๐ฉ๐ช
NoaQT
2026-04-05 22:04:45
(2 months ago)
103.191.254.134 - - [05/Apr/2026:16:31:43 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.pinter ...
show more
103.191.254.134 - - [05/Apr/2026:16:31:43 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.pinterest.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.191.254.134 - - [05/Apr/2026:16:37:02 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.facebook.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.191.254.134 - - [05/Apr/2026:16:44:28 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.facebook.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.191.254.134 - - [05/Apr/2026:16:59:31 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.whatsapp.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.191.254.134 - - [05/Apr/2026:17:00:28 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.w
...
show less
DDoS Attack
๐ฉ๐ช
NoaQT
2026-04-05 15:43:01
(2 months ago)
103.191.254.134 - - [05/Apr/2026:17:37:53 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.secure ...
show more
103.191.254.134 - - [05/Apr/2026:17:37:53 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.secure.co/home" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.191.254.134 - - [05/Apr/2026:17:39:11 +0200] "GET /web/login HTTP/1.1" 499 0 "https://shop.linkmedia.org/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.191.254.134 - - [05/Apr/2026:17:39:11 +0200] "GET /web/login HTTP/1.1" 499 0 "https://shop.linkmedia.org/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.191.254.134 - - [05/Apr/2026:17:41:16 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.instagram.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
103.191.254.134 - - [05/Apr/2026:17:41:16 +0200] "GET /web/login HTTP/1.1" 499 0 "https://www.
...
show less
DDoS Attack
๐บ๐ธ
quilla
2026-04-03 03:20:35
(2 months ago)
Botnet infected device observed in honeypot (Vector: TCP)
DDoS Attack
Anonymous
2026-03-02 21:20:03
(3 months ago)
| [Dangerous/Indonesia] Agressive IP 103.191.254.134 (~30 hits). Type: DoS Defender- Web server 400 ...
show more
| [Dangerous/Indonesia] Agressive IP 103.191.254.134 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐ฎ๐น
VHosting
2026-02-24 10:34:17
(4 months ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
๐ฎ๐ณ
liveaspankaj
2026-02-20 23:31:16
(4 months ago)
DDoS attack: 84 requests in 5m (GET / or repair.php).
DDoS Attack
๐ง๐ช
cmbplf
2026-02-20 07:40:52
(4 months ago)
734 limiting connections by zone (22h10m59s)
DDoS Attack
Anonymous
2026-02-09 02:04:41
(4 months ago)
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show more
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in thread-skip.asp
show less
Bad Web Bot
Exploited Host
๐จ๐ญ
Modules
2026-01-16 05:39:09
(5 months ago)
Open proxy http://103.191.254.134:8080 (RT:15463ms,Loc:Indonesia,ASN:AS149943)
Open Proxy
๐ญ๐บ
ksol-hostmaster
2025-10-19 17:28:23
(8 months ago)
Massive botnet baited into scraping tarpit
Bad Web Bot
๐ฉ๐ช
1gz
2025-08-31 15:03:22
(9 months ago)
Triggered Cloudflare WAF (ratelimit) from ID.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (ratelimit) from ID.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET method)
Endpoint: /auth/login
UA: HetrixTools Uptime Monitoring Bot. https://hetrix.tools/uptime-monitoring-bot.html
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
shabi
2025-08-28 09:26:20
(9 months ago)
IP: 103.191.254.134 [Country: ID] triggered WAF (l7ddos).
Action: managed_challenge
ASN: 149943 (IDN ...
show more
IP: 103.191.254.134 [Country: ID] triggered WAF (l7ddos).
Action: managed_challenge
ASN: 149943 (IDNIC-ADINET-AS-ID PT Ayodya Data Internusa)
Protocol: HTTP/2 (method GET)
Endpoint: /cc.gif
Time: 2025-08-28T09:22:58Z
User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36
---
Report generated by CFWAF2AbuseIPDB.
show less
DDoS Attack
Web Spam
Web App Attack
๐ฉ๐ช
1gz
2025-08-27 22:38:48
(9 months ago)
Triggered Cloudflare WAF (firewallCustom) from ID.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/2 ...
show more
Triggered Cloudflare WAF (firewallCustom) from ID.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; U; PPC Mac OS X; pl-PL; rv:1.0.1) Gecko/20021111 Chimera/0.6
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
CommanderRoot
2025-08-26 19:01:46
(9 months ago)
HTTP request flood
DDoS Attack
Web Spam
๐ฉ๐ช
Packets-Decreaser.NET
2025-08-13 18:16:38
(10 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam