTPS 443, GET multiple random .php paths (wp-9xay.php, wafs.php, n30n.php, manager.php, 1.php, etc.)
Seen: 2026-09-16 06:22 EDT
- 06:22:58-06:23:14: ~30 rapid GET requests to random .php paths (wp-9xay.php, wafs.php, n30n.php, wp-update.php, hosty.php, gssdd.php, etc.) all returned 404
- 06:23:19: IDS alert triggered - Multiple web server 400 error codes from same source ip 4.224.45.129
Categories: Web App Attack, Bad Web Bot
show less
SSH brute-force attempt from known-compromised host to port 22.
Target: SSH 22, connection attempt f ...
show moreSSH brute-force attempt from known-compromised host to port 22.
Target: SSH 22, connection attempt from 195.178.110.218:58231 to our network
Seen: 2026-09-16 06:01 EDT
- 06:01:03: IDS ET COMPROMISED rule [1:2500016:7746] - Known Compromised or Hostile Host Traffic TCP 195.178.110.218:58231 -> port 22
- 06:01:04: firewall block - TCP SYN from 195.178.110.218 port 58231 to port 22
Categories: SSH, Port Scan
show less
Rapid web shell scanning with ~28 requests to .php paths (shlo.php, priv8.php, wso.php, 1.php, file. ...
show moreRapid web shell scanning with ~28 requests to .php paths (shlo.php, priv8.php, wso.php, 1.php, file.php, etc.) and WordPress probe paths, all returned 404.
Target: HTTPS 443, GET multiple .php paths and wp-includes/wp-trackback.tech
Seen: 2026-09-16 05:24 EDT
- 05:24:31-05:24:37: ~28 rapid GET requests to web shell paths (shlo.php, priv8.php, wso.php, 1.php, file.php, abcd.php, admin.php, etc.) and wp-includes/wp-trackback - all returned 404
- 05:24:37: IDS alert - Sustained web attack from known-hostile source 45.138.16.184
Categories: Web App Attack, Bad Web Bot, Hacking
show less
Probed sensitive file /.env on WordPress site.
Target: HTTPS 443, GET /.env.tech
Seen: 2026-09-16 05 ...
show moreProbed sensitive file /.env on WordPress site.
Target: HTTPS 443, GET /.env.tech
Seen: 2026-09-16 05:52 EDT
- 05:52:38: GET /.env returned 403 (nginx)
- 05:52:39: IDS alert - Malware C2 infrastructure detecting GET /.env
Categories: Web App Attack, Bad Web Bot
show less
Web scanner probing WordPress wp-includes paths; requests returned 404.
Target: HTTP 80, GET //wp2/w ...
show moreWeb scanner probing WordPress wp-includes paths; requests returned 404.
Target: HTTP 80, GET //wp2/wp-includes/wlwmanifest.xml, //media/wp-includes/wlwmanifest.xml
Seen: 2026-09-16 04:51 EDT
- 04:51:00: GET //wp2/wp-includes/wlwmanifest.xml returned 404
- 04:51:00: GET //media/wp-includes/wlwmanifest.xml returned 404
Categories: Web App Attack, Bad Web Bot
show less
Sustained web application attack probing WordPress wp-includes paths; 5 requests returned 403.
Targe ...
show moreSustained web application attack probing WordPress wp-includes paths; 5 requests returned 403.
Target: HTTPS 443, GET /wp-includes/ paths (IXR, js, js/plupload, js/codemirror, widgets)
Seen: 2026-09-16 04:22 EDT
- 04:22:56-04:22:59: 5 rapid GET requests to /wp-includes/IXR/, /wp-includes/js/, /wp-includes/js/plupload/, /wp-includes/js/codemirror/, /wp-includes/widgets/ returned 403
- IDS alert: sustained web attack from known-hostile source 91.224.92.159
Categories: Web App Attack, Bad Web Bot, Hacking
show less
Automated web vulnerability scanner probed 50+ sensitive file paths (config files, backup archives, ...
show moreAutomated web vulnerability scanner probed 50+ sensitive file paths (config files, backup archives, Git/SVN dirs, secret keys, deployment scripts).tech. All requests returned 403/404.
Target: HTTP 80/443, GET paths including /.git/logs/HEAD, /.svn/entries, /storage/oauth-private.key, /wwwroot.bak, /deploy.sh, /sites/default/settings.php.save, /client_secrets.json, /.vscode/settings.json...
Seen: 2026-09-16 03:40 EDT
- 03:40:06-03:40:11: ~50 rapid GET requests to sensitive paths including /.git/logs/HEAD, /.svn/entries, /storage/oauth-private.key, /storage/oauth-public.key, /.vscode/settings.json, /.claude/settings.json, /wwwroot.bak, /www.bak, /deploy.sh, /setup.sh, /sites/default/settings.php.save, /client_secrets.json, /secret_token.rb, /.github/workflows/build.yaml
- All requests returned 403 (nginx access forbidden) or 404 (upstream not found) - fully blocked
- IDS alert: Multiple web server 400 error codes from same source ip
Categories: Web App Attack, Bad Web Bot, Hacking
show less
Exploited HackingTrio scanner probing with "Hello, World" user agent โ POST to web shell exploit pat ...
show moreExploited HackingTrio scanner probing with "Hello, World" user agent โ POST to web shell exploit path (GponForm/diag_Form).
Target: HTTP 80, POST /GponForm/diag_Form?images/ with HackingTrio UA 'Hello, World'
Seen: 2026-09-16 02:37 EDT
- 02:37:35: IDS rule ET EXPLOIT HackingTrio UA (Hello, World) triggered โ POST to /GponForm/diag_Form?images/ HTTP/1.1 with UA 'Hello, World' โ got 404
- 02:37:36: IDS rule ET WEB_SERVER WebShell Generic - wget http - POST triggered on same connection โ got 404
- 02:37:37-02:37:38: firewall block for 119.73.19.184:53356 -> port 80 (TCP)
Categories: Web App Attack, Bad Web Bot
show less
Automated WordPress web shell scanner probing 20+ PHP paths.tech; all requests returned 404/403.
Tar ...
show moreAutomated WordPress web shell scanner probing 20+ PHP paths.tech; all requests returned 404/403.
Target: HTTP 80/443.tech, GET paths including /000.php, /wp-admin/css/about.php, /txets.php, /ioxi-o.php, /dex.php, /style.php, /wp-mail.php, /bless.php, /hp2.php and 15+ other web shell probes
Seen: 2026-09-16 00:06 EDT
- 00:06:57 GET /000.php โ 404, Go-http-client/2.0
- 00:06:57 GET /wp-admin/css/about.php โ 403, upstream=
- 00:06:58 GET /wp-includes/hp2.php โ 404, Go-http-client/2.0
- 00:06:59 GET /dex.php โ 404, Go-http-client/2.0
- 00:07:01 GET /wp-mail.php โ 500, Go-http-client/2.0
- 00:07:03 GET /wp-content/themes/txets.php โ 404, Go-http-client/2.0
- 00:07:04 GET /php8.php โ 404, Go-http-client/2.0
Categories: Web App Attack, Bad Web Bot
show less
CVE-2025-55182 (React2Shell) exploit attempt, JavaScript __proto__ prototype pollution, and multi-pa ...
show moreCVE-2025-55182 (React2Shell) exploit attempt, JavaScript __proto__ prototype pollution, and multi-path web probing from HighPerfScanner bot, all blocked at firewall.
Target: HTTPS 443, exploit paths: CVE-2025-55182 React2Shell, __proto__ prototype pollution in POST /, GET /.git/config, GET /actuator/env
Seen: 2026-09-15 21:00 EDT
- 2026-09-15 21:00:24 - IDS IDS: CVE-2025-55182 React2Shell exploit attempt from 204.76.203.31:45394 to port 443
- 2026-09-15 21:00:24 - IDS IDS: JS prototype pollution via __proto__ in HTTP body from 204.76.203.31:45394 to port 443
- 2026-09-15 21:00:24 - Nginx received GET /.git/config 400 from 204.76.203.31
- 2026-09-15 21:00:24 - Nginx received GET /actuator/env 400 from 204.76.203.31
- 2026-09-15 21:00:24 - Nginx received POST / with exploit payload 400 from 204.76.203.31
- 2026-09-15 21:00:24 - Nginx received GET / from HighPerfScanner/10G 444 from 204.76.203.31
- 2026-09-15 21:00:23 - IDS IDS: CVE-2025-55182 + prototype pollution also s...
Categories: Web App Attack, Port Scan
show less
Plus sustained port scanning on ports 80/443.
Target: POST with React2Shell exploit payload and __pr ...
show morePlus sustained port scanning on ports 80/443.
Target: POST with React2Shell exploit payload and __proto__ prototype pollution in HTTP body
Seen: 2026-09-15 19:58 EDT
- 2026-09-15 19:58:23 - IDS IDS detected CVE-2025-55182 (React2Shell) exploit attempt and JavaScript prototype pollution from 187.77.129.24:39928 targeting port 80
- 2026-09-15 19:58:22 - POST / HTTP/1.1 returned 401 nginx for this IP, indicating exploit request was rejected at proxy layer
Categories: Web App Attack, Port Scan
show less
Known-malicious IP attempted telnet connection to lab infrastructure. Target: TCP 23 (telnet) on [ou ...
show moreKnown-malicious IP attempted telnet connection to lab infrastructure. Target: TCP 23 (telnet) on [our server]. Seen: 2026-09-15 12:33 US Eastern. Evidence: Suricata ET COMPROMISED alert [1:2500012:7745] at 12:33:42: TCP SYN from 176.65.139.206:53483 to [our server]:23; [internal host] filterlog at 12:33:42: packet blocked (rule 0,52) on cc1 interface.
show less
Active command injection attacks against a [internal host] server, successfully executing shell comm ...
show moreActive command injection attacks against a [internal host] server, successfully executing shell commands to drop a PHP webshell. Target: HTTPS 443 ([internal host]), GET /x$(x=... base64-encoded bash injection) targeting path traversal/RCE vulnerability.. Seen: 2026-09-15 08:00 to 09:40 US Eastern. Evidence: Graylog logs show continuous GET requests from 139.28.18.122 containing bash command substitution syntax returning HTTP 200 responses; Requests attempt to write a base64-decoded PHP file 'shx77b17.php' and cURL a command-and-control webhook; Attacker process (pid 34976) observed on the target host executing system reconnaissance commands.
show less
Web App AttackHacking
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.