HTTP GET /.git/config from 93.123.109.175 using Go-http-client/1.1 on 2025-11-19 22:02 Asia/Seoul, a ...
show moreHTTP GET /.git/config from 93.123.109.175 using Go-http-client/1.1 on 2025-11-19 22:02 Asia/Seoul, attempting to access an exposed Git configuration file. Configuration leakage scan.
show less
Automated WordPress scanner probing many installation paths for wlwmanifest.xml (/sito/wp-includes/w ...
show moreAutomated WordPress scanner probing many installation paths for wlwmanifest.xml (/sito/wp-includes/wlwmanifest.xml, /cms/wp-includes/wlwmanifest.xml, /site/wp-includes/wlwmanifest.xml, /wp2/wp-includes/wlwmanifest.xml, /media/wp-includes/wlwmanifest.xml, /test/wp-includes/wlwmanifest.xml, /wp1/wp-includes/wlwmanifest.xml, /shop/wp-includes/wlwmanifest.xml, /2019/wp-includes/wlwmanifest.xml, /2018/wp-includes/wlwmanifest.xml, /news/wp-includes/wlwmanifest.xml, /wp/wp-includes/wlwmanifest.xml, /website/wp-includes/wlwmanifest.xml, /wordpress/wp-includes/wlwmanifest.xml, /web/wp-includes/wlwmanifest.xml, /blog/wp-includes/wlwmanifest.xml) plus /xmlrpc.php?rsd and repeated GET /. Typical WordPress scanning attack.
show less
Repeated probing for WordPress setup script paths /wp-admin/setup-config.php and /wordpress/wp-admin ...
show moreRepeated probing for WordPress setup script paths /wp-admin/setup-config.php and /wordpress/wp-admin/setup-config.php from 2a06:98c0:3600::103 on 2025-11-19 and 2025-11-20, resulting in HTTP 404 responses. Typical automated WordPress installation scanner.
show less
Automated vulnerability and configuration scanner using python-httpx/0.24.1. After GET / and GET /sc ...
show moreAutomated vulnerability and configuration scanner using python-httpx/0.24.1. After GET / and GET /script.js the client attempted many environment and config paths (/.env*, /admin/.env*, /api/.env*, /app/.env*, /config/.env*, /src/.env*, /public/.env*, /assets/.env*, /includes/.env*, /system/.env*, /lib/.env*, /application/.env*, /modules/.env*, /vendor/.env*, /themes/.env*, /storage/.env*), plus /.git/config and numerous PHP info/debug endpoints such as /phpinfo.php, /info.php, /test.php and backup/temp variants. Activity around 2025-11-18 22:02-22:04 Asia/Seoul indicates clear automated Web App Attack.
show less
Automated scanner using python-httpx/0.28.1. Requested / and /script.js then probed for sensitive fi ...
show moreAutomated scanner using python-httpx/0.28.1. Requested / and /script.js then probed for sensitive files including /.git/config, multiple /.env* paths (root, /api, /config), PHP info endpoints (/phpinfo.php, /phpinfo, /info.php, /php.php, /test.php, /dashboard/phpinfo.php, /admin/phpinfo.php, /dev/phpinfo.php, /staging/phpinfo.php, /backup/phpinfo.php) and various secrets/log files such as /.aws/credentials, /application.properties, /application.yml, /appsettings.json, /config/secrets.yml, /deploy.sh, /error.log, /access.log, /debug.log, /logs/* and /storage/logs/laravel.log. Activity around 2025-11-19 01:10 Asia/Seoul is consistent with automated Web App Attack / configuration and log leakage scanning.
show less
Automated WordPress scanner probing many WordPress installation paths for wlwmanifest.xml and relate ...
show moreAutomated WordPress scanner probing many WordPress installation paths for wlwmanifest.xml and related files plus /xmlrpc.php?rsd and repeated GET / around 2025-11-19 01:49-01:50 Asia/Seoul.
show less
Automated WordPress scanner probing multiple installation paths for wlwmanifest.xml and /xmlrpc.php? ...
show moreAutomated WordPress scanner probing multiple installation paths for wlwmanifest.xml and /xmlrpc.php?rsd.
show less
Automated WordPress scanner probing many installation paths for wlwmanifest.xml and multiple GET / p ...
show moreAutomated WordPress scanner probing many installation paths for wlwmanifest.xml and multiple GET / plus /xmlrpc.php?rsd attempts. Typical WordPress scanning attack.
show less
Repeated probing for WordPress setup script paths /wp-admin/setup-config.php and /wordpress/wp-admin ...
show moreRepeated probing for WordPress setup script paths /wp-admin/setup-config.php and /wordpress/wp-admin/setup-config.php resulting in HTTP 404 responses. Automated WordPress installation scanner.
show less
Probe for WordPress and Joomla core script files: /wp-includes/js/jquery/jquery.js and /media/system ...
show moreProbe for WordPress and Joomla core script files: /wp-includes/js/jquery/jquery.js and /media/system/js/core.js resulting in HTTP 404 responses. Indicative of automated vulnerability scanning.
show less
Automated scan for environment and configuration files: /web/.env, /.env.example, /secrets.env, /bac ...
show moreAutomated scan for environment and configuration files: /web/.env, /.env.example, /secrets.env, /backend/.env, /.config.yaml, /laravel/.env, /admin/.env, /app_dev.php/_profiler/phpinfo, /dev/.env, /phpinfo/, /api/.env, /twilio.env, /sendgrid.env, /.env and others, along with GET /, all around 2025-11-16 02:22 Asia/Seoul (Web App Attack / config disclosure / exploited host and bad web bot behavior).
show less
HTTP GET /.git/config from 93.123.109.107 using python-requests/2.25.1 attempting to access an expos ...
show moreHTTP GET /.git/config from 93.123.109.107 using python-requests/2.25.1 attempting to access an exposed .git configuration file on 2025-11-16 00:49 Asia/Seoul (information disclosure / Web App Attack).
show less
Automated scan for multiple WordPress installation paths such as /sito/wp-includes/wlwmanifest.xml, ...
show moreAutomated scan for multiple WordPress installation paths such as /sito/wp-includes/wlwmanifest.xml, /cms/wp-includes/wlwmanifest.xml, /site/wp-includes/wlwmanifest.xml, /wp2/wp-includes/wlwmanifest.xml, /media/wp-includes/wlwmanifest.xml, /test/wp-includes/wlwmanifest.xml, /wp1/wp-includes/wlwmanifest.xml, /shop/wp-includes/wlwmanifest.xml, /2019/wp-includes/wlwmanifest.xml, /2018/wp-includes/wlwmanifest.xml, /news/wp-includes/wlwmanifest.xml, /wp/wp-includes/wlwmanifest.xml, /website/wp-includes/wlwmanifest.xml, /wordpress/wp-includes/wlwmanifest.xml, /web/wp-includes/wlwmanifest.xml, /blog/wp-includes/wlwmanifest.xml, plus /xmlrpc.php?rsd and repeated GET / requests on 2025-11-15 23:16 Asia/Seoul (WordPress scanner / Web App Attack).
show less
Repeated probing for WordPress setup script paths /wp-admin/setup-config.php and /wordpress/wp-admin ...
show moreRepeated probing for WordPress setup script paths /wp-admin/setup-config.php and /wordpress/wp-admin/setup-config.php resulting in HTTP 404 responses between 2025-11-15 22:21 and 2025-11-16 05:38 Asia/Seoul (automated Web App Attack / hacking attempt).
show less
Host attempted to access /.git/config, indicating a scan for exposed Git repository configuration wh ...
show moreHost attempted to access /.git/config, indicating a scan for exposed Git repository configuration which could reveal source code or sensitive information if misconfigured.
show less
Scanner requesting /wp-includes/js/jquery/jquery.js and /media/system/js/core.js, consistent with pr ...
show moreScanner requesting /wp-includes/js/jquery/jquery.js and /media/system/js/core.js, consistent with probing for WordPress and Joomla installations and their JavaScript assets as part of CMS fingerprinting and vulnerability scanning.
show less
Same WordPress enumeration pattern as 138.199.35.10: repeated probes for wlwmanifest.xml under many ...
show moreSame WordPress enumeration pattern as 138.199.35.10: repeated probes for wlwmanifest.xml under many possible WordPress install prefixes, xmlrpc.php?rsd, and /wp-includes/wlwmanifest.xml. Indicates automated probing for WordPress sites to target.
show less
Automated scanner requesting many WordPress-related wlwmanifest.xml paths across typical directory p ...
show moreAutomated scanner requesting many WordPress-related wlwmanifest.xml paths across typical directory prefixes (/sito, /cms, /site, /wp2, /media, /test, /wp1, /shop, /2019, /2018, /news, /wp, /website, /wordpress, /web, /blog) plus xmlrpc.php?rsd and /wp-includes/wlwmanifest.xml. Classic WordPress installation and vulnerability discovery scan.
show less