Massive automated vulnerability and directory traversal scan originating from CDNEXT (France). The a ...
show moreMassive automated vulnerability and directory traversal scan originating from CDNEXT (France). The actor is methodically probing for hundreds of known vulnerable WordPress themes and plugins (e.g., /revslider/, /travelscape/, /BrutalShell/) and sensitive administrative directories (/cgi-bin/, /ALFA_DATA/). The attack specifically targeted the autodiscover subdomain, executing over 1,000 requests in a high-velocity burst. The bot utilized a rotated User-Agent (Firefox 79 on macOS) to mimic legitimate traffic and bypass basic reputation filters.
show less
Systematic hunt for web shells and backdoors originating from Omegatech (Netherlands). The actor is ...
show moreSystematic hunt for web shells and backdoors originating from Omegatech (Netherlands). The actor is specifically probing for known malicious scripts including /wp-content/plugins/pwnd/pwnd.php, /worksec.php, and /wp-content/plugins/fix/up.php on doghousediving.org. This high-precision scan targets directories typically used by attackers to maintain persistence after an initial breach. The request pattern shows 31 targeted GET requests within a few seconds, indicating an automated post-exploitation scanner.
show less
Systematic directory "fuzzing" and brute-force attack originating from Microsoft Azure (Canada). The ...
show moreSystematic directory "fuzzing" and brute-force attack originating from Microsoft Azure (Canada). The actor is attempting to locate non-standard PHP shells and backdoors using randomized 5-letter filenames (e.g., /euhpb.php, /cqrrg.php, /fvlje.php) and specific exploit paths like /t00l.php and /karma_0cc5.php. Requests are sent with a null User-Agent, a signature matching a previous high-volume attack from the same ASN. Activity targets both the root domain and the www subdomain simultaneously.
show less
Aggressive, high-velocity directory brute-force attack originating from Microsoft Azure (Canada). Th ...
show moreAggressive, high-velocity directory brute-force attack originating from Microsoft Azure (Canada). The actor is probing for a wide array of PHP backdoors and randomized shell filenames (e.g., /fleen.php, /autogooey.php, /ws62.php, /wp-act.php) across multiple subdomains. The requests are sent with a completely stripped User-Agent, indicating a raw socket script designed to bypass basic filtering. High-density bursts of 400+ requests observed, targeting both the main site and autodiscover endpoints.
show less
Aggressive automated vulnerability scan (approx. 50+ req/sec burst) originating from Microsoft Azure ...
show moreAggressive automated vulnerability scan (approx. 50+ req/sec burst) originating from Microsoft Azure (Hong Kong). IP is systematically probing for common web shells and WordPress vulnerabilities, including /wp-content/uploads/users.php, /wp-admin/css/bolt.php, and /xmlrpc.php. The attack pattern demonstrates high-velocity reconnaissance across multiple subdomains (www, cpcontacts), targeting administrative scripts and unlinked PHP files.
show less
Systematic vulnerability scanning originating from Microsoft Azure (Singapore). IP is probing for se ...
show moreSystematic vulnerability scanning originating from Microsoft Azure (Singapore). IP is probing for sensitive WordPress directories and web shells, including /wp-includes/PHPMailer/, /wp-content/themes/admin.php, and /xmlrpc.php. Approximately 50% of the 207 requests bypassed automated bot detection, indicating a targeted attempt to identify server-side vulnerabilities. Probing behavior includes systematic reconnaissance of the 'www' and 'mail' subdomains.
show less
Aggressive automated vulnerability scanning originating from South Korea (Microsoft Azure infrastruc ...
show moreAggressive automated vulnerability scanning originating from South Korea (Microsoft Azure infrastructure). IP is systematically probing for WordPress exploits and backdoors including xmlrpc.php, wp-trackback.php, and various shell-indicative files (.PhP7, abcd.php, ioxi-o.php). Targeting multiple subdomains including cpcalendars, cpcontacts, and autodiscover. Velocity and payload signatures are consistent with automated reconnaissance for server compromise.
Report auto generated with AI script located at https://www.muttmutt.us/the-titan-shield-security-project/the-cloudflare-log-ultimate-automated-ip-abuse-reporting-guide/
show less
High-velocity automated exploit scan (approx. 14 req/sec) targeting WordPress and PHPUnit vulnerabil ...
show moreHigh-velocity automated exploit scan (approx. 14 req/sec) targeting WordPress and PHPUnit vulnerabilities. IP is actively probing for web shells including WSO (/wp-admin/wso.php) and Alfa Shell (/ALFA_DATA/alfacgiapi/), as well as RCE vectors in the PHPUnit vendor directory. Systematic reconnaissance across multiple subdomains (www, autodiscover) indicates a coordinated attempt to gain unauthorized shell access.
show less
Aggressive automated reconnaissance and directory traversal scan targeting sensitive configuration f ...
show moreAggressive automated reconnaissance and directory traversal scan targeting sensitive configuration files. Actor is probing for environment variables (.env), Git credentials (.git/config), AWS/S3 bucket configs, Stripe/Sendgrid keys, and server-side setup files (terraform.tfvars, nginx.conf, Vagrantfile). High-velocity signature (dozens of requests per second) originating from Hostbaltic (Lithuania) infrastructure. Clear attempt at information disclosure to facilitate a secondary breach.
show less
Massive automated API fuzzing and vulnerability scanning (1.83K+ requests). Target is probing for in ...
show moreMassive automated API fuzzing and vulnerability scanning (1.83K+ requests). Target is probing for insecure file upload handlers and webhook vulnerabilities across thousands of potential paths (e.g., /webhook/upload, /form/api/storage, /webhook/admin/import). High-velocity attack originating from Hostbaltic (Lithuania) infrastructure. The signature indicates a systematic search for RCE (Remote Code Execution) vulnerabilities via arbitrary file upload endpoints.
show less
Coordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within ...
show moreCoordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within the 181.215.65.x range are executing high-velocity, simultaneous POST requests (US Central Time) targeting /wp-login.php and /admin across multiple subdomains. This is a synchronized botnet effort to bypass rate limiting and compromise administrative credentials. Request volume exceeds 100 hits in a 10-second window.
show less
Coordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within ...
show moreCoordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within the 181.215.65.x range are executing high-velocity, simultaneous POST requests (US Central Time) targeting /wp-login.php and /admin across multiple subdomains. This is a synchronized botnet effort to bypass rate limiting and compromise administrative credentials. Request volume exceeds 100 hits in a 10-second window.
show less
Coordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within ...
show moreCoordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within the 181.215.65.x range are executing high-velocity, simultaneous POST requests (US Central Time) targeting /wp-login.php and /admin across multiple subdomains. This is a synchronized botnet effort to bypass rate limiting and compromise administrative credentials. Request volume exceeds 100 hits in a 10-second window.
show less
Coordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within ...
show moreCoordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within the 181.215.65.x range are executing high-velocity, simultaneous POST requests (US Central Time) targeting /wp-login.php and /admin across multiple subdomains. This is a synchronized botnet effort to bypass rate limiting and compromise administrative credentials. Request volume exceeds 100 hits in a 10-second window.
show less
Coordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within ...
show moreCoordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within the 181.215.65.x range are executing high-velocity, simultaneous POST requests (US Central Time) targeting /wp-login.php and /admin across multiple subdomains. This is a synchronized botnet effort to bypass rate limiting and compromise administrative credentials. Request volume exceeds 100 hits in a 10-second window.
show less
Coordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within ...
show moreCoordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within the 181.215.65.x range are executing high-velocity, simultaneous POST requests (US Central Time) targeting /wp-login.php and /admin across multiple subdomains. This is a synchronized botnet effort to bypass rate limiting and compromise administrative credentials. Request volume exceeds 100 hits in a 10-second window.
show less
Coordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within ...
show moreCoordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within the 181.215.65.x range are executing high-velocity, simultaneous POST requests (US Central Time) targeting /wp-login.php and /admin across multiple subdomains. This is a synchronized botnet effort to bypass rate limiting and compromise administrative credentials. Request volume exceeds 100 hits in a 10-second window.
show less
Coordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within ...
show moreCoordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within the 181.215.65.x range are executing high-velocity, simultaneous POST requests (US Central Time) targeting /wp-login.php and /admin across multiple subdomains. This is a synchronized botnet effort to bypass rate limiting and compromise administrative credentials. Request volume exceeds 100 hits in a 10-second window.
show less
Coordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within ...
show moreCoordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within the 181.215.65.x range are executing high-velocity, simultaneous POST requests (US Central Time) targeting /wp-login.php and /admin across multiple subdomains. This is a synchronized botnet effort to bypass rate limiting and compromise administrative credentials. Request volume exceeds 100 hits in a 10-second window.
show less
Coordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within ...
show moreCoordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within the 181.215.65.x range are executing high-velocity, simultaneous POST requests (US Central Time) targeting /wp-login.php and /admin across multiple subdomains. This is a synchronized botnet effort to bypass rate limiting and compromise administrative credentials. Request volume exceeds 100 hits in a 10-second window.
show less
Coordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within ...
show moreCoordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within the 181.215.65.x range are executing high-velocity, simultaneous POST requests (US Central Time) targeting /wp-login.php and /admin across multiple subdomains. This is a synchronized botnet effort to bypass rate limiting and compromise administrative credentials. Request volume exceeds 100 hits in a 10-second window.
show less
Coordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within ...
show moreCoordinated distributed brute-force attack originating from the CDNEXT network. Multiple IPs within the 181.215.65.x range are executing high-velocity, simultaneous POST requests targeting /wp-login.php and /admin across multiple subdomains. This is a synchronized botnet effort to bypass rate limiting and compromise administrative credentials. Request volume exceeds 100 hits in a 10-second window.
show less
Automated vulnerability scanning originating from Clouvider (USA). The actor is executing high-veloc ...
show moreAutomated vulnerability scanning originating from Clouvider (USA). The actor is executing high-velocity GET requests (US Central Time) targeting the wlwmanifest.xml endpoint across a wide variety of common WordPress subdirectories (e.g., //sito/, //cms/, //shop/, //blog/). The signature also includes probing for xmlrpc.php and mail-related subdomains (autodiscover). This systematic reconnaissance pattern is a clear indicator of a bot attempting to identify WordPress installations for potential exploitation.
show less
Persistent automated brute-force campaign originating from CDNEXT (USA). This actor is targeting mul ...
show morePersistent automated brute-force campaign originating from CDNEXT (USA). This actor is targeting multiple subdomains (www and cpcontacts) with high-velocity POST requests aimed at administrative login interfaces (/wp-login.php and /admin). The activity occurs in concentrated bursts across different hours of the day, indicating a coordinated credential stuffing or brute-force attack. The high-frequency request pattern across multiple hostnames confirms a malicious automated bot seeking unauthorized administrative access.
show less
Automated reconnaissance and exploitation attempt originating from Atheeb-AS (Saudi Arabia). The act ...
show moreAutomated reconnaissance and exploitation attempt originating from Atheeb-AS (Saudi Arabia). The actor is targeting forum infrastructure with high-velocity probes, specifically attempting to trigger administrative cron tasks (cron.task.core.tidy_warnings, cron.task.text_reparser.poll_option) and executing multiple automated POST requests to /cdn-cgi/rum. The signature involves rapid-fire scraping of CSS/JS assets and repeated search queries, indicating an automated bot attempting to identify vulnerabilities in the forum's backend processing.
show less
Web App Attack
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.