Observed aggressive, high-volume automated reconnaissance (T1595) targeting legacy and potentially v ...
show moreObserved aggressive, high-volume automated reconnaissance (T1595) targeting legacy and potentially vulnerable PHP application components. Forensic log analysis identifies systematic probing for suspicious artifacts, including /kaza.php and /w.php, consistent with attempts to identify webshells or unlinked administrative interfaces. Global threat intelligence correlation confirms a persistent malicious actor with a 100% abuse confidence rating. All unauthorized ingress attempts were successfully neutralized at the application layer, resulting in HTTP 404 response codes.
show less
Observed aggressive automated reconnaissance and path traversal exploitation attempts (T1595/T1005) ...
show moreObserved aggressive automated reconnaissance and path traversal exploitation attempts (T1595/T1005) targeting container management interfaces and legacy CGI binaries. The actor performed unauthorized GET requests toward /containers/json to map Docker infrastructure and executed a sophisticated POST request utilizing deep path traversal sequences (/%2e%2e/) toward /cgi-bin/bin/sh, indicating a clear Remote Code Execution (RCE) intent. Forensic correlation with global threat intelligence confirms a high-persistence malicious actor with a 100% abuse confidence rating. All ingress attempts were effectively neutralized, returning HTTP 404 and 400 response codes.
show less
Observed aggressive automated probing (T1595) and exploitation attempts targeting sensitive configur ...
show moreObserved aggressive automated probing (T1595) and exploitation attempts targeting sensitive configuration files and server-side execution environments. Log analysis reveals a sophisticated RCE attempt via a Base64-encoded Node.js payload obfuscated within a Next.js data query parameter (/_next/data/), explicitly attempting to execute child_process.execSync for system command injection. Secondary TTPs included unauthorized access attempts to /.env and /api/.env files for credential exfiltration. All malicious requests were successfully intercepted and neutralized, resulting in HTTP 403 Forbidden status codes.
show less
Malicious source (ISP: Hetzner Online GmbH) identified performing automated directory traversal and ...
show moreMalicious source (ISP: Hetzner Online GmbH) identified performing automated directory traversal and unauthorized sensitive file discovery (MITRE T1083). Forensic telemetry reveals persistent probing of /.env and /wp-login.php artifacts, indicating a coordinated intent to harvest environment variables and enumerate CMS administrative credentials. Aggregated intelligence from VirusTotal (12/94 malicious) confirms the IPโs active involvement in broad-spectrum distributed brute-force campaigns. All unauthorized interaction attempts were successfully neutralized by the ModSecurity WAF and local security policies, resulting in consistent HTTP 403 Forbidden and 404 Not Found responses.
show less
Observed high-frequency automated reconnaissance (T1595) targeting PHP-based web assets. Forensic ev ...
show moreObserved high-frequency automated reconnaissance (T1595) targeting PHP-based web assets. Forensic evidence identifies systematic probing for potential webshells or administrative backdoors, specifically targeting URIs /wsa.php and /100.php. Threat intelligence correlation confirms a high confidence of abuse associated with widespread botnet-driven scanning. All unauthorized ingress attempts were successfully mitigated at the application layer, resulting in HTTP 404 status codes.
show less
Malicious source identified executing automated reconnaissance and brute-force probing (MITRE T1083) ...
show moreMalicious source identified executing automated reconnaissance and brute-force probing (MITRE T1083) against WordPress authentication endpoints. Forensic analysis of Nginx access logs reveals 45 high-frequency requests targeting the /wp-login.php artifact within a singular alert window. Multi-vendor threat intelligence (VirusTotal 8/94) confirms active participation in distributed credential harvesting and web application scanning. All unauthorized interaction attempts were successfully neutralized via local security policy, resulting in continuous HTTP 404 responses.
show less
Observed systematic automated reconnaissance (T1595) utilizing the LeakIX (l9scan) platform to map t ...
show moreObserved systematic automated reconnaissance (T1595) utilizing the LeakIX (l9scan) platform to map the application attack surface. Forensic log analysis identifies targeted probing for sensitive API documentation and server metadata, specifically referencing /api-docs/swagger.json and /server. The activity is consistent with shadow API discovery and unauthorized vulnerability research conducted via Cloudflareโs proxy infrastructure to obfuscate the true source. All malicious ingress attempts were successfully neutralized at the origin, resulting in HTTP 404 status codes.
show less
Malicious actor (ISP: Cloudflare, Inc.) identified conducting automated reconnaissance and unauthori ...
show moreMalicious actor (ISP: Cloudflare, Inc.) identified conducting automated reconnaissance and unauthorized probing of sensitive CMS artifacts (MITRE T1083). Forensic telemetry from Nginx and ModSecurity confirms persistent targeting of the /xmlrpc.php endpoint, indicative of WordPress amplification or credential brute-force campaigns. Intelligence correlation from VirusTotal validates the IP's involvement in high-frequency web application attacks, with 10 vendors flagging the source as malicious. All observed interaction attempts were successfully neutralized by the WAF and local server configuration, resulting in consistent HTTP 403 Forbidden and 404 Not Found responses.
show less
Observed aggressive automated reconnaissance and vulnerability scanning (T1595) targeting PHP applic ...
show moreObserved aggressive automated reconnaissance and vulnerability scanning (T1595) targeting PHP application artifacts. The actor utilized HTTP/1.1 GET requests to probe for non-existent but high-interest paths including /new.php and /zxin.php, indicative of efforts to identify webshells or misconfigured administrative interfaces. Correlation with global threat intelligence indicates a persistent malicious actor with a 100% abuse confidence score. The attack was successfully mitigated with the server returning HTTP 404 for all requests.
show less
Malicious source identified performing automated reconnaissance and unauthorized sensitive file disc ...
show moreMalicious source identified performing automated reconnaissance and unauthorized sensitive file discovery (MITRE T1083). Forensic analysis of SIEM logs reveals persistent probing of critical URI artifacts including /.env and /wp-login.php, indicative of environment variable harvesting and CMS account enumeration or brute-force intent. Multi-vendor threat intelligence confirms the IP is associated with high-confidence bad web bot activity and distributed web application attacks. All unauthorized access attempts were successfully neutralized by the ModSecurity WAF and local server configurations, resulting in consistent HTTP 403 Forbidden and 404 Not Found responses.
show less
Observed persistent automated reconnaissance and mass-scanning activity (T1595) targeting web root i ...
show moreObserved persistent automated reconnaissance and mass-scanning activity (T1595) targeting web root infrastructure. Source utilized malformed HTTP/1.1 GET requests characterized by null User-Agent strings and missing headers, indicating non-browser automated probing typical of botnet-driven directory traversal attempts. Global threat intelligence correlation confirms 100% abuse confidence with high-volume reports across multiple security vendors for malicious behavior. All ingress attempts were successfully mitigated at the application tier, resulting in HTTP 400 status codes.
show less
Malicious actor (ISP: Microsoft Corporation) identified conducting aggressive automated directory tr ...
show moreMalicious actor (ISP: Microsoft Corporation) identified conducting aggressive automated directory traversal and credential discovery probing (MITRE T1083). Forensic analysis of Nginx and Apache logs reveals high-frequency requests targeting sensitive CMS endpoints, specifically /wp-login.php and /wp-signup.php, indicating an intent to enumerate user accounts or execute a brute-force authentication attack. The activity triggered 275 Wazuh security alerts (Rule 31101) within a compressed timeframe, characteristic of an automated bad web bot. All unauthorized access attempts were successfully mitigated, with the server returning persistent HTTP 404 responses.
show less
Observed systematic automated reconnaissance and path discovery targeting WordPress and administrati ...
show moreObserved systematic automated reconnaissance and path discovery targeting WordPress and administrative PHP artifacts. Source utilized HTTP/1.0 GET requests to probe sensitive URIs including /wp-editor.php and /adminfuns.php, indicating active scanning for misconfigurations and vulnerable web components (T1595). Threat intelligence confirms high-volume abuse reports consistent with bot-driven directory traversal and unauthorized probing. All malicious requests were successfully neutralized with HTTP 404 responses.
show less
Malicious source identified performing automated sensitive file discovery (MITRE T1083) specifically ...
show moreMalicious source identified performing automated sensitive file discovery (MITRE T1083) specifically targeting the /.env URI. Multi-vendor threat intelligence confirms the IP is actively engaged in distributed telnet brute-force campaigns and unauthorized port scanning. The observed TTPs involve high-frequency, automated probing for configuration artifacts and environment variables, indicative of a persistent bad web bot. All logged interaction attempts were successfully neutralized by the ModSecurity WAF and local firewall rules, resulting in consistent HTTP 403 Forbidden responses.
show less
Aggressive automated web reconnaissance and sensitive artifact enumeration. Source IP initiated targ ...
show moreAggressive automated web reconnaissance and sensitive artifact enumeration. Source IP initiated targeted probes for version control metadata, specifically /.git/config, attempting to identify server misconfigurations for credential exfiltration and source code disclosure. TTPs align with automated botnet infrastructure systematically searching for exposed Git repositories across the public web tier. The attack sequence was successfully neutralized by the server, yielding HTTP 403 (Forbidden) and 400 (Bad Request) responses across 16 distinct forensic events.
show less
Sustained web-tier reconnaissance and vulnerability enumeration originating from Microsoft Azure inf ...
show moreSustained web-tier reconnaissance and vulnerability enumeration originating from Microsoft Azure infrastructure. The actor executed high-velocity automated probing for sensitive PHP artifacts and known WordPress post-exploitation components, specifically targeting /100.php and /wp-content/plugins/hellopress/wp_filemanager.php. These TTPs indicate botnet-driven mass-exploitation activity seeking exposed CMS handlers or orphaned webshells. All malicious requests were successfully neutralized by the server infrastructure, resulting in 320 events yielding HTTP 404 (Not Found) response codes.
show less
Systematic automated web-tier reconnaissance and vulnerability enumeration targeting WordPress and P ...
show moreSystematic automated web-tier reconnaissance and vulnerability enumeration targeting WordPress and PHP artifacts. Source IP executed high-velocity directory and file enumeration, specifically targeting sensitive service endpoints and legacy scripts such as /xmlrpc.php, /file.php, and /wp.php. Investigative analysis of TTPs indicates botnet-driven mass-exploitation activity seeking exposed CMS handlers or misconfigured PHP application files for post-exploitation access. All malicious requests were successfully neutralized by the server infrastructure, yielding consistent HTTP 404 (Not Found) responses across 82 detected forensic events.
show less
High-velocity automated web reconnaissance and vulnerability enumeration. Source IP initiated a rapi ...
show moreHigh-velocity automated web reconnaissance and vulnerability enumeration. Source IP initiated a rapid polling sequence targeting specific PHP artifacts and potential administrative backdoors, including /inputs.php and /ioxi-o.php. TTPs are characteristic of botnet-driven mass-scanning infrastructure seeking exploitable application handlers or orphaned webshells. Forensic analysis confirms a sustained burst of 75 malicious GET requests, all of which were successfully neutralized at the application layer with HTTP 404 (Not Found) responses.
show less
Aggressive automated reconnaissance and sensitive artifact enumeration targeting environment configu ...
show moreAggressive automated reconnaissance and sensitive artifact enumeration targeting environment configuration and cloud metadata. The threat actor initiated persistent probing for critical secrets, specifically /.env and complex path traversal attempts for /home/user/.aws/credentials, indicating a clear intent to exfiltrate database credentials and AWS access keys. TTPs strictly align with automated exploitation infrastructure performing unauthorized path discovery and secret harvesting. All malicious requests were successfully neutralized by the server infrastructure, yielding HTTP 400 responses and triggering multi-event error escalation rules.
show less
Targeted reconnaissance and sensitive artifact enumeration. Source IP initiated automated probing fo ...
show moreTargeted reconnaissance and sensitive artifact enumeration. Source IP initiated automated probing for exposed version control directories, specifically targeting /.git/config to facilitate unauthorized source code or credential disclosure. These TTPs strictly align with automated botnet activity seeking common web server misconfigurations for post-exploitation. All anomalous requests were successfully neutralized by the server infrastructure, yielding HTTP 403 (Forbidden) and HTTP 400 (Bad Request) response codes across 24 distinct events.
show less
Automated web application reconnaissance and post-exploitation artifact discovery. The source IP, or ...
show moreAutomated web application reconnaissance and post-exploitation artifact discovery. The source IP, originating from Tencent Cloud infrastructure, utilized a script-based agent (python-requests) to probe for a pre-staged webshell backdoor at /she.php while explicitly attempting command execution via the 1=dir parameter. These TTPs indicate a targeted search for compromised hosts or vulnerable web-handlers consistent with automated botnet "door-knocking" operations. Probes were successfully neutralized at the application tier with HTTP 404 (Not Found) responses.
show less
Targeted web-tier reconnaissance and API enumeration. Actor utilized POST-method requests to probe i ...
show moreTargeted web-tier reconnaissance and API enumeration. Actor utilized POST-method requests to probe internal Next.js application structures and backend API endpoints, specifically targeting /_next and /api/route. This behavior is characteristic of automated scanning infrastructure attempting to map application logic or discover vulnerabilities within modern JavaScript frameworks. All anomalous probes were successfully identified and neutralized by the host, yielding HTTP 404 (Not Found) response codes across multiple attempts.
show less
Aggressive web-tier reconnaissance and post-exploitation artifact enumeration. The threat actor, uti ...
show moreAggressive web-tier reconnaissance and post-exploitation artifact enumeration. The threat actor, utilizing Azure cloud infrastructure, executed a high-velocity automated scan (202 events) specifically polling for established webshell backdoors such as '/FoxWSOv1.php' and vulnerable WordPress components like '/wp-content/plugins/hellopress/wp_filemanager.php'. These TTPs are characteristic of botnet infrastructure attempting to identify and leverage existing compromises or unpatched directory vulnerabilities for unauthorized access. All malicious requests were successfully neutralized at the application layer, resulting in HTTP 404 (Not Found) response codes across the targeted assets.
show less
Targeted web-tier reconnaissance and directory enumeration originating from Microsoft Azure infrastr ...
show moreTargeted web-tier reconnaissance and directory enumeration originating from Microsoft Azure infrastructure. The actor executed high-velocity automated polling for hidden directories and WordPress theme artifacts, specifically targeting /.trash7206/index.php and /wp-content/themes/. These TTPs indicate automated botnet activity attempting to identify misconfigured application handlers or orphaned backup files for post-exploitation. All malicious requests were successfully neutralized by the host, yielding HTTP 404 (Not Found) and HTTP 403 (Forbidden) response codes across 74 distinct events.
show less
Targeted web-tier reconnaissance and automated vulnerability enumeration originating from Microsoft ...
show moreTargeted web-tier reconnaissance and automated vulnerability enumeration originating from Microsoft Azure infrastructure in Hong Kong. The actor executed a high-velocity polling sequence for sensitive PHP artifacts, specifically targeting endpoints such as /inputs.php and /elp.php. These TTPs indicate automated botnet activity seeking legacy backdoors or misconfigured application handlers for post-exploitation access. All malicious requests were successfully neutralized by the host, yielding HTTP 404 (Not Found) response codes across 75 distinct events.
show less
Bad Web BotWeb App Attack
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.