A brute-force attack from IP 149.126.102.98 via NTLM authentication, with rapid sequential attempts ...
show moreA brute-force attack from IP 149.126.102.98 via NTLM authentication, with rapid sequential attempts to guess passwords for accounts.
show less
159.253.120.107 - - [23/Apr/2025:16:32:20 +0300] "GET /phpmyadmin/scripts/setup.php HTTP/1.1" 404 68 ...
show more159.253.120.107 - - [23/Apr/2025:16:32:20 +0300] "GET /phpmyadmin/scripts/setup.php HTTP/1.1" 404 682 "-" "python-requests/2.27.1"
An automated phpMyAdmin vulnerability probe from IP 159.253.120.107, where the attacker specifically targeted the setup.php script in phpMyAdmin's /scripts/ directory using a Python Requests library user-agent, which is a known attack vector that could allow remote code execution in vulnerable phpMyAdmin versions.
show less
196.251.81.150 - - [24/Apr/2025:03:39:27 +0300] "GET /pma2005/ HTTP/1.1" 404 682 "https://196.188.10 ...
show more196.251.81.150 - - [24/Apr/2025:03:39:27 +0300] "GET /pma2005/ HTTP/1.1" 404 682 "https://196.188.108.34/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1"
196.251.81.150 - - [24/Apr/2025:03:39:26 +0300] "GET /mysqlmanager/ HTTP/1.1" 404 682 "https://196.188.108.34/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1"
A targeted scan for phpMyAdmin installations from IP 196.251.81.150, where the attacker systematically checked for multiple outdated phpMyAdmin versions (2.8.0.1 through 2.8.2) and alternative database management paths (/pma2005/, /mysqlmanager/, /sqlmanager/) using a spoofed Firefox 9.0.1 user agent on Windows XP.
show less
43.155.14.19 - - [22/Apr/2025:20:08:08 +0300] "GET /data.rar HTTP/1.1" 404 682 "-" "Mozilla/5.0 (Mac ...
show more43.155.14.19 - - [22/Apr/2025:20:08:08 +0300] "GET /data.rar HTTP/1.1" 404 682 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/65.0.3325.162 Safari/537.36 OPR/51.0.2830.55"
43.155.14.19 - - [22/Apr/2025:20:08:08 +0300] "GET /bbs.sql.gz HTTP/1.1" 404 682 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.80 Safari/537.36 OPR/56.0.3051.116"
An automated scan for exposed backup and database files from IP 43.155.14.19, where the attacker systematically probed for archives (.rar, .7z, .tar.tgz), database dumps (.sql, .sql.gz), and Java/web application files (.jar, .zip) using spoofed user agents mimicking outdated browsers on multiple platforms (macOS, Windows, Linux).
show less
13.66.246.180 - - [20/Apr/2025:21:30:11 +0000] "GET /phpinfo.php HTTP/1.1" 404 134 "-" "Mozilla/5.0 ...
show more13.66.246.180 - - [20/Apr/2025:21:30:11 +0000] "GET /phpinfo.php HTTP/1.1" 404 134 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
13.66.246.180 - - [20/Apr/2025:21:30:10 +0000] "GET /config.json HTTP/1.1" 404 134 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
An automated reconnaissance activity from IP 13.66.246.180, where the attacker systematically probed for sensitive files and debugging endpoints including PHP information leaks (phpinfo.php, _profiler/phpinfo), configuration files (.env, .env.project, config.json), Yii framework debug panels (/debug/default/view), and Symfony development tools (frontend_dev.php).
show less
172.232.159.13 - - [19/Apr/2025:20:02:24 +0300] "GET /indice.cfm HTTP/1.1" 404 682 "-" "curl/7.54.0" ...
show more172.232.159.13 - - [19/Apr/2025:20:02:24 +0300] "GET /indice.cfm HTTP/1.1" 404 682 "-" "curl/7.54.0"
172.232.159.13 - - [19/Apr/2025:20:02:24 +0300] "GET /inicio.jhtml HTTP/1.1" 404 682 "-" "curl/7.54.0"
Automated scanning activity from IP 172.232.159.13 (with an initial typo showing as 72.232.159.13), where the attacker conducted a multi-technology probe by checking for common web administration interfaces and index files across different platforms - testing ColdFusion (indice.cfm), Java (admin.jsp, inicio.jhtml), Perl (base.pl, indice.pl), and basic HTTP access, using both blank user-agent requests and curl/7.54.0.
show less
13.78.163.10 - - [20/Apr/2025:23:17:07 +0300] "GET /phpinfo.php HTTP/1.1" 404 682 "-" "Mozilla/5.0 ( ...
show more13.78.163.10 - - [20/Apr/2025:23:17:07 +0300] "GET /phpinfo.php HTTP/1.1" 404 682 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
13.78.163.10 - - [20/Apr/2025:23:17:06 +0300] "GET /_profiler/phpinfo HTTP/1.1" 404 682 "-"
Reconnaissance activity from IP 13.78.163.10, where an attacker probed for sensitive files and PHP information leaks by attempting to access phpinfo.php, /_profiler/phpinfo, /?phpinfo=1, and various configuration files (.json, config.json) using a spoofed Firefox 77 user agent (Mac OS X)
show less
43.128.72.97 - - [16/Apr/2025:16:10:56 +0000] "GET /api/actuator/ HTTP/1.1" 404 162 "-" "Mozilla/5.0 ...
show more43.128.72.97 - - [16/Apr/2025:16:10:56 +0000] "GET /api/actuator/ HTTP/1.1" 404 162 "-" "Mozilla/5.0 (iPhone; U; CPU iPhone OS 4_2_1 like Mac OS X; nb-no) AppleWebKit/533.17.9 (KHTML, like Gecko) Version/5.0.2 Mobile/8C148a Safari/6533.18.5"
43.128.72.97 - - [16/Apr/2025:16:10:55 +0000] "GET /actuator/;/env HTTP/1.1" 404 162 "-" "Mozilla/5.0 (iPhone; U; CPU iPhone OS 4_2_1 like Mac OS X; nb-no) AppleWebKit/533.17.9 (KHTML, like Gecko) Version/5.0.2 Mobile/8C148a Safari/6533.18.5"
43.128.72.97 - - [16/Apr/2025:16:10:54 +0000] "GET /actuator/env HTTP/1.1" 404 162 "-" "Mozilla/5.0 (iPhone; U; CPU iPhone OS 4_2_1 like Mac OS X; nb-no) AppleWebKit/533.17.9 (KHTML, like Gecko) Version/5.0.2 Mobile/8C148a Safari/6533.18.5"
This log shows automated scanning activity from 43.128.72.97, where the attacker probed for Spring Boot Actuator endpoints (/actuator/env, /api/actuator/, and a potential path traversal attempt /actuator/;/env) using a spoofed iPhone Safari (iOS 4.2.1) user agent to disguise the requests
show less
A brute-force attack from IP 185.7.214.89 via NTLM authentication, with rapid sequential attempts to ...
show moreA brute-force attack from IP 185.7.214.89 via NTLM authentication, with rapid sequential attempts to guess passwords for accounts.
show less
112.81.90.243 - - [16/Apr/2025:01:15:30 -0400] "GET /.env.bak HTTP/1.1" 404 153 "-" "Mozilla/5.0 (iP ...
show more112.81.90.243 - - [16/Apr/2025:01:15:30 -0400] "GET /.env.bak HTTP/1.1" 404 153 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_5_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Mobile/15E148 Safari/604.1" "-"
An attempted security breach from IP 112.81.90.243, where the attacker tried to access a backup environment file (/.env.bak) using what appears to be a spoofed iPhone Safari browser (iOS 17.5.1) user agent.
show less
117.133.133.87 - - [15/Apr/2025:23:05:03 +0300] "GET /index.php?lang=../../../../../../../../tmp/ind ...
show more117.133.133.87 - - [15/Apr/2025:23:05:03 +0300] "GET /index.php?lang=../../../../../../../../tmp/index1 HTTP/1.1" 404 682 "-" "Custom-AsyncHttpClient"
This log entry records a failed Local File Inclusion (LFI) / Directory Traversal attack from IP 117.133.133.87, where the attacker attempted to exploit the lang parameter in index.php to access /tmp/index1 using a path traversal payload.
show less
89.189.74.70 - - [13/Apr/2025:18:30:41 +0300] "GET /getGfiUpgradeFile?fileName=../../../../../../../ ...
show more89.189.74.70 - - [13/Apr/2025:18:30:41 +0300] "GET /getGfiUpgradeFile?fileName=../../../../../../../etc/passwd HTTP/1.1" 404 682 "-" "Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
89.189.74.70 - - [13/Apr/2025:18:30:39 +0300] "GET /common/download/resource?resource=/profile/../../../../etc/passwd HTTP/1.1" 404 682 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.2.17"
89.189.74.70 - - [13/Apr/2025:18:30:39 +0300] "GET /sysaid/getGfiUpgradeFile?fileName=../../../../../../../etc/passwd HTTP/1.1" 404 682 "-" "Mozilla/5.0 (SS; Linux i686; rv:120.0) Gecko/20100101 Firefox/120.0"
The log shows multiple attempts by the IP address 89.189.74.70 to exploit path traversal vulnerabilities in different web applications. This attacker is trying to access sensitive system files (/etc/passwd) by manipulating file path parameters
show less
The logs are showing a wave of requests for standard ".well-known" files, most of which are part of ...
show moreThe logs are showing a wave of requests for standard ".well-known" files, most of which are part of browser privacy initiatives, federated identity systems, or mobile app integrations.
104.196.163.251 - - [10/Apr/2025:01:21:00 +0000] "GET /.well-known/related-website-set.json HTTP/1.1" 404 33 "https://member.redcrosseth.org/" "Mozilla/5.0 (Linux; Android 8.1.0; Moto G (4)) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Mobile Safari/537.36 PTST/250402.153735"
show less
Web App Attack
By clicking βAccept allβ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.