Directory enumeration via HEAD requests (/old/, /backup/, /blog/, /wordpress/).
Uses historical do ...
show moreDirectory enumeration via HEAD requests (/old/, /backup/, /blog/, /wordpress/).
Uses historical domains (candida.de, alkohol-ade.com) as referers -
evidence of prior reconnaissance into server history. Rotating user agents.
show less
MJ12bot impersonation with curated German-language search queries
targeting specific alcohol/neuro ...
show moreMJ12bot impersonation with curated German-language search queries
targeting specific alcohol/neuroscience topic niche. Same keyword
list previously seen from Asian IPs - distributed botnet using
shared target list. Verizon fixed line, likely compromised endpoint.
show less
Headless browser accessing specific forum post ID (48086), followed by
5 rapid admin-ajax POSTs in ...
show moreHeadless browser accessing specific forum post ID (48086), followed by
5 rapid admin-ajax POSTs in 7 seconds, then navigating to target article.
No fbclid this time - forum post used as entry point.
Vodafone Kabel Deutschland Berlin.
show less
Directory enumeration via HEAD requests probing for hidden WordPress
installations and backup dire ...
show moreDirectory enumeration via HEAD requests probing for hidden WordPress
installations and backup directories (/wordpress/, /backup/, /wp/, /old/,
/new/). Rotating user agents. Uses unrelated domain as referer to
obscure origin.
show less
Login attempt with redirect to specific member profile ID (/participant/xxxx/).
Fake user agent: O ...
show moreLogin attempt with redirect to specific member profile ID (/participant/xxxx/).
Fake user agent: Opera 9.69 with Khmer language code (km-KH) - non-existent
combination. Previously reported as Bad Web Bot with fake UA.
show less
Extensive webshell enumeration. Probed dozens of known and
randomly-named PHP backdoor paths inclu ...
show moreExtensive webshell enumeration. Probed dozens of known and
randomly-named PHP backdoor paths including wp-content/plugins/,
wp-admin/maint/, and root-level shells (asd.php, t.php, a.php,
ws81.php, 6xBAm3vODE05BSzkJZRAws.php etc.).
show less
Scanning for sensitive files: wp-config.php.bak, /.env, PHP webshells.
Rate-limited and blocked by ...
show moreScanning for sensitive files: wp-config.php.bak, /.env, PHP webshells.
Rate-limited and blocked by NinjaFirewall. Fro LLC datacenter,
Kansas City. Consistent with multiple reports today across German
WordPress sites.
show less
Systematic webshell enumeration across WordPress directories.
Probing for known backdoor filenames ...
show moreSystematic webshell enumeration across WordPress directories.
Probing for known backdoor filenames (worksec.php) and PHP files
in theme/plugin/cache directories. Looking for previously planted
shells.
show less
Credential stuffing attack against ARMember login endpoint /aa-login/.
5 rapid POST requests to ad ...
show moreCredential stuffing attack against ARMember login endpoint /aa-login/.
5 rapid POST requests to admin-ajax.php within 9 seconds.
Fixed line ISP, likely compromised endpoint.
show less
Webshell scanning and plugin exploit probing. Attempted to access
known webshell paths: moon.php, ...
show moreWebshell scanning and plugin exploit probing. Attempted to access
known webshell paths: moon.php, a1.php, ahax.php, lite.php, k.php,
leaf.php, wp_filemanager.php (hellopress plugin exploit),
wp-conflg.php (typosquatted wp-config.php). No User-Agent,
no Referer - automated scanner. Web App Attack.
show less
Plugin health-check endpoint reconnaissance (?wmo_hc= parameter).
Same IP rotated two different us ...
show morePlugin health-check endpoint reconnaissance (?wmo_hc= parameter).
Same IP rotated two different user agents (Windows Chrome, Mac Firefox)
within 1 second. Also probed typo domain to confirm shared infrastructure.
OVH datacenter IP, no legitimate use case. Web App Attack.
show less
Plugin reconnaissance probe. Parameter ?element-bbcode-showed=1
with cache-buster timestamp. Data ...
show morePlugin reconnaissance probe. Parameter ?element-bbcode-showed=1
with cache-buster timestamp. Data center IP (Fine Group Servers,
AS59651, Marsta SE). Known bulletproof hosting range.
Category: Web App Attack.
show less
Headless browser attack disguised as Facebook iOS app traffic.
Fake iOS 26.x UA (non-existent OS v ...
show moreHeadless browser attack disguised as Facebook iOS app traffic.
Fake iOS 26.x UA (non-existent OS version). 4 simultaneous
POST /wp-admin/admin-ajax.php within 1 second + POST /.
fbclid-cloaked. IP appears to be compromised Swiss business endpoint.
show less
MJ12bot impersonation, ignoring robots.txt. Systematic forum crawling/content harvesting on WordPres ...
show moreMJ12bot impersonation, ignoring robots.txt. Systematic forum crawling/content harvesting on WordPress site. IP belongs to Lyse Tele AS Norway. Already listed as 100% abuse score.
show less
Scripted behavior with repeated identical navigation sequence, UA switching between WebView and MIUI ...
show moreScripted behavior with repeated identical navigation sequence, UA switching between WebView and MIUI Browser, multiple simultaneous admin-ajax calls β part of ongoing coordinated botnet attack since 2026-04-29
show less
fbclid cover, simultaneous POST on / and double admin-ajax in one second β part of ongoing coordinat ...
show morefbclid cover, simultaneous POST on / and double admin-ajax in one second β part of ongoing coordinated botnet attack since 2026-04-29
show less
Fake iOS 26.4 (OS doesn't exist), fbclid cover, simultaneous POST on / and admin-ajax β part of ongo ...
show moreFake iOS 26.4 (OS doesn't exist), fbclid cover, simultaneous POST on / and admin-ajax β part of ongoing coordinated botnet attack since 2026-04-29
show less
Credential stuffing, systematic login endpoint enumeration targeting both /aa-login/ and /einloggen- ...
show moreCredential stuffing, systematic login endpoint enumeration targeting both /aa-login/ and /einloggen-2/ after failed login β part of ongoing coordinated botnet attack since 2026-04-29
show less
UA inconsistency between GET and POST (FB_IAB missing on first request), 7x simultaneous admin-ajax ...
show moreUA inconsistency between GET and POST (FB_IAB missing on first request), 7x simultaneous admin-ajax calls targeting registration page β part of ongoing coordinated botnet attack since 2026-04-29
show less
ARMember-specific login endpoint probing (/arm-login/), infrastructure subdomain scanning, switching ...
show moreARMember-specific login endpoint probing (/arm-login/), infrastructure subdomain scanning, switching between .at and .com domains β part of ongoing coordinated attack since 2026-04-29
show less
Targeted members-only content access attempt, POST on / after access denial β part of ongoing coordi ...
show moreTargeted members-only content access attempt, POST on / after access denial β part of ongoing coordinated botnet attack since 2026-04-29
show less
Fake iPadOS 26.3.1 (OS doesn't exist), systematic login enumeration targeting /einloggen-2 β part of ...
show moreFake iPadOS 26.3.1 (OS doesn't exist), systematic login enumeration targeting /einloggen-2 β part of ongoing coordinated botnet attack since 2026-04-29
show less
Source map enumeration (.css.map, .js.map files) to identify plugin versions and code structure for ...
show moreSource map enumeration (.css.map, .js.map files) to identify plugin versions and code structure for vulnerability research β confirmed by AbuseIPDB report 'trolling for resource vulnerabilities' from same day
show less
Web App Attack
By clicking βAccept allβ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.