Aggressive automated credential and vulnerability scan. This IP sent 578 requests targeting 239 dist ...
show moreAggressive automated credential and vulnerability scan. This IP sent 578 requests targeting 239 distinct paths in two bursts on 2026-08-12: 344 requests from 04:37:16โ04:37:28 UTC and 234 requests from 05:49:46โ05:49:55 UTC. Targets included /.env variants, /.aws/credentials, /.ssh/id_rsa, /.git/config, /.htpasswd, cloud service-account files, private keys, Terraform state, /actuator/env, Swagger, GraphQL and administrative endpoints. The source alternated between a spoofed Applebot-Extended user agent and a Chrome user agent during the same attack. Responses were primarily HTTP 403/404/301. This was systematic credential discovery and web-application reconnaissance, not legitimate crawling.
show less
Automated credential and vulnerability scan. At least 100 requests were sent in approximately 77 sec ...
show moreAutomated credential and vulnerability scan. At least 100 requests were sent in approximately 77 seconds on 2026-08-12 between 13:40:04 and 13:41:21 UTC. Targets included /.env, /.aws/credentials, /.ssh/id_rsa, /.gcp/credentials.json, /.kube/config, /.docker/config.json, /.git/HEAD, /config.php.bak, /private-key, service-account files, Kubernetes tokens, /@fs/ path-traversal targets and /_ignition/health-check. The source rotated spoofed ChatGPT-User, OAI-SearchBot, Google-Extended and Amzn-SearchBot user agents to disguise the scan. All attempts returned HTTP 403 or 404; no compromise was detected.
show less
Automated HTTP vulnerability scanner sent more than 120 malicious requests attempting to retrieve ex ...
show moreAutomated HTTP vulnerability scanner sent more than 120 malicious requests attempting to retrieve exposed credentials, private SSH keys, configuration files and database backups. Requested paths included /.env, /.env.production, /.env.backup, /id_rsa, /.ssh/id_rsa.pem, /database.sql, /backup.sql.gz, /phpinfo.php, /config/database.yml and /composer.json. The scanner also used /./ path-normalisation variants in apparent attempts to bypass URL filtering. Requests were detected and blocked as hostile-path activity. Earliest observation: 2026-06-22 02:09:26 Europe
show less
Repeated malicious POST requests to /index.php targeting a WordPress site. Payload contained URL-enc ...
show moreRepeated malicious POST requests to /index.php targeting a WordPress site. Payload contained URL-encoded binary garbage including NULL byte characters (%00), triggering firewall rule: "ASCII character 0x00 (NULL byte)" in POST data. Request was blocked as CRITICAL by WAF. No legitimate user-agent behavior observed; appears to be automated exploit/scanner traffic.
show less
Malicious scanner probing for exposed configuration/secrets files.
The same IP requested suspicio ...
show moreMalicious scanner probing for exposed configuration/secrets files.
The same IP requested suspicious sensitive paths within seconds while rotating fake crawler user agents:
* `/application.yml`
* `/secrets.yml`
User agents used:
* `Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot`
* `Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)`
The bot identity was not verified and appears spoofed. This looks like automated reconnaissance for leaked YAML configuration files, secrets, credentials, or application settings.
show less
Automated web application attack / sensitive file probing. The IP requested /.env.production, a high ...
show moreAutomated web application attack / sensitive file probing. The IP requested /.env.production, a high-risk environment configuration file path commonly targeted to steal production secrets such as database credentials, API keys, SMTP passwords, tokens, and app keys. This was not legitimate visitor traffic. Request was blocked by WAF
show less
Automated web application scan / probing for exposed environment files. The IP requested /.env.local ...
show moreAutomated web application scan / probing for exposed environment files. The IP requested /.env.local, a high-risk sensitive configuration file path commonly targeted to steal secrets such as database credentials, API keys, SMTP passwords, and application tokens. This was not normal user traffic. Request was blocked by WAF
show less
Repeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true. This endpo ...
show moreRepeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true. This endpoint is commonly targeted to detect exposed application configuration. Pattern matches automated vulnerability scanning across multiple IPs.
show less
Repeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true. This endpo ...
show moreRepeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true. This endpoint is commonly targeted to detect exposed application configuration. Pattern matches automated vulnerability scanning across multiple IPs.
show less
Automated probing for authentication endpoints. Requests include /admin, /login, /register, /user/lo ...
show moreAutomated probing for authentication endpoints. Requests include /admin, /login, /register, /user/login, /administrator/. Multiple inconsistent user agents (Android, iPhone, iPad, Linux, Mac) within seconds indicate spoofing. Pattern consistent with automated scanning for exposed login panels.
show less
Repeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across mult ...
show moreRepeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across multiple IPs. This endpoint is commonly targeted to detect exposed application configuration. Pattern indicates automated vulnerability scanning for misconfigured web applications.
show less
Repeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across mult ...
show moreRepeated probing of Joomla API endpoint /api/index.php/v1/config/application?public=true across multiple IPs. This endpoint is commonly targeted to detect exposed application configuration. Pattern indicates automated vulnerability scanning for misconfigured web applications.
show less
Bad Web BotWeb App AttackHacking
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.