๐ฉ๐ช
NoaQT
2026-04-05 22:02:17
(2 months ago)
103.169.149.5 - - [05/Apr/2026:16:32:34 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.yahoo.co ...
show more
103.169.149.5 - - [05/Apr/2026:16:32:34 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.yahoo.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.169.149.5 - - [05/Apr/2026:16:33:00 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.GVFLRcS.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.169.149.5 - - [05/Apr/2026:16:33:49 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.whatsapp.com/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.169.149.5 - - [05/Apr/2026:16:33:00 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.GVFLRcS.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
...
show less
DDoS Attack
๐ฉ๐ช
NoaQT
2026-04-05 14:38:05
(2 months ago)
103.169.149.5 - - [05/Apr/2026:16:32:34 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.yahoo.co ...
show more
103.169.149.5 - - [05/Apr/2026:16:32:34 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.yahoo.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.169.149.5 - - [05/Apr/2026:16:33:00 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.GVFLRcS.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.169.149.5 - - [05/Apr/2026:16:33:49 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.whatsapp.com/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.169.149.5 - - [05/Apr/2026:16:33:00 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.GVFLRcS.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.169.149.5 - - [05/Apr/2026:16:33:49 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.whatsapp.com/" "Mozilla/5.0
...
show less
DDoS Attack
๐บ๐ธ
COMPLEX
2026-01-26 01:07:20
(4 months ago)
Triggered Cloudflare WAF (l7ddos) from ID.
Action taken: BLOCK
ASN: undefined (undefined)
Protocol: ...
show more
Triggered Cloudflare WAF (l7ddos) from ID.
Action taken: BLOCK
ASN: undefined (undefined)
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:146.0) Gecko/20100101 Firefox/146.0
show less
DDoS Attack
Bad Web Bot
๐ช๐ธ
cuscusero (FlexBacks, FlexChar, FlexAve, FlexCDNM, FlexTudy, ColdHosting SL)
2026-01-16 01:06:20
(4 months ago)
[CPD ESP-BCN02-FW11-394] Suspicious connection detected on port 21. DDoS detected
DDoS Attack
FTP Brute-Force
Brute-Force
๐ฎ๐น
VHosting
2025-12-30 13:28:20
(5 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
๐ฉ๐ช
Szymekk
2025-12-02 13:57:26
(6 months ago)
Fail2Ban: SSH brute force attempt [srv01]
Brute-Force
SSH
๐ฉ๐ช
Tizian Maxime Weigt
2025-11-25 08:18:56
(6 months ago)
Incoming DDoS to port 443 (L7 HTTPS Flood) Detected
DDoS Attack
๐บ๐ธ
skycodee
2025-10-05 12:49:07
(8 months ago)
Repeated TLS handshake abuse against Pterodactyl Wings (port 8080)
DDoS Attack
๐บ๐ธ
SuperEvilLuke
2025-10-01 21:37:21
(8 months ago)
Malicious activity detected from 142339 IDNIC-KANGENNET-AS-ID PT Kangen Network Solusindo towards ho ...
show more
Malicious activity detected from 142339 IDNIC-KANGENNET-AS-ID PT Kangen Network Solusindo towards host panel.embotic.xyz (GET HTTP/2) @ 2025-10-01T21:37:21Z (2 occurrences)
show less
DDoS Attack
Exploited Host
๐บ๐ธ
SuperEvilLuke
2025-09-29 20:34:56
(8 months ago)
Malicious activity detected from 142339 IDNIC-KANGENNET-AS-ID PT Kangen Network Solusindo towards ho ...
show more
Malicious activity detected from 142339 IDNIC-KANGENNET-AS-ID PT Kangen Network Solusindo towards host panel.embotic.xyz (GET HTTP/2) @ 2025-09-29T20:34:56Z (5 occurrences)
show less
DDoS Attack
Exploited Host
๐ฌ๐ง
Silly Development
2025-09-28 11:28:07
(8 months ago)
Malicious activity detected from 142339 IDNIC-KANGENNET-AS-ID PT Kangen Network Solusindo towards ho ...
show more
Malicious activity detected from 142339 IDNIC-KANGENNET-AS-ID PT Kangen Network Solusindo towards host paid.sillydev.co.uk (GET HTTP/2) @ 2025-09-28T11:28:07Z (6 occurrences)
show less
DDoS Attack
Exploited Host
๐ฌ๐ง
Silly Development
2025-09-28 10:54:49
(8 months ago)
Malicious activity detected from 142339 IDNIC-KANGENNET-AS-ID PT Kangen Network Solusindo towards ho ...
show more
Malicious activity detected from 142339 IDNIC-KANGENNET-AS-ID PT Kangen Network Solusindo towards host paid.sillydev.co.uk (GET HTTP/2) @ 2025-09-28T10:54:49Z (2 occurrences)
show less
DDoS Attack
Exploited Host
๐ฉ๐ช
1gz
2025-09-24 15:00:44
(8 months ago)
Triggered Cloudflare WAF (firewallCustom) from ID.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET met ...
show more
Triggered Cloudflare WAF (firewallCustom) from ID.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
Silly Development
2025-09-20 22:58:01
(8 months ago)
Malicious activity detected from 142339 IDNIC-KANGENNET-AS-ID PT Kangen Network Solusindo towards ho ...
show more
Malicious activity detected from 142339 IDNIC-KANGENNET-AS-ID PT Kangen Network Solusindo towards host panel.sillydev.co.uk (GET HTTP/2) @ 2025-09-20T22:58:01Z (32 occurrences)
show less
DDoS Attack
Exploited Host
๐ฉ๐ช
Packets-Decreaser.NET
2025-09-17 23:02:51
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam