Extremely aggressive, high-velocity automated vulnerability scanning and web shell hunting. The acto ...
show moreExtremely aggressive, high-velocity automated vulnerability scanning and web shell hunting. The actor is systematically probing the cpcontacts subdomain for a massive list of known malicious PHP backdoors and administrative entry points.
Observed Activity:
Malicious Shell Hunting: Intensive probing for known backdoors: /bolt.php, /rip.php, /ioxi-o.php, /sx.php, and /ammika.php.
WordPress Core Targeting: Systematic scanning for unauthorized scripts placed in core directories: /wp-admin/css/bolt.php, /wp-content/upgrade/222.php, and /wp-includes/nux.php.
Administrative Probing: Searching for administrative and diagnostic tools: /adminfuns.php, /autodiagnosis.php, and various scripts in /wp-admin/maint/.
Method: High-speed automated HTTP GET requests (23+ requests logged within the exact same second), indicating a highly efficient exploit scanner.
Frequency: This is a persistent, automated attack pattern designed to locate pre-existing infections or exploit weak file permissions.
show less
Persistent and aggressive vulnerability scanning detected targeting sensitive mail and web storage s ...
show morePersistent and aggressive vulnerability scanning detected targeting sensitive mail and web storage subdomains (mail., webdisk.). The actor is systematically probing for common web shell backdoors, WordPress administrative vulnerabilities, and unauthorized file uploaders.
Observed Activity: * Shell/Backdoor Hunting: Extensive searching for malicious PHP scripts including /wsoyanz.php, /bolt.php, /ioxi-o.php, /fff.php, and /rip.php.
WordPress Exploitation: Targeting core directories with randomized PHP filenames: /wp-content/themes/admin.php, /wp-admin/css/bolt.php, /wp-act.php, and /wp-conf.php.
Administrative Probing: Scanning for entry points in /wp-admin/, /cgi-bin/, and obscured paths like /.trash7206/ and /.well-known/logs233/.
Method: High-frequency automated HTTP GET requests tailored to find misconfigured or previously compromised environments.
Frequency: Sustained activity across multiple hours on March 12, indicating a botnet-driven scanning operation.
show less
Aggressive automated vulnerability scanning and backdoor probing detected. The source is targeting a ...
show moreAggressive automated vulnerability scanning and backdoor probing detected. The source is targeting administrative subdomains (cpcontacts.) and the root domain to locate and exploit web shells and malicious PHP scripts.
Observed Activity:
Backdoor/Shell Hunting: Probing for known malicious scripts: /wsoyanz.php, /randkeyword.PhP7, /ioxi-o.php, /xleet, and /ws.php.
WordPress Exploitation: Systematic scanning of /wp-content/ and /wp-includes/ for administrative bypasses and obfuscated shells (e.g., /wp-content/themes/hideo/network.php, /wp-admin/images/).
Administrative Probing: Attempting to access sensitive paths including wp-login.php, wp-trackback.php, and the .well-known/ directory.
Method: Rapid, high-density GET requests (multiple hits per second), indicating the use of an automated exploit kit.
Intent: Identifying Remote Code Execution (RCE) vulnerabilities or unauthorized file uploaders.
show less
Aggressive vulnerability scanning and exploit probing targeted at the webdisk subdomain. The source ...
show moreAggressive vulnerability scanning and exploit probing targeted at the webdisk subdomain. The source is systematically searching for insecure file upload modules and sensitive WordPress core directories to identify potential entry points.
Observed Activity:
Targeted Exploit Search: Probing for a known vulnerable Joomla extension: /modules/mod_simplefileuploadv1.3/elements/.
WordPress Probing: Intensive scanning for non-standard or malicious PHP files within core directories: /wp-includes/js/jquery/jquery.php, /wp-content/themes/admin.php, and /wp-user.php.
Infrastructure Hunting: Systematic checking of /uploads/ and /wp-includes/certificates/ to locate sensitive files or writeable directories.
Frequency: High-density burst (all requests occurring within the same second), characteristic of an automated security scanner or botnet-driven attack tool.
Intent: Identifying Remote Code Execution (RCE) vulnerabilities or unauthorized file upload capabilities.
show less
Aggressive automated vulnerability scanning and directory traversal attempts detected. The source is ...
show moreAggressive automated vulnerability scanning and directory traversal attempts detected. The source is specifically targeting administrative subdomains (cpcalendars., cpanel.) to hunt for backdoors, misconfigured WordPress core files, and sensitive info pages.
Observed Activity:
Backdoor & Shell Hunting: Probing for known malicious filenames like /images/wso.php, /0x.php, /222.php, and /wp-fclass.php.
WordPress Exploitation: Systematic scanning of /wp-includes/ and /wp-content/ for "about.php" scripts (often used as obfuscated shells) and probing xmlrpc.php.
Infrastructure Probing: Specifically targeting CPanel/Control Panel subdomains to find entry points through extensions or themes.
Frequency: High-velocity bursts (multiple requests within the same second), characteristic of a botnet-driven exploit scanner.
Intent: Identifying Remote Code Execution (RCE) vulnerabilities or pre-existing web shells to gain unauthorized server access.
show less
Aggressive automated vulnerability scanning and backdoor hunting detected. The source is systematica ...
show moreAggressive automated vulnerability scanning and backdoor hunting detected. The source is systematically probing for a wide range of common web shells, administrative scripts, and WordPress-specific files across multiple hostnames.
Observed Activity:
Backdoor/Shell Hunting: Targeted requests for malicious PHP scripts including /0x1949.php, /as.php, /bs1.php, /sx.php, and /ws.php.
WordPress Probing: Scanned for sensitive core files and login entry points: /wp-class.php, /wp-includes/wp-class.php, /wp-login.php, and /wp-admin/maint/admin.php.
Systematic Scanning: Rapid GET requests for common system and configuration files: /autoload_classmap.php, /ini.php, /install.php, and /manager.php.
Frequency: High-density bursts (multiple hits per second) occurring in a sustained automated fashion.
Intent: Identifying unauthorized remote access points or Remote Code Execution (RCE) vulnerabilities.
show less
Extremely aggressive automated vulnerability scanning and web shell hunting detected. The source is ...
show moreExtremely aggressive automated vulnerability scanning and web shell hunting detected. The source is performing exhaustive probing for backdoors, unauthorized file uploaders, and specific WordPress vulnerabilities across multiple hostnames.
Observed Activity:
Backdoor/Shell Hunting: Targeted requests for known malicious scripts: /alfanew.php7, /fierzashell.php, /alfa-rex.php, and /bolt.php.
WordPress Core & Plugin Exploitation: Probing for vulnerabilities in revslider, ninja-forms, and sensitive core paths including /wp-includes/PHPMailer.php, /xmlrpc.php, and various obscured PHP files in wp-admin and wp-includes.
Administrative Probing: Scanning for /admin/, /update/, and .well-known/ directories to find misconfigured or unprotected scripts.
Frequency: Persistent, high-density bursts across multiple hours (March 11–12), indicating a sophisticated botnet exploit kit.
Intent: Identifying Remote Code Execution (RCE) entry points and bypassing security via pre-existing backdoors or known plugin flaws.
show less
Aggressive automated vulnerability scanning and backdoor probing detected. The source is systematica ...
show moreAggressive automated vulnerability scanning and backdoor probing detected. The source is systematically targeting multiple subdomains to locate and exploit malicious PHP scripts and administrative entry points.
Observed Activity:
Backdoor Hunting: Targeted probing for known shell patterns: /karma_0cc5.php, /karma_e76a.php, /karma_b001.php, /sc.php, /t00l.php, and /bolt.php.
WordPress Probing: Scanned for vulnerabilities in core directories: /wp-admin/images/acxx.php.
Systematic Crawling: Rapid GET requests for a variety of randomized and suspicious PHP files (e.g., /cqrrg.php, /fvlje.php, /fsjne.php, /zwq13.php).
Pattern: Activity is mirrored across www. and autodiscover. hostnames, indicating an automated botnet-style scanner.
Frequency: Extremely high density (multiple requests per second), consistent with automated exploit kits. 365 requests total.
Intent: Attempting to find unauthorized file uploaders, command shells, or RCE vulnerabilities.
show less
Aggressive automated vulnerability scanning and backdoor hunting detected. The source is systematica ...
show moreAggressive automated vulnerability scanning and backdoor hunting detected. The source is systematically probing for web shells and known vulnerable paths across root and subdomains.
Observed Activity:
Shell Probing: Targeted /alfashell.php, /axx.php, /prv8.php, and /f35.php, indicating an attempt to locate pre-installed malicious shells.
WordPress Exploitation: Probing specific plugin and core paths: /wp-content/plugins/pwnd/as.php, /wp-includes/SimplePie/, and /wp-admin/js/fi.php.
Systematic Scanning: Rapid GET requests for common database and admin files: /database.php, /acp.php, /dev.php, and /init.php.
Frequency: Multiple requests per second in high-density bursts, consistent with botnet-led exploit kits. 523 requests total.
Intent: Identifying unauthorized entry points for Remote Code Execution (RCE) or data exfiltration.
show less
Over 450 malicious requests detected within a 24-hour period. The source is performing aggressive au ...
show moreOver 450 malicious requests detected within a 24-hour period. The source is performing aggressive automated scans for various suspicious PHP endpoints and known vulnerabilities.
Observed Activity:
Vulnerability Probing: Targeted /wp-content/plugins/hellopress/wp_filemanager.php, likely searching for file upload or remote code execution exploits.
Malicious Script Scanning: Rapid GET requests for numerous non-existent or suspicious PHP files including /karma_0cc5.php, /karma_e76a.php, /sc.php, /12.php, and various 5-character randomized scripts (e.g., /euhpb.php, /cqrrg.php, /fvlje.php).
Frequency: High-volume bursts (over 200 mitigated events) appearing to bypass or test standard security configurations.
User Agent: Unknown/Other (Desktop), consistent with automated bot activity.
show less
Summary of Activity:
The source IP engaged in an aggressive automated vulnerability scan, totaling ...
show moreSummary of Activity:
The source IP engaged in an aggressive automated vulnerability scan, totaling 529 requests within a single hour. Cloudflare identified and mitigated 210 of these as suspicious. The attacker utilized a "Desktop" user-agent with an "Unknown/Other" browser and operating system, typical of automated headless scanning tools.
Observed Attack Patterns:
The attacker systematically probed for common backdoors, web shells, and WordPress vulnerabilities. The frequency of requests (multiple per second) indicates a high-velocity bot attack.
Extracted Malicious Paths (Categorized):
Web Shells & RCE Probes: /rip.php, /sbhu.php, /ws84.php, /ws83.php, /ws75.php, /public/ws49.php, /byypas.php, /assacc.php.
WordPress Hardening Bypass/Exploits: /wp-tap.php, /wp-tot.php, /wp-good.php, /wp-blogs.php, /wp-png.php, /wp-access.php, /wp-content/radio.php.
Suspicious PHP Payloads: /goat.php, /koiy.php, /qqjki.php, /vrhiw.php, /lclnqiii.php, /xenium4.php, /vhwwnrnmqc.php, /bkyac.php, /awdld.php
show less
Engaged in a heavy automated vulnerability scan against multiple domains. The attacker targeted know ...
show moreEngaged in a heavy automated vulnerability scan against multiple domains. The attacker targeted known malicious web shell paths (e.g., /wp-includes/js/crop/shell.php, /WSO.php, /alfanew.php) and attempted to access sensitive plugin directories for Remote Code Execution (RCE). Over 100 requests were made in under 3 seconds, indicating an aggressive automated exploit attempt.
show less
Attempted to access the following over about 30 seconds:
/wp-content/plugins/linkpreview/av.php
...
show moreAttempted to access the following over about 30 seconds:
/wp-content/plugins/linkpreview/av.php
/img/chat-search.php
/images/file.php
/wp-admin/user/file.php
/wp-admin/maint/flex.php
/wp-content/themes/tflow/adminfus.php
/js/1.php7
/wp-content/click.php
/as/function.php
/css/about.php
/type.php
/files.php%20
/wp-includes/wp-conflg.php
/setup-config.php
/wp-includes/PHPMailer/autoload_classmap.php
/backup/autoload_classmap.php
/wp-content/plugins/wp-theme-editor/include.php%20
/wp-includes/class-wp-taxonomy-sample.php
/wp-includes/ID3/chosen.php
/wp-includes/load.php
/wp-content/themes/twentytwentyfour/install.php
/wp-admin/css/colors/blue/admin-footer.php
/wp-content/plugins/erinyani/
/wp-includes/sitemaps/
/wp-content/uploads/2023/11/
/wp-includes/images/
show less
Attempting to access:
/wp-content/themes/admin.php
/wp-content/plugins/index.php
/wp-content/them ...
show moreAttempting to access:
/wp-content/themes/admin.php
/wp-content/plugins/index.php
/wp-content/themes/index.php
/index/function.php
/wp-includes/Requests/src/Response/about.php
/wp-admin/images/
/wp-includes/images/
/wp-includes/PHPMailer/
/uploads/
/cgi-bin/
show less