Systematic web-tier reconnaissance and vulnerability probing. Source IP executed a high-velocity aut ...
show moreSystematic web-tier reconnaissance and vulnerability probing. Source IP executed a high-velocity automated scan targeting sensitive service endpoints and legacy PHP scripts, including /xmlrpc.php and /file.php, indicative of CMS-targeting botnet TTPs. Forensic analysis confirms the actor is utilizing Microsoft Azure infrastructure to conduct mass-scale directory enumeration and artifact discovery. All malicious requests were successfully neutralized at the application layer, resulting in HTTP 404 (Not Found) response codes across the targeted assets.
show less
Broad web-tier reconnaissance and telemetry gathering initiated by known commercial scanning infrast ...
show moreBroad web-tier reconnaissance and telemetry gathering initiated by known commercial scanning infrastructure (ONYPHE). The source IP systematically polled the web server root directory (GET /), triggering SIEM Rule 31101 (Web server 400 error code) due to an invalid or unsupported request structure. TTPs strictly align with automated internet-wide port scanning and banner grabbing rather than targeted exploitation. The automated probing was successfully neutralized at the web tier, resulting in an HTTP 400 (Bad Request) response code.
show less
Aggressive web-tier reconnaissance and vulnerability enumeration. The source IP initiated a high-vel ...
show moreAggressive web-tier reconnaissance and vulnerability enumeration. The source IP initiated a high-velocity burst of automated HTTP requests, triggering multiple 400-level web server errors indicative of malformed payloads or webshell probing. TTPs strictly align with mass-scanning botnet operations originating from Lithuanian cloud infrastructure (UAB Host Baltic) attempting to identify exploitable web application flaws. The malicious activity exceeded SIEM severity thresholds, triggering an automated Active Response mitigation that successfully neutralized the threat via an immediate firewall-level IP ban (Connection Dropped).
show less
Aggressive web-tier reconnaissance and vulnerability enumeration. The source IP initiated a high-vel ...
show moreAggressive web-tier reconnaissance and vulnerability enumeration. The source IP initiated a high-velocity burst of automated HTTP requests, triggering multiple 400-level web server errors indicative of malformed payloads or webshell probing. TTPs strictly align with mass-scanning botnet operations originating from Lithuanian cloud infrastructure (UAB Host Baltic) attempting to identify exploitable web application flaws. The malicious activity exceeded SIEM severity thresholds, triggering an automated Active Response mitigation that successfully neutralized the threat via an immediate firewall-level IP ban (firewalld-drop).
show less
Aggressive web-tier reconnaissance and vulnerability enumeration. Source IP initiated a high-velocit ...
show moreAggressive web-tier reconnaissance and vulnerability enumeration. Source IP initiated a high-velocity burst of automated HTTP requests, triggering multiple 400-level web server errors indicative of webshell and misconfiguration probing. TTPs align with mass-scanning botnet operations originating from CIPHER OPERATIONS DOO infrastructure attempting to identify exploitable web application flaws. The malicious activity exceeded SIEM severity thresholds, triggering an automated Active Response mitigation that successfully neutralized the threat via an immediate firewall-level IP ban (Connection Dropped).
show less
Aggressive web-tier reconnaissance and webshell enumeration. Source IP initiated a high-velocity bur ...
show moreAggressive web-tier reconnaissance and webshell enumeration. Source IP initiated a high-velocity burst of automated HTTP requests probing for sensitive configuration artifacts and exposed administrative endpoints. TTPs indicate an automated botnet originating from Kprohost infrastructure actively hunting for exploitable web application flaws. Activity exceeded SIEM severity thresholds, triggering an automated Active Response mitigation that successfully neutralized the threat via an immediate firewall-level IP ban (Connection Dropped / HTTP 403).
show less
Targeted web-tier reconnaissance and administrative backdoor enumeration. Source IP initiated a high ...
show moreTargeted web-tier reconnaissance and administrative backdoor enumeration. Source IP initiated a high-velocity burst of over 100 automated HTTP GET requests polling for sensitive PHP scripts and exposed WordPress administrative components (specifically targeting /wp-editor.php and /adminfuns.php). TTPs are highly consistent with automated mass-scanning botnet infrastructure attempting to locate and exploit unpatched CMS instances or orphaned webshells. All anomalous probes were successfully neutralized by the target server, resulting in HTTP 404 (Not Found) response codes.
show less
Targeted web-tier reconnaissance and backdoor enumeration. Source IP is rapidly polling for establis ...
show moreTargeted web-tier reconnaissance and backdoor enumeration. Source IP is rapidly polling for established post-exploitation webshells and vulnerable CMS components—specifically targeting /wp-content/plugins/hellopress/wp_filemanager.php (a known artifact from Balada/Elementor mass-compromise campaigns) alongside generic shells like /wpls.php. TTPs strictly align with automated botnet infrastructure attempting to identify and co-opt previously compromised WordPress environments. A localized burst of 14 distinct anomalous GET requests was detected. All probes successfully neutralized and dropped with HTTP 404 responses.
show less
HackingBad Web Bot
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.