Automated PHP remote code execution / webshell drop against Joomla com_content (feed view, {source} ...
show moreAutomated PHP remote code execution / webshell drop against Joomla com_content (feed view, {source} template injection). Single source sent GET /index.php?option=com_content&view=featured&format=feed with an injected <?= file_put_contents('a6955c8bd301.php', base64_decode(...)) ?> payload intended to write a persistent PHP webshell to disk. Decoded shell is password-gated (md5 of cookie d), provides arbitrary code execution via eval(base64_decode(REQUEST[id])) and file upload via multipart POST, and echoes a fixed beacon value to confirm install. All 3 requests blocked (HTTP 444, connection dropped by WAF/tripwire)
show less
Automated WordPress user enumeration and login brute-force. Single source retrieved the REST users e ...
show moreAutomated WordPress user enumeration and login brute-force. Single source retrieved the REST users endpoint (GET /?rest_route=/wp/v2/users, HTTP 200) to enumerate usernames, then attempted authentication via POST /wp-login.php and POST /xmlrpc.php. Login and xmlrpc attempts blocked (HTTP 403); the REST user-enumeration request succeeded (HTTP 200). Rotating User-Agents per request. Activity: 2026-08-12 21:06:51-21:06:57 CEST (UTC+2).
show less
Automated WordPress reconnaissance. Single source swept for xmlrpc.php across ~14 candidate subdirec ...
show moreAutomated WordPress reconnaissance. Single source swept for xmlrpc.php across ~14 candidate subdirectories (/, /blog/, /wp/, /wordpress/, /site/, /news/, /web/, /main/, /cms/, /wp-site/, /wpsite/, /old/, /new/) via POST, plus GET probes for /wp-admin/ and /wp-login.php, rotating User-Agents per request. Target is not WordPress - all xmlrpc.php probes returned 404/301. No credentials submitted; endpoint discovery only. Activity: 2026-08-12 10:27:49-10:27:55 CEST (UTC+2).
show less
Automated webshell/backdoor and admin-panel scanner. Single source enumerated dozens of canonical ba ...
show moreAutomated webshell/backdoor and admin-panel scanner. Single source enumerated dozens of canonical backdoor/shell filenames (e.g. alfa-rex.php, adminfuns.php, 222.php, bypass.php, lock360.php, goat1.php) and admin/upload paths in two bursts. These names only exist on already-compromised servers - each hit is a bot checking for a pre-existing backdoor. All requests returned 404/403 (one 200 on a directory index); nothing present, no compromise. Activity: 2026-08-12 20:40:05-20:40:18 and 22:39:56-22:40:09 CEST (UTC+2).
show less
Automated web-application vulnerability scan against a Joomla com_content article. Single source fuz ...
show moreAutomated web-application vulnerability scan against a Joomla com_content article. Single source fuzzed every query parameter (option, view, id, catid, Itemid) of a real article URL with injection payloads: SQL-injection quote/array probes (e.g. option=com_content'[0]), cross-site scripting via <script>alert(String.fromCharCode(88,83,83))</script>, and local file inclusion (option=/etc/passwd). 27 requests in a ~6-second burst. XSS blocked (HTTP 403), LFI blocked (HTTP 444); SQLi quote probes returned the normal article (200/301) with no SQL error or data disclosure. Activity: 2026-08-06 03:40:51-03:40:57 CEST (UTC+2).
show less
Automated SQL injection attack (sqlmap) against a Joomla com_content site. Single source sent 226 re ...
show moreAutomated SQL injection attack (sqlmap) against a Joomla com_content site. Single source sent 226 requests in ~2 seconds via the 'option' parameter on / , using UNION-based payloads with classic sqlmap signatures: string-context injection (option=lfiirqvr' UNION ALL SELECT ...), incremental NULL columns, CONCAT(0x7e...0x7e) hex delimiters and --+- comment terminators, plus random _= cache-buster params. 220 of 226 requests blocked with HTTP 403 by WAF; no data disclosed. Same UA and technique as attacks from 138.68.137.164 minutes earlier - appears to be a coordinated multi-IP campaign from DigitalOcean against Joomla properties. Activity: 2026-07-13 19:32:40-41 CEST (UTC+2).
show less
Automated SQL injection attack (sqlmap) against Joomla com_content. Single source sent 225 requests ...
show moreAutomated SQL injection attack (sqlmap) against Joomla com_content. Single source sent 225 requests over ~6.5h enumerating UNION-based SQLi payloads across two endpoints: /component/content/article/... via the catid parameter, and /2022/index.php (com_content) via the option/id/Itemid parameters. Payloads carried classic sqlmap signatures: UNION ALL SELECT with incremental NULL columns, CONCAT(0x7e...0x7e) hex delimiters, and --+- comment terminators, plus random _= cache-buster params. Example: catid=-9625791 UNION ALL SELECT ...CONCAT(0x7e...,0x7e) --+- . 213 of 225 requests blocked with HTTP 403 by WAF; no data disclosed. Activity: 2026-07-13 19:22 to 2026-07-14 01:49 CEST (UTC+2).
show less
Automated PHP remote code execution attempt (ThinkPHP-style ?s= code injection). Source injected PHP ...
show moreAutomated PHP remote code execution attempt (ThinkPHP-style ?s= code injection). Source injected PHP via the query string to write a webshell dropper, e.g. GET /?p=/&s=<?=file_put_contents('runtime/archive/china6.php', base64_decode('...'))?> . The decoded payload writes a Gif89-masqueraded PHP dropper that fetches http://8.163.30.85/php/china.txt and includes it (referenced second-stage malware/C2 host: 8.163.30.85). Followed by GET /runtime/archive/china6.php to trigger the shell. Activity: 2026-07-12 13:08:55-13:10:11 CEST (UTC+2). All injection attempts returned 403; dropped file not present (302). Attempt failed.
show less
Automated WordPress reconnaissance / vulnerability scan. Single source enumerated wp-includes/wlwman ...
show moreAutomated WordPress reconnaissance / vulnerability scan. Single source enumerated wp-includes/wlwmanifest.xml across ~15 candidate subdirectories (/blog/, /web/, /wordpress/, /website/, /wp/, /news/, /2020/, /2019/, /shop/, /wp1/, /test/, /wp2/, /site/, /cms/, /sito/) within ~5 seconds, using leading double-slash paths (e.g. GET //blog/wp-includes/wlwmanifest.xml). Classic mass WordPress-discovery bot. Activity: 2026-07-08 06:28:18-06:28:23 CEST (UTC+2). All responses 404 - no WordPress present at probed paths.
show less
Automated WordPress reconnaissance / vulnerability scan. Single source enumerated wp-includes/wlwman ...
show moreAutomated WordPress reconnaissance / vulnerability scan. Single source enumerated wp-includes/wlwmanifest.xml across ~16 candidate subdirectories (/blog/, /web/, /wordpress/, /website/, /wp/, /news/, /2018/, /2019/, /shop/, /wp1/, /test/, /media/, /wp2/, /site/, /cms/, /sito/) within ~2 seconds, using leading double-slash paths (e.g. GET //blog/wp-includes/wlwmanifest.xml). Classic mass WordPress-discovery bot. Activity: 2026-07-06 02:46:41-02:46:43 CEST (UTC+2). All responses 404 - no WordPress present at probed paths.
show less
Automated Joomla Helix3 RCE / webshell attempt via python-requests/2.34.2. Sequence per pass: GET /t ...
show moreAutomated Joomla Helix3 RCE / webshell attempt via python-requests/2.34.2. Sequence per pass: GET /templates/shaper_helix3/templateDetails.xml (version fingerprint), POST /index.php?option=com_ajax&plugin=helix3&format=json, then GET for a randomly-named file such as /images/nuja5j.php.json?c=id across /, /images/, /cache/, /media/, /templates/shaper_helix3/ and .../layouts/. The c=id parameter attempts to execute the Unix 'id' command via a dropped shell. Random 6-char names rotated each pass (nuja5j, 3suhpl, fveoxu, s7js6h). Two bursts: 2026-07-06 15:06 and 18:59 CEST (UTC+2). All responses 302/403 - attempt failed.
show less
Automated Joomla Helix3 template exploitation / webshell probe. Repeated POST to /index.php?option=c ...
show moreAutomated Joomla Helix3 template exploitation / webshell probe. Repeated POST to /index.php?option=com_ajax&plugin=helix3&format=json followed by GET requests for 'cox.json' across multiple directories (/, /images/, /media/, /tmp/, /templates/) checking for a dropped webshell. User-Agent rotated per request (iPhone/Firefox/Chrome/Edge/Linux) from one source IP within ~20 seconds. Activity: 2026-07-08 02:55:49 to 02:56:12 CEST (UTC+2). All responses 301/302/403 - attempt failed.
show less
Bad Web BotWeb App AttackHacking
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.