Automated vulnerability reconnaissance originating from AWS infrastructure. This actor is executing ...
show moreAutomated vulnerability reconnaissance originating from AWS infrastructure. This actor is executing high-velocity directory brute-forcing targeting the wlwmanifest.xml and xmlrpc.php endpoints across dozens of common WordPress subdirectories (e.g., /sito/, /cms/, /shop/, /blog/). The signature involves systematic probing for Windows Live Writer manifest files to identify WordPress installations and potential vulnerabilities. The bot's rapid-fire request pattern and targeting of legacy entry points across multiple hours indicate a coordinated reconnaissance effort for unauthorized access.
show less
Aggressive brute-force and vulnerability reconnaissance originating from Hostbaltic (Lithuania). The ...
show moreAggressive brute-force and vulnerability reconnaissance originating from Hostbaltic (Lithuania). The actor is executing high-velocity GET requests targeting common WordPress login and administrative entry points across multiple directory structures, including /cms/, /blog/, /wp/, and /wordpress/. The systematic nature of these probes indicates an automated attempt to locate and compromise administrative credentials. This activity triggered multiple Cloudflare Managed Challenges, confirming a high-confidence threat profile.
show less
Aggressive automated vulnerability scanning and shell-hunting originating from Microsoft Azure (Irel ...
show moreAggressive automated vulnerability scanning and shell-hunting originating from Microsoft Azure (Ireland). This actor is targeting multiple subdomains (www and cpcontacts) with high-velocity probes. The signature involves searching for specific malicious backdoors and shells (rafa.php, gu.php, wp-wlx.php) and probing sensitive theme directories (pridmag) and plugin paths (hellopress/wp_filemanager.php). The bot is also hunting for configuration leaks in hidden PKI validation paths. This high-frequency activity with a null user agent is a clear indicator of automated reconnaissance for unauthorized access.
show less
Aggressive automated vulnerability scanning and backdoor hunting originating from a high-risk ASN in ...
show moreAggressive automated vulnerability scanning and backdoor hunting originating from a high-risk ASN in the Netherlands. This actor is executing high-velocity POST requests targeting very specific malicious web shell paths, including ALFA_DATA/alfacgiapi/perl.alfa, wp-content/plugins/fix/up.php, and wp-content/themes/seotheme/db.php. The signature involves spoofed mobile user agents and systematic probing for pre-existing infections or unauthorized file upload handlers. The repeated nature of these bursts across multiple hours indicates a coordinated exploitation attempt.
show less
Aggressive automated exploit agent originating from Truespeed (UK). Actor is targeting the WordPress ...
show moreAggressive automated exploit agent originating from Truespeed (UK). Actor is targeting the WordPress admin-ajax.php endpoint with repeated POST requests, triggering multiple Cloudflare Interactive Challenges (Custom Rules) which the agent failed to solve or bypassed. The persistence of these requests after being challenged, combined with systematic scraping of internal plugin assets and bulk image downloads, confirms this is a malicious bot attempting to locate and exploit AJAX-based vulnerabilities.
show less
Aggressive automated vulnerability scanning and shell-hunting originating from Microsoft Azure (Cana ...
show moreAggressive automated vulnerability scanning and shell-hunting originating from Microsoft Azure (Canada). This actor is targeting autodiscover infrastructure with high-velocity probes. The signature involves searching for known malicious backdoors and shells (bolt.php, ioxi-o.php, rip.php) and probing sensitive WordPress directories for unauthorized scripts (wp-admin/includes/v2.php). The bot is also hunting for configuration leaks in hidden paths like .well-known/hp2.php, indicating a clear intent to find or establish unauthorized access points.
show less
Aggressive automated vulnerability scanning and backdoor hunting originating from Microsoft Azure (S ...
show moreAggressive automated vulnerability scanning and backdoor hunting originating from Microsoft Azure (South Korea). This actor is targeting mail infrastructure (mail.muttmutt.us) with high-velocity probes. The signature involves broad directory brute-forcing for known web shells (alfa-rex.php, akc.php, gecko-litespeed.php) and exploiting hidden paths like .well-known/acme-challenge/ and .tmb/. The bot is also hunting for unauthorized administrative upload points and specific WordPress core vulnerabilities, indicating a coordinated reconnaissance effort for post-exploitation access.
show less
Aggressive automated vulnerability scanning and backdoor hunting originating from Microsoft Azure (C ...
show moreAggressive automated vulnerability scanning and backdoor hunting originating from Microsoft Azure (Canada). This actor is targeting both the root domain and www subdomain with high-velocity GET requests. The signature involves probing for common shell entry points and sensitive directory listings, including /wp-content/uploads/, /cgi-bin/, and generic PHP scripts such as wp-good.php, adminfuns.php, and chosen.php. The bot also attempts to access sensitive theme indices and administrative files. This is a clear indicator of non-human reconnaissance for unauthorized access.
show less
Aggressive automated vulnerability scanning originating from PT Trisari Data Indonusa (Indonesia). T ...
show moreAggressive automated vulnerability scanning originating from PT Trisari Data Indonusa (Indonesia). The actor is utilizing a Go-based HTTP client (Go-http-client/2.0) to conduct high-frequency probes for specialized backdoors across the root domain and www subdomain. The signature is highly specific, repeatedly targeting unique filenames like postnews.php, txets.php, and schallfuns.php across various core directories (/wp-admin/, /wp-content/, /wp-includes/). This behavior indicates a targeted attempt to trigger specific pre-installed malware or exploit a very particular set of unauthorized upload handlers.
show less
Persistent automated vulnerability scanning campaign originating from Microsoft Azure (Poland). This ...
show morePersistent automated vulnerability scanning campaign originating from Microsoft Azure (Poland). This actor is targeting the root domain and the autodiscover subdomain with synchronized, high-frequency probes. The bot is specifically hunting for generic shell names (shell.php, ws.php, up.php, 1.php) and well-known vulnerabilities in WordPress plugins (e.g., wp_filemanager.php in the hellopress directory). The signature shows a systematic approach to identifying post-exploitation backdoors and administrative maintenance leaks.
show less
Automated vulnerability scanner originating from Microsoft Azure (Hong Kong). This actor is conducti ...
show moreAutomated vulnerability scanner originating from Microsoft Azure (Hong Kong). This actor is conducting targeted probes for known web shells and post-exploitation backdoors. Signature attempts include hunting for alfa-rex.php7, akc.php, ioxi-o.php, and xwx1.php. The bot is also attempting to find unauthorized administrative entry points by masquerading as legitimate WordPress files in non-standard locations (e.g., wp-includes/images/wp-login.php). This systematic reconnaissance of the root domain is a clear indicator of a non-human threat actor looking for legacy vulnerabilities or unauthorized access points.
show less
Automated multi-stage vulnerability reconnaissance originating from Microsoft Azure (Singapore). The ...
show moreAutomated multi-stage vulnerability reconnaissance originating from Microsoft Azure (Singapore). The actor is specifically targeting mail infrastructure (mail.muttmutt.us) and the root domain to locate pre-installed web shells and backdoors. Probes include hunting for specific malicious signatures such as ioxi-o.php, bolt.php, rip.php, and xmr.php. The bot is also attempting to find unauthorized administrative entry points in the /wp-admin/maint/ directory and hidden indices like /.trash7206/. This systematic scanning across different service endpoints indicates a coordinated effort to find legacy vulnerabilities or unauthorized access points for potential infrastructure takeover.
show less
Aggressive automated vulnerability scanning and shell-hunting originating from Microsoft Azure (Japa ...
show moreAggressive automated vulnerability scanning and shell-hunting originating from Microsoft Azure (Japan). The actor is specifically targeting the webdisk subdomain, searching for unauthorized administrative scripts and backdoors. Probes include high-velocity attempts to access akc.php, ioxi-o.php, bolt.php, and 0x.php. The scanner is also hunting for configuration leaks and unauthorized upload handlers within wp-content/uploads, wp-includes, and hidden directories like .well-known/logs233/. This activity spans multiple days, indicating a persistent effort to locate legacy vulnerabilities or post-exploitation shells.
show less
Aggressive automated vulnerability scanning and backdoor hunting originating from Microsoft Azure (A ...
show moreAggressive automated vulnerability scanning and backdoor hunting originating from Microsoft Azure (Australia). This actor is targeting mail infrastructure (webmail.muttmutt.us) with high-velocity probes across two days. The scanning behavior focuses on discovering pre-existing web shells (e.g., alfa-rex.php, ioxi-o.php, gecko-litespeed.php) and leveraging hidden directories like .well-known and .tmb. Additionally, the bot is hunting for unauthorized administrative access points within WordPress core structures (wp-admin/css/colors/ectoplasm/, wp-content/themes/hideo/network.php). This is a clear signature of non-human reconnaissance for post-exploitation entry points.
show less
Aggressive automated vulnerability scanning and backdoor hunting campaign originating from Microsoft ...
show moreAggressive automated vulnerability scanning and backdoor hunting campaign originating from Microsoft Azure (Hong Kong). The actor is targeting both the primary www domain and administrative subdomains (cpcontacts). The logs show high-velocity probes (over 60 requests in a single minute) targeting core WordPress directories for known malicious scripts including alfa-rex.php7, akc.php, and ioxi-o.php. The scanner is also searching for legacy file managers (db.php, file.php) and unauthorized administrative entry points within wp-content/plugins and wp-includes. This is a clear signature of non-human reconnaissance for post-exploitation backdoors.
show less
Automated vulnerability scanning and shell-hunting activity originating from Microsoft Azure (Japan) ...
show moreAutomated vulnerability scanning and shell-hunting activity originating from Microsoft Azure (Japan). The actor is targeting administrative subdomains (cpcalendars, cpanel) with high-velocity GET requests. Probes are specifically looking for common web shell signatures and backdoors, including alfa-rex.php7, akc.php, ioxi-o.php, and 0x.php. The bot is also attempting to find unauthorized administrative entry points within core WordPress directories (wp-admin/includes/, wp-content/plugins/) and hunting for sensitive "about" and "function" files hidden in deep directory structures. This is a clear signature of a non-human exploit scanner targeting infrastructure management endpoints.
show less
Persistent automated vulnerability scanning campaign originating from Microsoft Azure (India). This ...
show morePersistent automated vulnerability scanning campaign originating from Microsoft Azure (India). This actor is targeting administrative subdomains (cpcalendars, autodiscover) with high-frequency probes for pre-installed web shells and backdoors. Signatures include attempts to access alfa-rex.php, rip.php, mariju.php, and bolt.php. The bot is also hunting for configuration leaks and unauthorized upload handlers within the .well-known and /wp-admin/maint/ directories. This systematic reconnaissance across multiple infrastructure endpoints suggests a coordinated effort to find legacy vulnerabilities or unauthorized access points.
show less
Aggressive automated vulnerability scanner originating from Microsoft Azure (India). This actor is c ...
show moreAggressive automated vulnerability scanner originating from Microsoft Azure (India). This actor is conducting a persistent, multi-stage campaign targeting both the root domain and specialized subdomains (cpcontacts). The activity involves broad-spectrum probing for common web shell entry points (e.g., alfa-rex.php, mariju.php, gecko.php), configuration files, and unauthorized file managers (filemanager.php, ftp.php). Notably, the bot is attempting to abuse the .well-known directory to hide malicious scripts. The high frequency and diversity of the requested PHP paths indicate a comprehensive reconnaissance effort for post-exploitation backdoors.
show less
Automated multi-vector exploit reconnaissance originating from Microsoft Azure (Australia). This act ...
show moreAutomated multi-vector exploit reconnaissance originating from Microsoft Azure (Australia). This actor is targeting email and contact synchronization subdomains (cpcontacts, webmail, autodiscover) to locate pre-installed web shells and WordPress vulnerabilities. Probes include known malicious scripts like alfa-rex.php, rip.php, and akc.php, as well as hunting for administrative entry points in the wp-content/uploads and cgi-bin directories. The coordinated nature of these requests across different service endpoints indicates a sophisticated bot targeting infrastructure management.
show less
Sustained automated vulnerability scanning and shell-hunting campaign originating from Microsoft Azu ...
show moreSustained automated vulnerability scanning and shell-hunting campaign originating from Microsoft Azure (India). The actor is targeting administrative subdomains (cpcalendars, cpanel) with high-velocity probes for known web shells and backdoors, including alfa.php, alfa-rex.php, wsoyanz.php, and mariju.php. The scan includes attempts to leverage the .well-known directory for hidden script execution and searches for unauthorized file upload handlers. Activity spans multiple sessions across the day, indicating a persistent effort to compromise the server's control infrastructure.
show less
Automated exploit scan and backdoor hunting campaign originating from Microsoft Azure (Canada). The ...
show moreAutomated exploit scan and backdoor hunting campaign originating from Microsoft Azure (Canada). The actor is executing high-velocity requests (50+ probes in under 5 seconds) targeting root and core WordPress directories. Probes focus on common web shell filenames (zwso.php, manager.php, 0x.php) and unauthorized PHP execution points within wp-includes and wp-content. The scanner is also specifically looking for configuration leaks via paths like /wp-admin/network/wp-conflg.php (typosquatting style). This is a clear signature of non-human reconnaissance for pre-existing or post-exploitation backdoors.
show less
Persistent, multi-vector automated exploit campaign originating from Microsoft Azure (South Korea). ...
show morePersistent, multi-vector automated exploit campaign originating from Microsoft Azure (South Korea). The actor is performing systematic directory traversal and shell hunting across multiple sensitive subdomains (cpcalendars, webdisk, mail, webmail). The attack targets core WordPress directories (wp-includes, wp-content) and searches for specific malicious signatures including alfa-rex.php, wso.php, and various numeric/random PHP backdoors (222.php, ioxi-o.php). The breadth of the scan—spanning several hours and targeting infrastructure management subdomains—indicates a highly organized effort to identify unauthorized access points.
show less
Aggressive, multi-stage automated exploit campaign originating from a Microsoft Azure node (Japan). ...
show moreAggressive, multi-stage automated exploit campaign originating from a Microsoft Azure node (Japan). The actor is systematically probing mail, webdisk, and other subdomains for WordPress vulnerabilities and pre-installed web shells. Targeted paths include core directory overrides (e.g., /wp-includes/Requests/alfa-rex.php, /wp-admin/css/bolt.php) and specialized probes for the .well-known directory (e.g., mariju.php, gecko-litespeed.php). The high concurrency and breadth of filenames indicate a sophisticated scanner searching for legacy backdoors or unauthorized file upload points.
show less
Automated exploit reconnaissance and backdoor hunting campaign originating from Microsoft Azure (Can ...
show moreAutomated exploit reconnaissance and backdoor hunting campaign originating from Microsoft Azure (Canada). Actor is executing high-velocity, concurrent probes against www and webdisk for a wide variety of malicious PHP shells (e.g., karma_b001.php, bolt.php, t00l.php, alfashell.php) and randomized filenames (e.g., euhpb.php, cqrrg.php). The rapid-fire nature of these requests (multiple per second) across different subdomains indicates a sophisticated automated scanner looking for unauthorized file upload vulnerabilities.
show less
Massive automated vulnerability scan and web shell discovery campaign originating from a Microsoft A ...
show moreMassive automated vulnerability scan and web shell discovery campaign originating from a Microsoft Azure node. The actor is rapid-firing requests (over 100 in a single second) targeting a wide array of known backdoors, shells, and administrative scripts (e.g., alfashell.php, RIP.php, tinyfilemanager.php, BDKR28WP.php). The scan specifically targets the /home/ subdomain, attempting to locate unauthorized PHP execution points within WordPress core directories (wp-includes, wp-content). This is a clear signature of highly aggressive, non-human reconnaissance for post-exploitation entry points.
show less
Web App Attack
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.