Web attack probing for WordPress: 4 requests in 1 seconds, 2 blocked. Matching requests, 2026-09-29 ...
show moreWeb attack probing for WordPress: 4 requests in 1 seconds, 2 blocked. Matching requests, 2026-09-29 UTC: 21:42:13 GET /wp-json/wp/v2/posts?per_page=1; 21:42:14 GET /feed/. User-Agent: "Mozilla/5.0 (compatible; WordPressPostChecker/1.0)".
show less
Web attack probing for secret and configuration files, path traversal, WordPress, admin and login pa ...
show moreWeb attack probing for secret and configuration files, path traversal, WordPress, admin and login pages, PHP scripts, remote code execution: 258 requests in 9 seconds, 239 blocked. Matching requests, 2026-09-29 UTC: 07:00:39 GET /config/.env.php; 07:00:39 GET /@fs/.env?raw&url??; 07:00:39 GET /.env.swp; 07:00:39 GET /.env.dev; 07:00:39 GET /var/run/secrets/kubernetes.io/serviceaccount/token; 07:00:39 GET /userfiles?path=../../../.env; 07:00:39 GET /api/w/default/jobs_u/get_log_file/../../../../proc/self/environ; 07:00:39 GET /@fs/app/.env.production?import&raw??; and 171 more. User-Agent rotated between 33 values: "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"; "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) V"; "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"; and 30 more. The crawler names are claimed, not verified.
show less
Web attack probing for admin and login pages, secret and configuration files, PHP scripts, remote co ...
show moreWeb attack probing for admin and login pages, secret and configuration files, PHP scripts, remote code execution: 76 requests in 43 seconds, 45 blocked. Matching requests, 2026-09-28 UTC: 22:07:02 GET /actuator/threaddump; 22:07:02 GET /login; 22:07:03 GET /actuator/gateway/routes; 22:07:03 GET /actuator/beans; 22:07:04 GET /appsettings.json; 22:07:04 GET /appsettings.json; 22:07:04 GET /appsettings.Development.json; 22:07:05 GET /console; and 24 more. User-Agent: "CCBot/2.0 (https://commoncrawl.org/faq/)".
show less
Web attack probing for secret and configuration files, PHP scripts, WordPress: 29 requests in 1 seco ...
show moreWeb attack probing for secret and configuration files, PHP scripts, WordPress: 29 requests in 1 seconds, 12 blocked. Matching requests, 2026-09-28 UTC: 03:57:13 GET /.env; 03:57:13 GET /.config/gcloud/application_default_credentials.json; 03:57:13 GET /.env.bak; 03:57:13 GET /appsettings.json; 03:57:13 GET /auth.json; 03:57:13 GET /api/phpinfo.php; 03:57:13 GET /.git/config; 03:57:13 GET /backup/.env; and 17 more. User-Agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36".
show less
Web attack probing for secret and configuration files, WordPress, admin and login pages, PHP scripts ...
show moreWeb attack probing for secret and configuration files, WordPress, admin and login pages, PHP scripts, remote code execution: 42 requests in 44 seconds, 32 blocked. Matching requests, 2026-09-27 UTC: 18:09:10 GET /config.php.bak; 18:09:11 GET /wp-config.old; 18:09:11 GET /wp/.env; 18:09:11 GET /storage/.env; 18:09:12 GET /actuator/beans; 18:09:12 GET /actuator/mappings; 18:09:13 GET /appsettings.json; 18:09:14 GET /app/settings.py; and 12 more. User-Agent: "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected])".
show less
Web attack probing for admin and login pages, PHP scripts: 21 requests in 5 minutes, 19 blocked. Mat ...
show moreWeb attack probing for admin and login pages, PHP scripts: 21 requests in 5 minutes, 19 blocked. Matching requests, 2026-09-27 UTC: 11:32:39 GET /administrator/components/com_jce/; 11:37:16 POST /index.php?option=com_jce; 11:37:16 GET /tmp/jce_sficdi.xml.php; 11:37:17 POST /index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon; 11:37:17 GET /media/com_sppagebuilder/assets/iconfont/icovxrjrw/fonts/fxfequi.php5; 11:37:17 GET /media/com_sppagebuilder/assets/iconfont/icoewisyv/fonts/fjitmnk.php5; 11:37:17 POST /index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon; 11:37:17 POST /index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon; and 8 more. User-Agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0".
show less
Web attack probing for secret and configuration files, PHP scripts: 19 requests in 1 seconds, 9 bloc ...
show moreWeb attack probing for secret and configuration files, PHP scripts: 19 requests in 1 seconds, 9 blocked. Matching requests, 2026-09-26 UTC: 02:37:39 GET /.env; 02:37:40 GET /.env.staging; 02:37:40 GET /v1/.env; 02:37:40 GET /.env.local; 02:37:40 GET /web/.env; 02:37:40 GET /server/.env; 02:37:40 GET /phpinfo.php; 02:37:40 GET /secrets.yaml. User-Agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36".
show less
Web attack probing for WordPress, secret and configuration files, admin and login pages, PHP scripts ...
show moreWeb attack probing for WordPress, secret and configuration files, admin and login pages, PHP scripts, remote code execution, path traversal: 49 requests in 7 minutes, 38 blocked. Matching requests, 2026-09-25 UTC: 18:29:15 GET /wp-config.php.old; 18:29:16 GET /.env.swp; 18:29:16 GET /config.php.bak; 18:29:18 GET /actuator/loggers; 18:29:19 GET /.streamlit/secrets.toml; 18:29:20 GET /dev/.env; 18:29:26 POST /dashboard; 18:29:28 POST /icecoder/lib/terminal-xhr.php; and 15 more. User-Agent: "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)".
show less
Web attack probing for WordPress: 4 requests in 2 seconds, all blocked (HTTP 403). Matching requests ...
show moreWeb attack probing for WordPress: 4 requests in 2 seconds, all blocked (HTTP 403). Matching requests, 2026-09-24 UTC: 02:12:01 GET /wp-json/; 02:12:02 GET /wp-login.php; 02:12:03 GET /xmlrpc.php. User-Agent: "CMS-Security-Auditor/1.0 (+authorized self-check; contact: local-admin)".
show less
Bad Web BotWeb App Attack
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.