Malicious scanner probing for exposed configuration/secrets files.
The same IP requested suspicio ...
show moreMalicious scanner probing for exposed configuration/secrets files.
The same IP requested suspicious sensitive paths within seconds while rotating fake crawler user agents:
* `/application.yml`
* `/secrets.yml`
User agents used:
* `Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot`
* `Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)`
The bot identity was not verified and appears spoofed. This looks like automated reconnaissance for leaked YAML configuration files, secrets, credentials, or application settings.
show less
Automated web application attack / sensitive file probing. The IP requested /.env.production, a high ...
show moreAutomated web application attack / sensitive file probing. The IP requested /.env.production, a high-risk environment configuration file path commonly targeted to steal production secrets such as database credentials, API keys, SMTP passwords, tokens, and app keys. This was not legitimate visitor traffic. Request was blocked by WAF
show less
Automated web application scan / probing for exposed environment files. The IP requested /.env.local ...
show moreAutomated web application scan / probing for exposed environment files. The IP requested /.env.local, a high-risk sensitive configuration file path commonly targeted to steal secrets such as database credentials, API keys, SMTP passwords, and application tokens. This was not normal user traffic. Request was blocked by WAF
show less
Repeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true. This endpo ...
show moreRepeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true. This endpoint is commonly targeted to detect exposed application configuration. Pattern matches automated vulnerability scanning across multiple IPs.
show less
Repeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true. This endpo ...
show moreRepeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true. This endpoint is commonly targeted to detect exposed application configuration. Pattern matches automated vulnerability scanning across multiple IPs.
show less
Automated probing for authentication endpoints. Requests include /admin, /login, /register, /user/lo ...
show moreAutomated probing for authentication endpoints. Requests include /admin, /login, /register, /user/login, /administrator/. Multiple inconsistent user agents (Android, iPhone, iPad, Linux, Mac) within seconds indicate spoofing. Pattern consistent with automated scanning for exposed login panels.
show less
Repeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across mult ...
show moreRepeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across multiple IPs. This endpoint is commonly targeted to detect exposed application configuration. Pattern indicates automated vulnerability scanning for misconfigured web applications.
show less
Repeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across mult ...
show moreRepeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across multiple IPs. This endpoint is commonly targeted to detect exposed application configuration. Pattern indicates automated vulnerability scanning for misconfigured web applications.
show less
Repeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across mult ...
show moreRepeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across multiple IPs. This endpoint is commonly targeted to detect exposed application configuration. Pattern indicates automated vulnerability scanning for misconfigured web applications.
show less
Repeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across mult ...
show moreRepeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across multiple IPs. This endpoint is commonly targeted to detect exposed application configuration. Pattern indicates automated vulnerability scanning for misconfigured web applications.
show less
Repeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across mult ...
show moreRepeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across multiple IPs. This endpoint is commonly targeted to detect exposed application configuration. Pattern indicates automated vulnerability scanning for misconfigured web applications.
show less
Repeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across mult ...
show moreRepeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across multiple IPs. This endpoint is commonly targeted to detect exposed application configuration. Pattern indicates automated vulnerability scanning for misconfigured web applications.
show less
Automated probing for authentication endpoints. Requests include /admin, /administrator/, /user/logi ...
show moreAutomated probing for authentication endpoints. Requests include /admin, /administrator/, /user/login, /register following initial homepage access. Multiple inconsistent user agents (Android, iPhone, Linux, Mac) within seconds indicate spoofing. Pattern consistent with reconnaissance for CMS login panels.
show less
Automated probing for admin/login endpoints. Requests include /admin, /login, /user/login, /administ ...
show moreAutomated probing for admin/login endpoints. Requests include /admin, /login, /user/login, /administrator/ and malformed path /-/-/-/-/-/-/-/-/-/-/. Multiple different user agents (Linux, iPad, Android) within seconds indicate UA spoofing. Pattern consistent with malicious scanning for authentication panels.
show less
Automated HTTP probing for sensitive files on website. Same source IP requested /docker-compose.yml, ...
show moreAutomated HTTP probing for sensitive files on website. Same source IP requested /docker-compose.yml, /.env.bak, /db.php, /composer.json, and /settings.php within the same second. User-Agent strings varied across Windows/Mac/Linux Firefox 133 at identical timestamps, indicating likely spoofing/automation. This activity matches malicious reconnaissance for exposed configuration/secrets and web application probing. No legitimate access expected.
show less
Automated scanning activity detected.
The IP performed rapid sequential requests targeting sensit ...
show moreAutomated scanning activity detected.
The IP performed rapid sequential requests targeting sensitive endpoints:
- /admin
- /administrator/
- /user/login
- /register
User-Agent strings were rotated between requests (Android, iPhone, Linux, Mac, iPad), indicating spoofing.
Request frequency and behavior are consistent with automated vulnerability scanning and credential harvesting attempts.
No legitimate browsing pattern observed.
show less
Automated probing for Joomla API configuration endpoint. Request to /api/index.php/v1/config/applica ...
show moreAutomated probing for Joomla API configuration endpoint. Request to /api/index.php/v1/config/application?public=true on a non-Joomla site. Likely reconnaissance scanning for exposed configuration data. No legitimate user behavior.
show less
Automated malicious probing against website. Source IP 45.135.193.131 requested /backend/.env and us ...
show moreAutomated malicious probing against website. Source IP 45.135.193.131 requested /backend/.env and used multiple spoofed Firefox 1.0.2 user-agent strings. This appears to be reconnaissance for exposed environment/config files and not legitimate browser traffic.
show less
Suspicious automated behavior targeting web application logic. Triggered a custom verification endpo ...
show moreSuspicious automated behavior targeting web application logic. Triggered a custom verification endpoint multiple times in rapid succession.
show less
Bad Web Bot
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.