Automated probing for authentication endpoints. Requests include /admin, /administrator/, /user/logi ...
show moreAutomated probing for authentication endpoints. Requests include /admin, /administrator/, /user/login, /register following initial homepage access. Multiple inconsistent user agents (Android, iPhone, Linux, Mac) within seconds indicate spoofing. Pattern consistent with reconnaissance for CMS login panels.
show less
Automated probing for admin/login endpoints. Requests include /admin, /login, /user/login, /administ ...
show moreAutomated probing for admin/login endpoints. Requests include /admin, /login, /user/login, /administrator/ and malformed path /-/-/-/-/-/-/-/-/-/-/. Multiple different user agents (Linux, iPad, Android) within seconds indicate UA spoofing. Pattern consistent with malicious scanning for authentication panels.
show less
Automated HTTP probing for sensitive files on website. Same source IP requested /docker-compose.yml, ...
show moreAutomated HTTP probing for sensitive files on website. Same source IP requested /docker-compose.yml, /.env.bak, /db.php, /composer.json, and /settings.php within the same second. User-Agent strings varied across Windows/Mac/Linux Firefox 133 at identical timestamps, indicating likely spoofing/automation. This activity matches malicious reconnaissance for exposed configuration/secrets and web application probing. No legitimate access expected.
show less
Automated scanning activity detected.
The IP performed rapid sequential requests targeting sensit ...
show moreAutomated scanning activity detected.
The IP performed rapid sequential requests targeting sensitive endpoints:
- /admin
- /administrator/
- /user/login
- /register
User-Agent strings were rotated between requests (Android, iPhone, Linux, Mac, iPad), indicating spoofing.
Request frequency and behavior are consistent with automated vulnerability scanning and credential harvesting attempts.
No legitimate browsing pattern observed.
show less
Automated probing for Joomla API configuration endpoint. Request to /api/index.php/v1/config/applica ...
show moreAutomated probing for Joomla API configuration endpoint. Request to /api/index.php/v1/config/application?public=true on a non-Joomla site. Likely reconnaissance scanning for exposed configuration data. No legitimate user behavior.
show less
Automated malicious probing against website. Source IP 45.135.193.131 requested /backend/.env and us ...
show moreAutomated malicious probing against website. Source IP 45.135.193.131 requested /backend/.env and used multiple spoofed Firefox 1.0.2 user-agent strings. This appears to be reconnaissance for exposed environment/config files and not legitimate browser traffic.
show less
Suspicious automated behavior targeting web application logic. Triggered a custom verification endpo ...
show moreSuspicious automated behavior targeting web application logic. Triggered a custom verification endpoint multiple times in rapid succession.
show less
Automated probing detected against web application.
Request details:
- Method: GET
- URI: /core ...
show moreAutomated probing detected against web application.
Request details:
- Method: GET
- URI: /core/install.php
- User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36
Behavior indicates reconnaissance for exposed installation scripts or vulnerable endpoints. This path is not present on the server and is commonly targeted during automated scans.
No legitimate user interaction expected for this endpoint.
Action taken:
- Request blocked (403/404)
- Logged for monitoring and potential blacklist
Assessment: Malicious or suspicious automated scanning activity.
show less
Automated probe targeting sensitive configuration files.
IP attempted to access:
GET /.env.stagi ...
show moreAutomated probe targeting sensitive configuration files.
IP attempted to access:
GET /.env.staging
User-Agent:
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
This pattern is consistent with vulnerability scanning for exposed environment files (.env).
Request was blocked. No successful access.
show less
GET /wp-login.php / GET /wp-admin/index.php SERVER:HTTP_USER_AGENT = Mozilla/5.0 (WordPress CMS Scan ...
show moreGET /wp-login.php / GET /wp-admin/index.php SERVER:HTTP_USER_AGENT = Mozilla/5.0 (WordPress CMS Scanner)]
WAF triggered
show less
Automated probe attempting to access /config/.env to retrieve sensitive credentials.
Likely vulnera ...
show moreAutomated probe attempting to access /config/.env to retrieve sensitive credentials.
Likely vulnerability scanning activity.
show less
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrom ...
show moreUA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36
URI: /core/install.php
Trigger WAF.
show less
Automated WordPress reconnaissance.
Requests to /wp-login.php and /wp-admin/index.php using user ag ...
show moreAutomated WordPress reconnaissance.
Requests to /wp-login.php and /wp-admin/index.php using user agent "WordPress CMS Scanner".
Clearly malicious enumeration of admin endpoints for potential brute force or vulnerability exploitation.
Traffic blocked by security system.
show less
Automated exploit scanning against WordPress front controller.
Repeated POST requests to /index.php ...
show moreAutomated exploit scanning against WordPress front controller.
Repeated POST requests to /index.php containing random parameter names and binary payloads with NULL bytes (0x00).
Payload appears fuzzed/malformed, consistent with vulnerability probing tools.
No legitimate application behavior would generate this traffic.
Requests were blocked by WAF.
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0 WAF TRIGGERED
show less
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/13 ...
show moreUA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
ANTI BOT SYSTEM TRIGGERED
show less
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/13 ...
show moreUA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36 triggered anti bot system
show less
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrom ...
show moreUA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36
URI: /core/install.php
Triggered WAF
show less