Threat LevelMEDIUM45/1004 rule types
4 incidents on record · 4 rule types · last seen 9d ago
| PTR | N/A |
| Org / ASN | China Mobile Communications Group Co., Ltd |
| Country | 🇨🇳 China |
| City | Guangzhou, Guangdong |
| Timezone | Asia/Shanghai |
Attack Analysis
Git Repository Exposure Probe
This IP requested the /.git/config file, attempting to access an accidentally exposed Git repository's configuration — often containing remote repository URLs, and sometimes credentials embedded in them. No legitimate client ever requests this path.
wp-config.php Backup File Probe
This IP requested a backup or editor-leftover copy of wp-config.php (e.g. wp-config.php.bak, wp-config.php~) — the file holding a WordPress site's database credentials and secret keys in plaintext. A successful hit hands an attacker full database access.
Backup & Database File Probe
This IP requested common backup file paths (.bak, .sql, .zip, wp-config.bak), hunting for database dumps or config files containing plaintext credentials. A single exposed wp-config.bak can hand an attacker full database access. This attack is automated and deliberate.
Reports (4)
| Date | Severity | Description |
|---|---|---|
| 21 Sep 2026 - 12:16 | high | Web: Backup/database file probe |
| 21 Sep 2026 - 12:16 | medium | Query Guard — Path Wpconfig Backup |
| 20 Sep 2026 - 10:05 | high | Web: Git repo exposure probe |
| 20 Sep 2026 - 10:05 | medium | Query Guard — Path Git Config Exposed |
EagleEye Intelligence