Unauthorized automated vulnerability scanning targeting our production API at api.getltvpn.com on Oc ...
show moreUnauthorized automated vulnerability scanning targeting our production API at api.getltvpn.com on October 8, 2026, between 06:16 and 08:34 (UTC+3).
Source IP: 5.199.164.231.
The attacker sent numerous HTTP requests attempting to access sensitive configuration files (.env, .env.production, .env.backup), AWS credentials, service account secrets, internal API endpoints, and system files such as /etc/passwd.
The scanning also included directory traversal, SQL injection, and remote code execution probes targeting multiple web applications and frameworks.
All observed requests returned HTTP 403 (Forbidden). This activity was unauthorized and is not associated with any approved penetration testing or security assessment.
The incident has also been reported directly to the hosting provider, Cherry Servers, with supporting HTTP access logs.
show less
Bad Web BotWeb App AttackSQL InjectionHacking
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.