Aggressive automated scanning for exposed credentials/backups: /.env, /wp-config.php.old across site ...
show moreAggressive automated scanning for exposed credentials/backups: /.env, /wp-config.php.old across sites on our hosting.
show less
Aggressive automated scanning for exposed source control / info-leak: /.git/config, /xampp/phpinfo.p ...
show moreAggressive automated scanning for exposed source control / info-leak: /.git/config, /xampp/phpinfo.php across sites on our hosting.
show less
Aggressive automated scanning (l9explore/LeakIX) for exposed secrets: mass GET probing /.env and cre ...
show moreAggressive automated scanning (l9explore/LeakIX) for exposed secrets: mass GET probing /.env and credential files across our hosting.
show less
Aggressive automated scanning for exposed source control: ~25000 GET probing /.git/config and git tr ...
show moreAggressive automated scanning for exposed source control: ~25000 GET probing /.git/config and git tree paths across sites on our hosting.
show less
WordPress 'wp2shell' core-RCE exploitation. ~300 POST /index.php?rest_route=/batch/v1 (HTTP 207) com ...
show moreWordPress 'wp2shell' core-RCE exploitation. ~300 POST /index.php?rest_route=/batch/v1 (HTTP 207) combined with ~340 wp-login.php brute-force requests.
show less
WordPress attack. ~95 POST /?rest_route=/batch/v1 ('wp2shell' core RCE) plus WP recon (/wp-includes/ ...
show moreWordPress attack. ~95 POST /?rest_route=/batch/v1 ('wp2shell' core RCE) plus WP recon (/wp-includes/version.php, /wp-json/), using a spoofed 'authorized self-check auditor' User-Agent (NOT authorized by us).
show less
Automated WordPress attack. ~525 POST /index.php?rest_route=/batch/v1 ('wp2shell' core RCE) with log ...
show moreAutomated WordPress attack. ~525 POST /index.php?rest_route=/batch/v1 ('wp2shell' core RCE) with login probing (/api/v1/login) and malformed TLS/port-scan traffic.
show less
WordPress 'wp2shell' core-RCE exploitation. ~50 POST batch-endpoint (HTTP 207) plus wp-login.php pro ...
show moreWordPress 'wp2shell' core-RCE exploitation. ~50 POST batch-endpoint (HTTP 207) plus wp-login.php probing.
show less
Automated WordPress 'wp2shell' core-RCE exploitation. ~80 POST to /?rest_route=/batch/v1 & /wp-json/ ...
show moreAutomated WordPress 'wp2shell' core-RCE exploitation. ~80 POST to /?rest_route=/batch/v1 & /wp-json/batch/v1 (HTTP 207).
show less
WordPress 'wp2shell' core-RCE exploitation. ~100 POST /index.php?rest_route=/batch/v1 (HTTP 207) plu ...
show moreWordPress 'wp2shell' core-RCE exploitation. ~100 POST /index.php?rest_route=/batch/v1 (HTTP 207) plus wp-login.php probing, 2026-07-30..31.
show less
Automated WordPress 'wp2shell' core-RCE exploitation. ~110 POST to /?rest_route=/batch/v1 & /wp-json ...
show moreAutomated WordPress 'wp2shell' core-RCE exploitation. ~110 POST to /?rest_route=/batch/v1 & /wp-json/batch/v1 (HTTP 207) using a spoofed 'vuln_scanner' User-Agent (not authorized).
show less
Automated WordPress 'wp2shell' core-RCE exploitation. ~170 POST to batch endpoint variants (HTTP 207 ...
show moreAutomated WordPress 'wp2shell' core-RCE exploitation. ~170 POST to batch endpoint variants (HTTP 207), 2026-07-27..31.
show less
WordPress 'wp2shell' core-RCE exploitation (User-Agent 'wp2shell', POST /?rest_route=/batch/v1) plus ...
show moreWordPress 'wp2shell' core-RCE exploitation (User-Agent 'wp2shell', POST /?rest_route=/batch/v1) plus wp-login.php login probing.
show less
Automated WordPress 'wp2shell' core-RCE exploitation. ~55 POST /?rest_route=/batch/v1 (HTTP 207), Us ...
show moreAutomated WordPress 'wp2shell' core-RCE exploitation. ~55 POST /?rest_route=/batch/v1 (HTTP 207), User-Agent 'wp2shell'.
show less
Automated WordPress 'wp2shell' core-RCE exploitation. ~95 POST /?rest_route=/batch/v1 (HTTP 207), Us ...
show moreAutomated WordPress 'wp2shell' core-RCE exploitation. ~95 POST /?rest_route=/batch/v1 (HTTP 207), User-Agent 'wp2shell'.
show less
Automated WordPress 'wp2shell' core-RCE exploitation. ~120 POST /?rest_route=/batch/v1 (HTTP 207), U ...
show moreAutomated WordPress 'wp2shell' core-RCE exploitation. ~120 POST /?rest_route=/batch/v1 (HTTP 207), User-Agent 'wp2shell'.
show less
Automated WordPress 'wp2shell' core-RCE exploitation. ~930 POST /?rest_route=/batch/v1 & /wp-json/ba ...
show moreAutomated WordPress 'wp2shell' core-RCE exploitation. ~930 POST /?rest_route=/batch/v1 & /wp-json/batch/v1, 2026-07-28..29.
show less
Automated WordPress 'wp2shell' core-RCE exploitation. ~600 POST batch-endpoint with path/case-evasio ...
show moreAutomated WordPress 'wp2shell' core-RCE exploitation. ~600 POST batch-endpoint with path/case-evasion (/wp-json/Batch/v1, /wp-json//batch/v1).
show less
Automated WordPress 'wp2shell' core-RCE exploitation. ~430 POST to the batch endpoint (HTTP 207), Us ...
show moreAutomated WordPress 'wp2shell' core-RCE exploitation. ~430 POST to the batch endpoint (HTTP 207), User-Agent 'wp2shell', 2026-07-27..08-04.
show less
Automated WordPress 'wp2shell' core-RCE exploitation (CVE-2026-63030/CVE-2026-60137). Bursts of POST ...
show moreAutomated WordPress 'wp2shell' core-RCE exploitation (CVE-2026-63030/CVE-2026-60137). Bursts of POST /?rest_route=/batch/v1 & /wp-json/batch/v1 (HTTP 207) vs ~10 sites, User-Agent 'wp2shell'.
show less
WordPress XML-RPC credential brute-force. On 2026-07-20 ~13:57 UTC flooded POST /xmlrpc.php with hun ...
show moreWordPress XML-RPC credential brute-force. On 2026-07-20 ~13:57 UTC flooded POST /xmlrpc.php with hundreds of requests (system.multicall password guessing), Apache-HttpClient/Java UA. Brute-Force / Web App Attack. (Blocked by server, HTTP 503.)
show less
WordPress attack. On 2026-07-20 ~03:38 UTC scanned for backdoor/webshell filenames (adminfuns.php, i ...
show moreWordPress attack. On 2026-07-20 ~03:38 UTC scanned for backdoor/webshell filenames (adminfuns.php, inputs.php, /.well-known/logs233/index.php, edit.php, file.php etc.). Web App Attack / backdoor discovery.
show less
WordPress attack. On 2026-08-04 ~13:18 UTC probed and accessed uploaded PHP webshells (GET /wp-conte ...
show moreWordPress attack. On 2026-08-04 ~13:18 UTC probed and accessed uploaded PHP webshells (GET /wp-content/plugins/<random>/wp_filemanager.php, /1.php, /we.php, /ccc.php etc.). Web App Attack / webshell access.
show less
HackingWeb App Attack
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.