๐ท๐ด
Fn4ticHz
2026-05-09 14:01:24
(4 weeks ago)
Repeated DDoS targeted -- ZeroGuard X ManagedSRV
DDoS Attack
Exploited Host
๐ฎ๐น
VHosting
2026-04-26 08:43:11
(1 month ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
๐ฉ๐ช
NoaQT
2026-04-05 22:10:13
(2 months ago)
103.176.96.138 - - [05/Apr/2026:17:37:39 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.bing.co ...
show more
103.176.96.138 - - [05/Apr/2026:17:37:39 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.bing.com/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.176.96.138 - - [05/Apr/2026:17:37:53 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.instagram.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.176.96.138 - - [05/Apr/2026:17:38:17 +0200] "GET /web/login HTTP/1.1" 499 0 "https://app.site-top.biz/news" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.176.96.138 - - [05/Apr/2026:17:40:49 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.twitter.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.176.96.138 - - [05/Apr/2026:17:41:03 +0200] "GET /web/login HTTP/1.1" 499 0 "https://shop.cloud-future.biz
...
show less
DDoS Attack
๐ฉ๐ช
NoaQT
2026-04-05 15:41:04
(2 months ago)
103.176.96.138 - - [05/Apr/2026:17:37:39 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.bing.co ...
show more
103.176.96.138 - - [05/Apr/2026:17:37:39 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.bing.com/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.176.96.138 - - [05/Apr/2026:17:37:53 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.instagram.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.176.96.138 - - [05/Apr/2026:17:38:17 +0200] "GET /web/login HTTP/1.1" 499 0 "https://app.site-top.biz/news" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.176.96.138 - - [05/Apr/2026:17:37:53 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.instagram.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.176.96.138 - - [05/Apr/2026:17:38:17 +0200] "GET /web/login HTTP/1.1" 499 0 "https://app.site-top.
...
show less
DDoS Attack
๐บ๐ธ
COMPLEX
2026-03-06 17:05:07
(3 months ago)
Triggered Cloudflare WAF (l7ddos) from ID.
Action taken: MANAGED_CHALLENGE
ASN: undefined (undefined ...
show more
Triggered Cloudflare WAF (l7ddos) from ID.
Action taken: MANAGED_CHALLENGE
ASN: undefined (undefined)
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:146.0) Gecko/20100101 Firefox/146.0
show less
DDoS Attack
Bad Web Bot
๐ณ๐ฑ
ConsulHosting
2026-02-15 16:01:26
(3 months ago)
Part of an HTTP Flood DDoS attack and had sent at least 316 requests.
DDoS Attack
Exploited Host
๐ฎ๐ณ
Bharat Datacenter
2026-01-11 21:08:11
(4 months ago)
1: date=2026-01-12 time=02:37:04 eventtime=1768165624792320469 tz="+0530" logid="0720018432" type="u ...
show more
1: date=2026-01-12 time=02:37:04 eventtime=1768165624792320469 tz="+0530" logid="0720018432" type="utm" subtype="anomaly" eventtype="anomaly" level="alert" vd="root" severity="critical" srcip=103.176.96.138 srccountry="Indonesia" dstip=157.10.99.34 dstcountry="India" srcintf="x2" srcintfrole="wan" sessionid=0 action="clear_session" proto=6 service="HTTPS" count=148467 attack="tcp_syn_flood" srcport=60328 dstport=443 attackid=100663396 policyid=1 policytype="DoS-policy" ref="http://www.fortinet.com/ids/VID100663396" msg="anomaly: tcp_syn_flood, 4149 > threshold 2000, repeats 148467 times since last log, pps 4190 of prior second" crscore=50 craction=4096 crlevel="critical"
show less
Brute-Force
๐บ๐ธ
COMPLEX
2025-12-17 01:31:48
(5 months ago)
Triggered Cloudflare WAF (l7ddos) from ID.
Action taken: BLOCK
ASN: 147131 (IDNIC-GFIBER-AS-ID PT Gl ...
show more
Triggered Cloudflare WAF (l7ddos) from ID.
Action taken: BLOCK
ASN: 147131 (IDNIC-GFIBER-AS-ID PT Global Sarana Elektronika)
Protocol: HTTP/2 (GET method)
Endpoint: /
show less
DDoS Attack
Bad Web Bot
๐จ๐ญ
Modules
2025-12-14 04:04:38
(5 months ago)
Open proxy http://103.176.96.138:8082 (RT:8130ms,Loc:Indonesia,ASN:AS147131)
Open Proxy
๐ต๐น
PTnet
2025-12-07 06:20:15
(6 months ago)
DDoS Attack (jail:haproxy-https-flood)
DDoS Attack
Exploited Host
๐ต๐น
PTnet
2025-12-06 11:57:43
(6 months ago)
DDoS Attack (jail:haproxy-https-flood)
DDoS Attack
Exploited Host
๐ต๐น
PTnet
2025-12-04 19:46:03
(6 months ago)
DDoS Attack (jail:haproxy-https-flood)
DDoS Attack
Exploited Host
Anonymous
2025-12-04 07:20:11
(6 months ago)
botnet
DDoS Attack
๐บ๐ธ
1gz
2025-12-01 21:56:00
(6 months ago)
Triggered Cloudflare WAF (ratelimit) from ID.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endp ...
show more
Triggered Cloudflare WAF (ratelimit) from ID.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Opera/9.80 (Windows NT 6.1; Opera Tablet/15165; U; en) Presto/2.8.149 Version/11.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฎ๐ณ
Mcshield.org
2025-12-01 06:31:49
(6 months ago)
Connection closed by 103.176.96.138 [preauth] or weird packet
Brute-Force
SSH