Automated probing for network camera or embedded-device management endpoints.
The source requested ...
show moreAutomated probing for network camera or embedded-device management endpoints.
The source requested /SDK/webLanguage against an unrelated public web application, consistent with opportunistic Internet-wide scanning.
show less
Automated web vulnerability scanning targeting Microsoft Exchange/Autodiscover.
The source request ...
show moreAutomated web vulnerability scanning targeting Microsoft Exchange/Autodiscover.
The source requested /autodiscover/autodiscover.json?@zdi/Powershell against a non-Exchange public web application.
show less
Automated probing for exposed environment files. The source repeatedly requested /.env against a pub ...
show moreAutomated probing for exposed environment files. The source repeatedly requested /.env against a public web application using the user agent VULN-Audit/1.0. This activity is consistent with credential and configuration-file discovery. The requests were redirected or blocked, and no sensitive file was exposed.
show less
Automated command-injection attempt targeting /shell. The request attempted to delete files in /tmp, ...
show moreAutomated command-injection attempt targeting /shell. The request attempted to delete files in /tmp, download a Mozi malware binary with wget, make it executable, and run it.
show less
Automated command-injection attempt targeting /shell. The request attempted to delete files in /tmp, ...
show moreAutomated command-injection attempt targeting /shell. The request attempted to delete files in /tmp, download a Mozi malware binary with wget, make it executable, and run it.
show less
Automated multi-vector web exploitation activity. The source attempted Apache Struts/XWork OGNL remo ...
show moreAutomated multi-vector web exploitation activity. The source attempted Apache Struts/XWork OGNL remote code execution, Log4Shell/JNDI LDAP injection, GeoServer command execution, FortiSandbox command injection, and remote shell-script download/execution using wget, busybox wget, curl, and sh. Requests were blocked by NGINX security rules.
The payload attempted to download shell scripts from 45.153.34.153.
show less
Automated malicious web scanner probing multiple PHP files and sensitive configuration paths, includ ...
show moreAutomated malicious web scanner probing multiple PHP files and sensitive configuration paths, including /config-backup.php, /sql.php, /php.ini, /settings.php, and /bootstrap.php. All requests were blocked with HTTP 403.
show less
Automated web vulnerability scanning against a public web application.
The source repeatedly probed ...
show moreAutomated web vulnerability scanning against a public web application.
The source repeatedly probed PHP and PHPUnit exploit paths, including:
GET /index.php
GET /panel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
User-Agent: libredtail-http
show less
Bad Web BotWeb App Attack
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.