Automated HTTP vulnerability scanner sent more than 120 malicious requests attempting to retrieve ex ...
show moreAutomated HTTP vulnerability scanner sent more than 120 malicious requests attempting to retrieve exposed credentials, private SSH keys, configuration files and database backups. Requested paths included /.env, /.env.production, /.env.backup, /id_rsa, /.ssh/id_rsa.pem, /database.sql, /backup.sql.gz, /phpinfo.php, /config/database.yml and /composer.json. The scanner also used /./ path-normalisation variants in apparent attempts to bypass URL filtering. Requests were detected and blocked as hostile-path activity. Earliest observation: 2026-06-22 02:09:26 Europe
show less
Repeated malicious POST requests to /index.php targeting a WordPress site. Payload contained URL-enc ...
show moreRepeated malicious POST requests to /index.php targeting a WordPress site. Payload contained URL-encoded binary garbage including NULL byte characters (%00), triggering firewall rule: "ASCII character 0x00 (NULL byte)" in POST data. Request was blocked as CRITICAL by WAF. No legitimate user-agent behavior observed; appears to be automated exploit/scanner traffic.
show less
Malicious scanner probing for exposed configuration/secrets files.
The same IP requested suspicio ...
show moreMalicious scanner probing for exposed configuration/secrets files.
The same IP requested suspicious sensitive paths within seconds while rotating fake crawler user agents:
* `/application.yml`
* `/secrets.yml`
User agents used:
* `Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot`
* `Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)`
The bot identity was not verified and appears spoofed. This looks like automated reconnaissance for leaked YAML configuration files, secrets, credentials, or application settings.
show less
Automated web application attack / sensitive file probing. The IP requested /.env.production, a high ...
show moreAutomated web application attack / sensitive file probing. The IP requested /.env.production, a high-risk environment configuration file path commonly targeted to steal production secrets such as database credentials, API keys, SMTP passwords, tokens, and app keys. This was not legitimate visitor traffic. Request was blocked by WAF
show less
Automated web application scan / probing for exposed environment files. The IP requested /.env.local ...
show moreAutomated web application scan / probing for exposed environment files. The IP requested /.env.local, a high-risk sensitive configuration file path commonly targeted to steal secrets such as database credentials, API keys, SMTP passwords, and application tokens. This was not normal user traffic. Request was blocked by WAF
show less
Repeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true. This endpo ...
show moreRepeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true. This endpoint is commonly targeted to detect exposed application configuration. Pattern matches automated vulnerability scanning across multiple IPs.
show less
Repeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true. This endpo ...
show moreRepeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true. This endpoint is commonly targeted to detect exposed application configuration. Pattern matches automated vulnerability scanning across multiple IPs.
show less
Automated probing for authentication endpoints. Requests include /admin, /login, /register, /user/lo ...
show moreAutomated probing for authentication endpoints. Requests include /admin, /login, /register, /user/login, /administrator/. Multiple inconsistent user agents (Android, iPhone, iPad, Linux, Mac) within seconds indicate spoofing. Pattern consistent with automated scanning for exposed login panels.
show less
Repeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across mult ...
show moreRepeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across multiple IPs. This endpoint is commonly targeted to detect exposed application configuration. Pattern indicates automated vulnerability scanning for misconfigured web applications.
show less
Repeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across mult ...
show moreRepeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across multiple IPs. This endpoint is commonly targeted to detect exposed application configuration. Pattern indicates automated vulnerability scanning for misconfigured web applications.
show less
Repeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across mult ...
show moreRepeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across multiple IPs. This endpoint is commonly targeted to detect exposed application configuration. Pattern indicates automated vulnerability scanning for misconfigured web applications.
show less
Repeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across mult ...
show moreRepeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across multiple IPs. This endpoint is commonly targeted to detect exposed application configuration. Pattern indicates automated vulnerability scanning for misconfigured web applications.
show less
Repeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across mult ...
show moreRepeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across multiple IPs. This endpoint is commonly targeted to detect exposed application configuration. Pattern indicates automated vulnerability scanning for misconfigured web applications.
show less
Repeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across mult ...
show moreRepeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across multiple IPs. This endpoint is commonly targeted to detect exposed application configuration. Pattern indicates automated vulnerability scanning for misconfigured web applications.
show less
HackingBad Web BotWeb App Attack
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.