Scrapping for sensitive configuration files using TLM-Audit-Scanner. Over 1.2k requests in 30 second ...
show moreScrapping for sensitive configuration files using TLM-Audit-Scanner. Over 1.2k requests in 30 seconds.
show less
Massive automated vulnerability scan (over 11k requests in 10m) targeting multiple subdomains (www, ...
show moreMassive automated vulnerability scan (over 11k requests in 10m) targeting multiple subdomains (www, autoconfig, autodiscover, cpanel). Actor is using Python/aiohttp to probe for sensitive debugging information (/debug/vars, /debug/pprof/), system health status, and environment variables via CORS exploitation attempts (/api/cors/file:///app/.env). Originating from AME Hosting LLC (AS399244).
show less
High-intensity automated scanning (519+ requests) targeting environment variables and server configu ...
show moreHigh-intensity automated scanning (519+ requests) targeting environment variables and server configuration files. Probing for .env files, phpinfo, and system status across multiple directories (/docker/.env, /kubernetes/.env, /aws/.env). Originating from AWS (AS16509). Clear malicious reconnaissance for information disclosure.
show less
Aggressive automated vulnerability reconnaissance (23.79k requests) originating from The Infrastruct ...
show moreAggressive automated vulnerability reconnaissance (23.79k requests) originating from The Infrastructure Group B.V. (Netherlands). The actor is executing a massive HEAD-request dictionary scan for sensitive administrative APIs, documentation, and configuration files, including /api/swagger, /rest/settings, and /api/v1/apikey across multiple subdomains (mail, ftp, etc.). Traffic is highly automated and mostly bypassed standard challenges.
show less
Aggressive automated vulnerability reconnaissance (22.99k requests) originating from The Infrastruct ...
show moreAggressive automated vulnerability reconnaissance (22.99k requests) originating from The Infrastructure Group B.V. (Netherlands). The actor is executing a massive dictionary scan for sensitive configuration files, internal APIs, and memory dumps, including /.env, /api/admin, /actuator/heapdump, and /api/private. High-velocity activity indicates a systematic attempt to compromise server-side environment variables and administrative interfaces. Activity mostly bypassed standard challenges due to volume.
show less
Automated environment file reconnaissance originating from Evoxt VPS infrastructure (Japan). The act ...
show moreAutomated environment file reconnaissance originating from Evoxt VPS infrastructure (Japan). The actor targeted multiple subdomains (cpanel, mail, autodiscover, webdisk) specifically requesting the /.env path. This coordinated dictionary attack is designed to harvest sensitive credentials and server configurations. Activity occurred in concentrated bursts, successfully mitigated by Cloudflare Managed Challenges.
show less
Automated vulnerability reconnaissance (1,180+ requests) originating from AWS infrastructure. System ...
show moreAutomated vulnerability reconnaissance (1,180+ requests) originating from AWS infrastructure. Systematic probing for PHP configuration leaks and server status pages, including /server-info.php, /_profiler/phpinfo, and /public/phpinfo.php. Activity detected and mitigated by Bot Fight Mode. Patterns indicate a coordinated attempt to harvest server-side environment variables and version data for exploit targeting.
show less
High-velocity automated reconnaissance (1,970+ requests) targeting sensitive cloud credentials and e ...
show moreHigh-velocity automated reconnaissance (1,970+ requests) targeting sensitive cloud credentials and environment configurations. Systematic probing for /s3/.aws/credentials, /aws/keys_backup.json, /web/.env.bak, and /.git/config. Extreme burst frequency reaching 40+ requests per second. Attack pattern is a coordinated effort to harvest access keys and database backups. Absence of legitimate User-Agent in most requests confirms a malicious exploit script.
Created with the AI Log Script https://www.muttmutt.us/the-titan-shield-security-project/the-cloudflare-log-ultimate-automated-ip-abuse-reporting-guide/
show less
High-velocity automated vulnerability scan (4,360 requests). The bot used Curl to probe for sensitiv ...
show moreHigh-velocity automated vulnerability scan (4,360 requests). The bot used Curl to probe for sensitive configuration backups, environment files, and API secrets (e.g., /oauth.bak, /archive/secrets.php, /monitor/env). Extensive targeting of actuator endpoints and internal API routes (/private/actuator, /api/v3/jwt). This is a coordinated attempt at credential discovery and information disclosure.
show less
Coordinated automated vulnerability scan (239 requests). Part of a massive subnet-wide campaign from ...
show moreCoordinated automated vulnerability scan (239 requests). Part of a massive subnet-wide campaign from 45.133.4.0/24 targeting infrastructure subdomains. The bot probed for PHPUnit RCE, Bitrix administrative vulnerabilities, and directory traversal entry points like TinyFileManager. Specifically targeted the autodiscover host and attempted to access PKI validation directories, indicating an attempt to manipulate or monitor certificate renewal processes.
show less
Coordinated automated vulnerability scan (244 requests). Part of a multi-IP attack from 45.133.4.0/2 ...
show moreCoordinated automated vulnerability scan (244 requests). Part of a multi-IP attack from 45.133.4.0/24 targeting subdomains. The bot executed high-velocity probes for PHPUnit RCE vulnerabilities, administrative extension controllers, and unauthorized shell access. Also targeted elFinder connectors and cache directories of specific WordPress plugins (Instabuilder2). This node is part of a systematic effort to identify and exploit server-side misconfigurations.
show less
Coordinated automated vulnerability scan (245 requests). Part of a massive subnet-wide attack from 4 ...
show moreCoordinated automated vulnerability scan (245 requests). Part of a massive subnet-wide attack from 45.133.4.0/24. Targeted the root domain for multiple exploit vectors including PHPUnit RCE, Bitrix administrative vulnerabilities, and various file manager connectors (TinyFileManager, elFinder). Probing for "shell" plugins and ACME challenge directories suggests an intent to establish a persistent backdoor and hijack SSL certificate workflows.
show less
Automated vulnerability scan and directory traversal attempt (252 requests). Part of a coordinated s ...
show moreAutomated vulnerability scan and directory traversal attempt (252 requests). Part of a coordinated subnet attack targeting cPanel subdomains. The bot utilized a specific Firefox 75 User-Agent to probe for RCE vulnerabilities (PHPUnit), administrative backdoors (Bitrix, OpenCart), and plugin-specific cache vulnerabilities (Instabuilder). Significant focus on common exploit paths and recursive directory probing to identify misconfigured assets.
show less
Aggressive automated vulnerability scan and webshell injection attempt (997 requests). Attacker util ...
show moreAggressive automated vulnerability scan and webshell injection attempt (997 requests). Attacker utilized high-velocity bursts (~40 req/s) targeting cPanel-related subdomains to probe for known backdoors and exploit vectors, including /c99shell.php, /abcd.php, and /dedi1.php. The bot specifically attempted to exploit the PHPUnit RCE vulnerability and probed the /.well-known/ directory for legacy configuration files. Activity indicates a systematic effort to achieve remote file inclusion (RFI) and unauthorized server control.
show less
Massive automated vulnerability scan and remote code execution (RCE) attempt (998 requests). Attacke ...
show moreMassive automated vulnerability scan and remote code execution (RCE) attempt (998 requests). Attacker targeted autodiscover subdomains using high-velocity bursts (~40 req/s) to probe for known backdoors and sensitive file paths including /abcd.php, /as.php, and /alfacgiapi/. The bot specifically attempted to exploit the PHPUnit vulnerability (/vendor/phpunit/phpunit/src/Util/PHP/) and searched for administrative upload modules. The activity utilized a legacy IE11/Trident User-Agent string to mask automated traffic. Systematic intent to achieve unauthorized server access through file inclusion and directory traversal.
show less
Aggressive automated vulnerability scan and webshell injection attempt (1,000 requests). Attacker ta ...
show moreAggressive automated vulnerability scan and webshell injection attempt (1,000 requests). Attacker targeted cpanel subdomains using high-velocity bursts (~35 req/s) to probe for common shells and backdoors including /c99shell.php, /c99.php, and /alfacgiapi/. The bot also attempted to exploit the PHPUnit RCE vulnerability (/vendor/phpunit/phpunit/src/Util/PHP/abcd.php) and probed for administrative vulnerabilities in Bitrix (/bitrix/admin/). Behavior indicates a coordinated effort to achieve remote file inclusion (RFI) and persistent server access.
show less
Massive automated vulnerability scan and webshell injection attempt (1,020 requests). Attacker utili ...
show moreMassive automated vulnerability scan and webshell injection attempt (1,020 requests). Attacker utilized high-velocity bursts (~45 req/s) to probe for sensitive WordPress directories and known exploit vectors, specifically targeting /BrutalShell/, /ALFA_DATA/, and /shell.php. The bot also attempted to leverage the PHPUnit RCE vulnerability (/vendor/phpunit/phpunit/src/Util/PHP/) and probed for various administrative file-upload modules. All traffic utilized a spoofed Firefox 74 User-Agent to bypass standard filters. Systematic intent to compromise origin through remote file inclusion and shell execution.
show less
Automated vulnerability scan and directory enumeration (186 requests in 28s). Attacker targeted auto ...
show moreAutomated vulnerability scan and directory enumeration (186 requests in 28s). Attacker targeted autodiscover subdomains and root directories, probing for WordPress themes (twentytwentyone, seotheme, alera), sensitive plugin paths (email-subscribers, background-image-cropper), and high-risk CMS modules (mod_simplefileuploadv1.3). Probing included cryptographic source folders (/sodium_compat/) and administrative backups (/backup/, /cgi-bin/). Behavior indicates systematic exploit mapping using a spoofed Chrome 79 User-Agent.
show less
Automated vulnerability scan and directory enumeration. Attacker bypassed edge mitigations using a s ...
show moreAutomated vulnerability scan and directory enumeration. Attacker bypassed edge mitigations using a spoofed Firefox 77 User-Agent, executing 186 requests in 3 seconds (~62 req/s). High-velocity probing targeted sensitive WordPress plugin directories (Litespeed-cache, Gravity Forms), CMS modules (mod_simplefileuploadv1.3), and server-level paths (/cgi-sys/, /pki-validation/). Behavior indicates a systematic exploit-mapping attempt.
show less
Systematic deep-directory reconnaissance and WordPress administrative probing (203 requests). The at ...
show moreSystematic deep-directory reconnaissance and WordPress administrative probing (203 requests). The attacker is targeting core sensitive paths including /wp-admin/includes/, /wp-includes/ID3/, and /wp-admin/maint/. This actor is specifically hunting for known web shells and backdoors like bolt.php and da222.php, as well as probing for directory listings in administrative subfolders. The use of varied PHP extensions (e.g., .PhP7) suggests an automated vulnerability research tool. Originates from Microsoft Azure infrastructure (Hong Kong).
show less
Aggressive "Shotgun" style shell discovery and backdoor probing (275 requests). The attacker is syst ...
show moreAggressive "Shotgun" style shell discovery and backdoor probing (275 requests). The attacker is systematically testing for high-risk PHP scripts and malformed filenames including /alfa-rex.php7, /wp-conflg.php (malicious typo-squatting), /ws62.php, and various short-form "dropper" scripts like zz.php, xa.php, and 0.php. This high-velocity scanning (targeting www.muttmutt.us) is indicative of an automated exploit kit attempting to locate and execute unauthorized entry points. Originates from Microsoft Azure infrastructure (United States).
show less
Aggressive, high-velocity "Shell & Backdoor" reconnaissance (360 requests) targeting the wtf subdoma ...
show moreAggressive, high-velocity "Shell & Backdoor" reconnaissance (360 requests) targeting the wtf subdomain. The attacker is probing for a wide array of known malicious PHP scripts and file managers, including /alfashell.php, /tinyfilemanager.php, /wp-michan.php, and /alfashell.php. Despite Cloudflare Bot Fight Mode challenges, over 180 requests successfully reached the origin. This represents a systematic effort to locate unauthorized administrative entry points or previously planted malware. Originates from Microsoft Azure infrastructure (France).
show less
High-intensity "backdoor hunting" scan (518 requests) targeting specific web shells and bypass scrip ...
show moreHigh-intensity "backdoor hunting" scan (518 requests) targeting specific web shells and bypass scripts. The attacker is systematically probing for high-risk malicious files including /wp-admin/wso.php (WSO Web Shell), /wp-content/plugins/wp-conflg.php, and various bypass.php or system_cache.php filenames across multiple themes. This activity is a clear attempt to locate and utilize existing backdoors or unauthorized entry points within the WordPress architecture. Originates from GSL Networks (AS137409) in Singapore.
show less
High-velocity reconnaissance scan (601 requests in a single burst) targeting WordPress core files an ...
show moreHigh-velocity reconnaissance scan (601 requests in a single burst) targeting WordPress core files and known plugin vulnerabilities. The attacker is systematically probing for sensitive directories and backdoors, including /wp-includes/PHPailer/, /phpunit/phpunit/, and /wp-content/plugins/pwnd-1/. Additional focus on administrative maintenance paths like /wp-admin/maint/ suggests an attempt to exploit misconfigured or "orphaned" WordPress installations. Originates from GSL Networks (AS137409) infrastructure in Singapore.
show less
Extremely aggressive, high-precision vulnerability and web shell scan originating from GSL Networks ...
show moreExtremely aggressive, high-precision vulnerability and web shell scan originating from GSL Networks (Australia). The actor is systematically probing for high-risk administrative backdoors and hacker toolkits, including /wp-content/ALFA_DATA/alfacgiapi/, /alfanew.php7, and /cgi-bin/mariju.php. The attack pattern involves over 1,000 requests in a sustained burst, targeting both core WordPress directories and obscure paths like /Files/Mo0n.php and /images/worksec.php. This is a sophisticated reconnaissance effort to identify and utilize remote code execution (RCE) entry points.
show less
VPN IPHackingWeb App Attack
By clicking βAccept allβ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.