PHP/ASP/JSP Source Backup File Grab for 2026-08-02

Last Updated: 00:00 UTC

Probing for backup copies of web application source files (.php.bak, .php.old, .php.txt, .php.orig, .php.swp). These files are frequently created by editors or deployment scripts and left accessible, exposing database credentials and application logic.

MITRE ATT&CK

Tactic: Credential Access (TA0006)
Technique: T1552.001 — Credentials in Files

Observed URIs

Attackers by Country

United States of America: 5United Kingdom of Great Britain and Northern Ireland: 1Canada: 1Germany: 1Indonesia: 1Korea, Republic of: 1Brazil: 1Singapore: 1Romania: 1
United States of America538.5%
United Kingdom of Great Britain and Northern Ireland17.7%
Canada17.7%
Germany17.7%
Indonesia17.7%
Korea, Republic of17.7%
Brazil17.7%
Singapore17.7%
Romania17.7%

IP Address : ASN : City/Provider

Share on: