[AI threat score: 10/100] IP 94.154.43.129 generated 1 total hit on 2026-08-22T21:27:47.754Z using a ...
show more[AI threat score: 10/100] IP 94.154.43.129 generated 1 total hit on 2026-08-22T21:27:47.754Z using a standard Chrome Windows User-Agent string. The single request was a GET method targeting the root path /, which was flagged by the reporting system under the reason tag nonexistent-endpoint. With only a solitary hit and no enumeration of sensitive files, paths, or parameters, the observed activity represents isolated baseline probing rather than a coordinated attack pattern. Likely motive: Automated bot crawl
show less
Automated malicious web reconnaissance/scanning against api.majikah.solutions. At approximately 2026 ...
show moreAutomated malicious web reconnaissance/scanning against api.majikah.solutions. At approximately 2026-08-22 03:30:03โ03:30:04 GMT+8, 195.178.110.199 issued numerous requests for sensitive, administrative, configuration, and known-vulnerable paths, including /.env.sample, /market/.env, /new/.env, /demo/.env, /.gitlab, /deploy.sh, /config/stripe.yaml, /config/constants.js, /conf.yaml, /dnscfg.cgi, /proc/index.cgi, /software/install-updates.cgi, /package-updates/perform.cgi, /package-updates/update.cgi, /rest/oauth1-credential/auth, and other generic exploit/reconnaissance paths. The requests targeted multiple unrelated technology/framework paths in rapid succession, consistent with automated vulnerability scanning/reconnaissance rather than normal application usage.
show less
Unsolicited developer marketing email received by [email protected]. Message originated fro ...
show moreUnsolicited developer marketing email received by [email protected]. Message originated from 140.205.208.114 (out208-114.dm.aliyun.com) via Alibaba Cloud SMTP infrastructure. Sender claimed to represent NiubiStar using [email protected], promoted niubistar.com, and specified Reply-To: [email protected], creating a sender/domain mismatch. Email contained unsolicited marketing/outreach content and personalized unsubscribe links. No malicious attachment observed.
show less
Automated malicious web application reconnaissance detected from 3.104.117.255 against id.majikah.so ...
show moreAutomated malicious web application reconnaissance detected from 3.104.117.255 against id.majikah.solutions. The IP systematically probed numerous application-specific paths for exposed environment and configuration files, including /api/.env, /.env.preprod, /prod/.env, /microservice/.env, /vite/.env, /sendgrid/.env, /campaign/.env, /email/.env, /mailer/.env, /bootstrap/.env, /panel/.env, and /lab/.env.
The source also probed /webmail/phpinfo.php, indicating attempts to identify exposed PHP configuration and diagnostic information. This behavior is consistent with automated vulnerability scanning and reconnaissance intended to discover exposed credentials, API keys, service configuration, environment variables, and other sensitive information.
The traffic was unsolicited and triggered our Cloudflare WAF. Observed on 2026-08-21 at approximately 10:02โ10:03 GMT+8. No legitimate application behavior was identified from this source.
show less
Automated malicious web application reconnaissance detected from 13.208.226.20 against majikah.solut ...
show moreAutomated malicious web application reconnaissance detected from 13.208.226.20 against majikah.solutions. The IP rapidly probed for sensitive configuration and diagnostic files, including multiple .env locations (/bulk/.env, /gcp/.env, /express/.env, /angular/.env) as well as phpinfo.php and related PHP diagnostic files across common directories such as /wp-admin/, /administrator/, /site/, /tmp/, /smtp/, and /htdocs/.
These requests are consistent with automated vulnerability scanning targeting exposed environment files, credentials, application configuration, PHP information, and other sensitive server-side resources. The traffic was unsolicited and triggered our Cloudflare WAF.
Observed on 2026-08-21 at approximately 10:23 GMT+8. No legitimate application behavior was identified from this source.
show less
Automated malicious web scanning detected from 40.85.222.29 against signature.majikah.solutions. The ...
show moreAutomated malicious web scanning detected from 40.85.222.29 against signature.majikah.solutions. The IP rapidly probed numerous WordPress and PHP-related paths, including /wp-admin/ and /wp-includes/Text/Diff/index.php, while requesting multiple randomly generated PHP filenames such as /wp-admin/UZirInCNFYQ.php, /wp-admin/YkUJz1cAtjd.php, /wp-admin/jTweH3qMp7D.php, /wp-admin/kmsOihDGg24.php, and /wp-admin/9qI78Dnj6rL.php.
The request pattern is consistent with automated vulnerability scanning and reconnaissance intended to identify exposed WordPress files, web shells, vulnerable plugins, or compromised PHP endpoints. The traffic was unsolicited and triggered our Cloudflare WAF.
Observed on 2026-08-21 at approximately 10:42 GMT+8. No legitimate application behavior was identified from this source.
show less
Automated malicious web scanning/reconnaissance detected from 4.232.94.23 against api.majikah.soluti ...
show moreAutomated malicious web scanning/reconnaissance detected from 4.232.94.23 against api.majikah.solutions. The IP generated 1,400+ requests that triggered our Cloudflare WAF, rapidly probing numerous nonexistent and suspicious PHP/WordPress paths, including /wp-content/packed.php/new.php, /wp-load.php, /cgi-bin/index.php, /wp-content/plugins/hellopress/wp_filemanager.php, and numerous randomly named .php files.
The request pattern is consistent with automated vulnerability scanning and attempts to identify exposed web shells, WordPress vulnerabilities, file managers, or other compromised PHP endpoints. The traffic was unsolicited and was blocked by the WAF.
Observed on 2026-08-21 around 12:37โ12:38 GMT+8. No legitimate application behavior was identified from this source.
show less
Automated malicious vulnerability scanning and exploitation attempts against a web application. Sour ...
show moreAutomated malicious vulnerability scanning and exploitation attempts against a web application. Source repeatedly probed for vulnerable PHPUnit eval-stdin.php endpoints across multiple common installation paths, attempted .env credential disclosure using encoded and extension-bypass techniques, and probed authentication/API endpoints including /api/v1/auto_login. Activity is consistent with automated vulnerability discovery and attempted exploitation.
show less
Automated malicious web scanning against an endpoint. The source IP repeatedly requested numerous no ...
show moreAutomated malicious web scanning against an endpoint. The source IP repeatedly requested numerous non-existent PHP files and administrative/backdoor-style paths, including /admin.php, /index.php, /images.php, /av.php, and randomly named PHP files. Activity is consistent with automated vulnerability/backdoor discovery and web application reconnaissance.
show less
Unsolicited marketing/spam email received on 2026-08-18. SMTP headers show the message originated fr ...
show moreUnsolicited marketing/spam email received on 2026-08-18. SMTP headers show the message originated from public IP 140.205.208.141 (out208-141.dm.aliyun.com) and was received by the downstream mail infrastructure via TLS. Message claimed From: [email protected] but used Reply-To: [email protected], indicating potentially deceptive sender identity. Subject: "ResultGenie: verified marketing outcomes from NiubiStar". Message-ID: <[email protected]>. Evidence: Received: from out208-141.dm.aliyun.com ([140.205.208.141]) by CMGW with ESMTPS; Tue, 18 Aug 2026 02:43:21 +0000.
show less