WordPress attack. On 2026-07-21 ~07:04 UTC POSTed to an uploaded webshell (filefuns.php) and to inje ...
show moreWordPress attack. On 2026-07-21 ~07:04 UTC POSTed to an uploaded webshell (filefuns.php) and to injected SEO-spam doorway loaders. Web App Attack / webshell operation.
show less
WordPress attack. On 2026-07-21 operated an uploaded PHP webshell / file manager (GET+POST /wp-conte ...
show moreWordPress attack. On 2026-07-21 operated an uploaded PHP webshell / file manager (GET+POST /wp-content/plugins/<random>/src/ui/index.php and filefuns.php) and deployed SEO-spam doorway malware that cloaks Japanese spam to Googlebot. Web App Attack / webshell.
show less
WordPress attack. On 2026-07-20 ~20:41 UTC logged in via an attacker-created rogue admin (POST /wp-l ...
show moreWordPress attack. On 2026-07-20 ~20:41 UTC logged in via an attacker-created rogue admin (POST /wp-login.php -> 302), then at ~20:44 UTC uploaded a malicious plugin webshell (POST /wp-admin/update.php?action=upload-plugin). Web App Attack / malware upload.
show less
Unauthorized WordPress compromise. On 2026-07-20 ~03:19 UTC this IP sent POST /?rest_route=/batch/v1 ...
show moreUnauthorized WordPress compromise. On 2026-07-20 ~03:19 UTC this IP sent POST /?rest_route=/batch/v1 (HTTP 207) exploiting the WordPress REST API to create a rogue administrator account without authentication (automated, rotating User-Agents). Web App Attack / privilege escalation.
show less
026-07-30 09:01:49-09:01:52 UTC. Automated attack (python-requests
user-agent) against an exposed p ...
show more026-07-30 09:01:49-09:01:52 UTC. Automated attack (python-requests
user-agent) against an exposed pgAdmin instance, from first request to
running cryptominer in ~3 seconds.
Sequence observed in application logs:
POST /browser/master_password 200
POST /browser/server/obj/1/ 200 (created server object)
POST /import_export/job/2 200 (RCE vector, CVE-2024-3116
class: runs a binary as a
background job)
DELETE /browser/server/obj/1/2 200 (removed its own trace)
The import/export job was used to download and execute an XMR
cryptominer; binary creation timestamp matches the request timestamps.
The source deleted the server object it created, indicating deliberate
cleanup rather than a simple vulnerability scan.
Opportunistic mass scanning, not targeted. Observed directly in logs on
infrastructure we operate.
show less
HackingWeb App Attack
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.