A reconnaissance scan targeting various possible directories for .env files (/auth/.env, /src/.env, ...
show moreA reconnaissance scan targeting various possible directories for .env files (/auth/.env, /src/.env, /private/.env, /shared/.env, /web/.env), which often contain environment variables, database credentials, API keys, and secrets.
156.242.125.25 - - [09/Apr/2025:19:23:47 +0000] "GET /master/.env HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.5845.140 Safari/537.36"
156.242.125.25 - - [09/Apr/2025:19:23:47 +0000] "GET /src/.env HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.5845.140 Safari/537.36"
show less
Automated reconnaissance activity from the IP 103.195.30.139. The user-agent mimics a mobile browser ...
show moreAutomated reconnaissance activity from the IP 103.195.30.139. The user-agent mimics a mobile browser, but the behavior is very indicative of a scanner or bot looking for exposed development/debug files and misconfigurations. Here's what stands out:
Targeted endpoints:
phpinfo variations (php_info.php, php.php, /info.php, etc.)
Symfony debug/profiler paths (/_profiler/phpinfo, /app_dev.php/_profiler/phpinfo)
Config file paths (/.env.dev.local, /config/aws.yml)
Other generic files (/temp.php, /linusadmin-phpinfo.php, /infos.php)
show less
111.41.147.227 - - [06/Apr/2025:15:03:07 +0000] "GET /test.cgi HTTP/1.1" [Reducted] ; /bin/cat /etc/ ...
show more111.41.147.227 - - [06/Apr/2025:15:03:07 +0000] "GET /test.cgi HTTP/1.1" [Reducted] ; /bin/cat /etc/passwd" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6.1 Safari/605.1.15"
This is a Shellshock exploit payload targeting a CGI script (/test.cgi), the attacker is trying to read the contents of /etc/passwd
show less
41.35.103.233 - - [07/Apr/2025:07:59:21 +0300] "POST /xmlrpc.php HTTP/1.1" 405 568 "-" "Mozilla/5.0 ...
show more41.35.103.233 - - [07/Apr/2025:07:59:21 +0300] "POST /xmlrpc.php HTTP/1.1" 405 568 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
This IP 41.35.103.233 request to **/xmlrpc.php** using the POST method is a common signature of WordPress-targeted probing, specifically for vulnerabilities related to xmlrpc.php
show less
209.38.250.32 - - [04/Apr/2025:06:35:08 +0300] "GET /HNAP1 HTTP/1.1" 404 682 "-" "Mozilla/5.0 (compa ...
show more209.38.250.32 - - [04/Apr/2025:06:35:08 +0300] "GET /HNAP1 HTTP/1.1" 404 682 "-" "Mozilla/5.0 (compatible; Odin; https://docs.getodin.com/)"
This IP address 209.38.250.32 made an attempt to access the /HNAP1 endpoints on the web server, which is commonly targeted during scans for vulnerable network devices
show less
161.35.235.208 - - [02/Apr/2025:16:32:26 +0000] "GET /admin/php/?file=memeklo.hitam HTTP/1.1" 404 12 ...
show more161.35.235.208 - - [02/Apr/2025:16:32:26 +0000] "GET /admin/php/?file=memeklo.hitam HTTP/1.1" 404 12112 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.78 Safari/537.36"
161.35.235.208 - - [02/Apr/2025:16:32:26 +0000] "GET /public/multiuploader/server/php/?file=memeklo.hitam HTTP/1.1" 404 12130 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.78 Safari/537.36"
This IP 161.35.235.208 attempted to access potentially vulnerable PHP file upload directories (/admin/php/ and /public/multiuploader/server/php/) with a specific filename "memeklo.hitam"
show less
52.77.244.71 - - [02/Apr/2025:18:23:46 +0000] "GET //web/.env HTTP/1.1" 404 119 "https://www.google. ...
show more52.77.244.71 - - [02/Apr/2025:18:23:46 +0000] "GET //web/.env HTTP/1.1" 404 119 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_1_5) Gecko/20031701 Firefox/13.0"
52.77.244.71 - - [02/Apr/2025:18:23:46 +0000] "GET //admin/.env HTTP/1.1" 404 121 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_1_5) Gecko/20031701 Firefox/13.0"
This IP 52.77.244.71 attempted to access .env files in directories such as /web/ and /admin/. These files typically contain sensitive configuration details.
show less
103.161.34.89 - - [01/Apr/2025:17:43:36 +0300] "GET /%2e%2e/%2e%2e/etc/passwd HTTP/1.1" 400 166 "-" ...
show more103.161.34.89 - - [01/Apr/2025:17:43:36 +0300] "GET /%2e%2e/%2e%2e/etc/passwd HTTP/1.1" 400 166 "-" "-"
103.161.34.89 - - [01/Apr/2025:17:43:35 +0300] "GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=%27;id;%27 HTTP/1.1" 404 682 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.120 Safari/537.36"
This IP address was observed engaging in malicious web-based activity, as evidenced by access logs. The behavior included repeated attempts to exploit vulnerabilities, like unauthorized access attempts to sensitive endpoints, and SQL injection attempt.
show less
A brute-force attack was attempted from IP 185.147.125.36 using NTLM authentication. This attacker t ...
show moreA brute-force attack was attempted from IP 185.147.125.36 using NTLM authentication. This attacker tried logging into [REDACTED] server several times with an invalid username, triggering multiple failed logins
show less
104.152.52.52 - - [31/Mar/2025:22:42:27 +0000] "POST /sdk HTTP/1.1" 404 162 "-" "Mozilla/5.0 (compat ...
show more104.152.52.52 - - [31/Mar/2025:22:42:27 +0000] "POST /sdk HTTP/1.1" 404 162 "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)"
This IP 104.152.52.52 attempted a POST request using the Nmap Scripting Engine, which is used for reconnaissance and vulnerability scanning
show less
85.215.138.170 - - [30/Mar/2025:14:54:37 +0000] "GET /test/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more85.215.138.170 - - [30/Mar/2025:14:54:37 +0000] "GET /test/wp-includes/wlwmanifest.xml HTTP/1.1" 404 564 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
85.215.138.170 - - [30/Mar/2025:14:54:37 +0000] "GET /wp1/wp-includes/wlwmanifest.xml HTTP/1.1" 404 564 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
This IP 85.215.138.170 has been making multiple attempts to access "wlwmanifest.xml" files across various WordPress-related directories, such as /test/, /shop/, and /2019/. This behavior suggests an automated scan for vulnerable or outdated WordPress installations, likely targeting sites for exploitation
show less
54.177.128.99 - - [30/Mar/2025:10:46:02 +0000] "GET //web/.env HTTP/1.1" 404 119 "https://www.google ...
show more54.177.128.99 - - [30/Mar/2025:10:46:02 +0000] "GET //web/.env HTTP/1.1" 404 119 "https://www.google.com/" "Mozilla/5.0 (Windows; U; MSIE 7.0b; Macintosh; .NET CLR 2.1.12482; Intel Mac OS X 11_2_0)"
54.177.128.99 - - [30/Mar/2025:10:46:01 +0000] "GET //admin/.env HTTP/1.1" 404 121 "https://www.google.com/" "Mozilla/5.0 (Windows; U; MSIE 7.0b; Macintosh; .NET CLR 2.1.12482; Intel Mac OS X 11_2_0)"
This IP 54.177.128.99 has been attempting to access .env files in various directories, including /web/, /admin/, /site/, and others. This suggests an automated scan for environment configuration files that may contain sensitive credentials, API keys, or database connection details.
show less
Brute-ForceWeb App Attack
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.