Automated vulnerability scanning / reconnaissance. Target probing for admin interfaces and specific ...
show moreAutomated vulnerability scanning / reconnaissance. Target probing for admin interfaces and specific CMS paths (/user/login, /manager/, /bitrix/js/...). Blocked with HTTP 403.
show less
Automated vulnerability scanner targeting sensitive files, environment configurations, and cloud cre ...
show moreAutomated vulnerability scanner targeting sensitive files, environment configurations, and cloud credentials (.env, secrets.toml, id_rsa, .git/.svn, kubeconfig, terrainform, mlflow API). Generated multiple 404 and 403 errors within a few minutes. User-agents are spoofed (Safari/Firefox on macOS).
show less
Automated web scanning targeting mail and address book configurations (Autodiscover, CardDAV, CalDAV ...
show moreAutomated web scanning targeting mail and address book configurations (Autodiscover, CardDAV, CalDAV). User-Agent spoofing Thunderbird. Probing web server structure (PROPFIND/POST requests).
show less
Aggressive directory brute-forcing / reconnaissance scan from OpenBaseBot. Testing multiple sensitiv ...
show moreAggressive directory brute-forcing / reconnaissance scan from OpenBaseBot. Testing multiple sensitive paths (e.g., /uploads/, /files/, /archives/) in a single second. Acting as a bad web bot. Blocked with 403 and 404 responses.
show less
Automated vulnerability scan / brute-force attempts from this IP targeting sensitive files (.env, ph ...
show moreAutomated vulnerability scan / brute-force attempts from this IP targeting sensitive files (.env, phpinfo, wp-config, credentials) using curl/8.7.1. All malicious requests were successfully blocked (HTTP 403) by Cloudflare WAF and local rules. Contributing to community defense.
show less
91.192.215.164 ***.*** - [17/Aug/2026:10:10:39 +0200] "GET /assets/dist/main.min.css?release=r260623 ...
show more91.192.215.164 ***.*** - [17/Aug/2026:10:10:39 +0200] "GET /assets/dist/main.min.css?release=r260623-1-master-d14a HTTP/1.1" 302 250 "https://***.***/" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_0 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.6651.1964 Mobile Safari/537.36"
AND :
GET /assets/img/icons/twitter.svg HTTP/1.1
GET /assets/img/tenor-logo-white.svg HTTP/1.1
GET /assets/icons/upload-icon.svg HTTP/1.1
GET /assets/img/tenor-logo.svg HTTP/1.1
GET /assets/img/icons/imessage.svg HTTP/1.1
etc.
etc.
etc.
show less
20.51.153.15 ***.*** - [17/Aug/2026:09:57:36 +0200] "GET /wp-content/plugins/hellopress/wp_filemanag ...
show more20.51.153.15 ***.*** - [17/Aug/2026:09:57:36 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 302 250 "-" "-"
AND :
GET /this_is_a_new_hello_world.php HTTP/1.1
GET /file19.php HTTP/1.1
GET /law.php HTTP/1.1
GET /file13.php HTTP/1.1
GET /file12.php HTTP/1.1
etc.
etc.
etc.
show less
20.186.30.159 ***.*** - [17/Aug/2026:07:07:24 +0200] "GET /wp-content/plugins/hellopress/wp_filemana ...
show more20.186.30.159 ***.*** - [17/Aug/2026:07:07:24 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 302 250 "-" "-"
AND :
GET /this_is_a_new_hello_world.php HTTP/1.1
GET //aa.php HTTP/1.1
GET //av.php HTTP/1.1
GET /media.php HTTP/1.1
GET /images.php HTTP/1.1
etc.
etc.
etc.
show less
68.155.155.23 ***.*** - [16/Aug/2026:23:42:30 +0200] "GET /wp-admin/images/ HTTP/1.1" 302 250 "-" "- ...
show more68.155.155.23 ***.*** - [16/Aug/2026:23:42:30 +0200] "GET /wp-admin/images/ HTTP/1.1" 302 250 "-" "-"
AND :
GET /wp-login.php HTTP/1.1
GET /wp-content/uploads/goods.php HTTP/1.1
GET /wp-includes/ID3/ HTTP/1.1
GET /.well-known/ HTTP/1.1
GET /wso.php HTTP/1.1
etc.
show less
34.76.164.214 ***.*** - [17/Aug/2026:00:29:49 +0200] "GET /wp-json HTTP/1.1" 302 250 "-" "Mozilla/5. ...
show more34.76.164.214 ***.*** - [17/Aug/2026:00:29:49 +0200] "GET /wp-json HTTP/1.1" 302 250 "-" "Mozilla/5.0 (compatible; cohere-ai/1.0; +https://cohere.com)"
AND :
GET /rclone.conf HTTP/1.1
GET /z9x8c7v6b5-debug-trigger-*** HTTP/1.1
GET /.git-credentials HTTP/1.1
POST /graphql HTTP/1.1
GET /.gitlab-ci.yml HTTP/1.1
etc.
etc.
etc.
show less
2a01:7e03::2000:68ff:fec9:142f www.***.*** - [17/Aug/2026:03:03:47 +0200] "HEAD /wordpress/ HTTP/1.1 ...
show more2a01:7e03::2000:68ff:fec9:142f www.***.*** - [17/Aug/2026:03:03:47 +0200] "HEAD /wordpress/ HTTP/1.1" 302 - "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:127.0) Gecko/20100101 Firefox/127.0"
AND :
HEAD /new/ HTTP/1.1
HEAD /wp/ HTTP/1.1
HEAD /blog/ HTTP/1.1
HEAD /backup/ HTTP/1.1
HEAD /old/ HTTP/1.1
show less
20.79.222.117 ***.*** - [16/Aug/2026:19:26:02 +0200] "GET /wp-content/plugins/hellopress/wp_filemana ...
show more20.79.222.117 ***.*** - [16/Aug/2026:19:26:02 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 302 250 "-" "-"
AND :
GET /this_is_a_new_hello_world.php HTTP/1.1
GET //aa.php HTTP/1.1
GET //av.php HTTP/1.1
GET /media.php HTTP/1.1
GET /images.php HTTP/1.1
etc.
etc.
etc.
show less
20.218.66.54 ***.*** - [16/Aug/2026:18:30:13 +0200] "GET /wp-content/plugins/hellopress/wp_filemanag ...
show more20.218.66.54 ***.*** - [16/Aug/2026:18:30:13 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 302 250 "-" "-"
AND :
GET /this_is_a_new_hello_world.php HTTP/1.1
GET /--wp-lgj.php HTTP/1.1
GET /lkui.php HTTP/1.1
GET /h2a2ck.php HTTP/1.1
GET /worksec.php HTTP/1.1
etc.
etc.
etc.
show less
35.224.100.210 ***.*** - [16/Aug/2026:14:09:34 +0200] "GET /wp-json HTTP/1.1" 302 250 "-" "Mozilla/5 ...
show more35.224.100.210 ***.*** - [16/Aug/2026:14:09:34 +0200] "GET /wp-json HTTP/1.1" 302 250 "-" "Mozilla/5.0 (compatible; cohere-ai/1.0; +https://cohere.com)"
AND :
GET /admin/login HTTP/1.1
GET /console HTTP/1.1
GET /login HTTP/1.1
GET /manage HTTP/1.1
GET /dashboard HTTP/1.1
etc.
etc.
etc.
show less
Bad Web BotWeb App Attack
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.