π©πͺ
Skyrider
2026-06-27 13:45:38
(2 days ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
πΊπΈ
Hmorrin
2026-06-25 03:15:52
(4 days ago)
Port Scan
Anonymous
2026-06-17 02:15:26
(1 week ago)
Large-scale coordinated botnet (200+k IPs). Attacker: mikhail-smirnov-79830323 (LinkedIn/profile ID) ...
show more
Large-scale coordinated botnet (200+k IPs). Attacker: mikhail-smirnov-79830323 (LinkedIn/profile ID) employed by Angara Technologies Group (Explicitly identified himself as enemy a week before attack began) | Attack Signature Blocked: /brands/aruba-networks/shopby/manufacturer-grandstream-extron-lsi-aruba_networks-haivision-xyz.html?mode=grid | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 | (Magento Site)
show less
Hacking
Bad Web Bot
π¨π¦
1gz
2026-06-12 08:18:46
(2 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /maqedoni/dalin-detajet-ku-do-te-varroset-ivanovic/365430/
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π«π·
Sklurk
2026-05-29 00:00:39
(1 month ago)
Web App Attack
Web App Attack
πΊπΈ
stechusa
2026-05-25 10:02:52
(1 month ago)
[Askari] | country=SG | Behavior: Concurrent page load during attack, HTTP/1.1 over TLS, Targeting s ...
show more
[Askari] | country=SG | Behavior: Concurrent page load during attack, HTTP/1.1 over TLS, Targeting specific pages, Outdated browser, URL template abuse
show less
Bad Web Bot
DDoS Attack
πΊπΈ
stechusa
2026-05-25 10:02:52
(1 month ago)
ELEVATED_THREAT | country=SG | ASN=Byteplus Pte. Ltd. | AbuseIPDB=50% | 54 IPs targeting /brand.html ...
show more
ELEVATED_THREAT | country=SG | ASN=Byteplus Pte. Ltd. | AbuseIPDB=50% | 54 IPs targeting /brand.html | Facet request during elevated threat (facet_ratio=0.80, unique_ips=144) | URL template shared by 30 IPs: /brand.html?bulb_shape_type=*&bulb_shape=*&bulb_type=*&mode=list&p=*
show less
Bad Web Bot
DDoS Attack
π¨π¦
polycoda
2026-05-24 13:21:44
(1 month ago)
π₯Ά Part of massive botnet scraping campaign that nearly turned into a DDoS on 2025-11-27
DDoS Attack
π«π·
Sklurk
2026-05-21 06:24:33
(1 month ago)
Web App Attack
Web App Attack
π¨π¦
1gz
2026-05-19 09:27:07
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /lifestyle/nga-macja-e-zeze-te-pasqyra-e-thyer-bestytnite-qe-trembin-shqiptaret/410491/kerko.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π«π·
bigorre.org
2026-05-08 16:24:14
(1 month ago)
Unidentified crawling: not a self-announced bot in user-agent
Bad Web Bot
π©πͺ
pltcldvlpr
2026-05-07 12:31:17
(1 month ago)
Unidentified crawler ignoring robots.txt: 101.47.26.242 - - [07/May/2026:14:31:14 +0200] "GET /proto ...
show more
Unidentified crawler ignoring robots.txt: 101.47.26.242 - - [07/May/2026:14:31:14 +0200] "GET /protocol?id=sn_4_135¶graph=2312096&seq=428 HTTP/1.1" 302 5 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" asn=150436 org="Byteplus Pte. Ltd."
101.47.26.242 - - [07/May/2026:14:31:16 +0200] "GET /protocol?id=sn_4_135&offset=400&seq=428 HTTP/1.1" 200 345660 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" asn=150436 org="Byteplus Pte. Ltd."
...
show less
Bad Web Bot
π¨π¦
1gz
2026-05-04 12:40:00
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /kosove/serbia-bllokon-pagesen-ndaj-viktimave-boshnjake-te-torturuara/184807/kerko.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π«π·
Sklurk
2026-05-04 00:04:52
(1 month ago)
Web App Attack
Web App Attack
π«π·
Sklurk
2026-05-02 04:54:50
(1 month ago)
Web App Attack
Web App Attack