๐ธ๐ฌ
Lian Nova Community
2025-11-09 00:15:00
(9 months ago)
Unusual activity, Open Proxy Detected.
Open Proxy
Web App Attack
๐ฆ๐บ
GreyWatch - Honeypot Intelligence
2025-11-08 15:14:22
(9 months ago)
ASN: 135463 (IDNIC-SUKOHARJOKAB-AS-ID PDE Setda Kabupaten Sukoharjo)
Botnet Zombie: This IP has been ...
show more
ASN: 135463 (IDNIC-SUKOHARJOKAB-AS-ID PDE Setda Kabupaten Sukoharjo)
Botnet Zombie: This IP has been detected as a botnet zombie | Outbound DDoS attack source | Malicious
show less
Bad Web Bot
Anonymous
2025-10-24 04:33:04
(10 months ago)
Forum/form spam
Web Spam
๐บ๐ธ
COMPLEX
2025-10-23 02:20:07
(10 months ago)
Triggered Cloudflare WAF (l7ddos) from ID.
Action taken: BLOCK
ASN: 135463 (IDNIC-SUKOHARJOKAB-AS-ID ...
show more
Triggered Cloudflare WAF (l7ddos) from ID.
Action taken: BLOCK
ASN: 135463 (IDNIC-SUKOHARJOKAB-AS-ID PDE Setda Kabupaten Sukoharjo)
Protocol: HTTP/2 (GET method)
Endpoint: /
show less
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-10-20 08:03:30
(10 months ago)
(mod_security) mod_security (id:240335) triggered by 103.70.79.3 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 103.70.79.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 20 04:03:21.757902 2025] [security2:error] [pid 2940:tid 2940] [client 103.70.79.3:58606] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.70.79.3 (+1 hits since last alert)|www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.vangentholding.com"] [uri "/xmlrpc.php"] [unique_id "aPXsyaK5QZ8G2Fox50m93AAAAA0"], referer: http://www.vangentholding.com/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
skycodee
2025-10-05 12:49:10
(10 months ago)
Repeated TLS handshake abuse against Pterodactyl Wings (port 8080)
DDoS Attack
๐ฌ๐ง
Silly Development
2025-09-29 20:52:30
(10 months ago)
Malicious activity detected from 135463 IDNIC-SUKOHARJOKAB-AS-ID PDE Setda Kabupaten Sukoharjo towar ...
show more
Malicious activity detected from 135463 IDNIC-SUKOHARJOKAB-AS-ID PDE Setda Kabupaten Sukoharjo towards host sillydev.co.uk (GET HTTP/2) @ 2025-09-29T20:52:30Z (18 occurrences)
show less
DDoS Attack
Exploited Host
๐ณ๐ฑ
exxos
2025-09-28 15:03:01
(10 months ago)
HTTP1.x attacks
DDoS Attack
๐ฉ๐ช
1gz
2025-09-26 11:39:38
(11 months ago)
Triggered Cloudflare WAF (firewallCustom) from ID.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET met ...
show more
Triggered Cloudflare WAF (firewallCustom) from ID.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET method)
Endpoint: /auth/login
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
Silly Development
2025-09-20 22:57:18
(11 months ago)
Malicious activity detected from 135463 IDNIC-SUKOHARJOKAB-AS-ID PDE Setda Kabupaten Sukoharjo towar ...
show more
Malicious activity detected from 135463 IDNIC-SUKOHARJOKAB-AS-ID PDE Setda Kabupaten Sukoharjo towards host panel.sillydev.co.uk (GET HTTP/2) @ 2025-09-20T22:57:18Z (1 occurrences)
show less
DDoS Attack
Exploited Host
๐บ๐ธ
yangfan
2025-09-15 12:32:11
(11 months ago)
IP: 103.70.79.3 [Country: ID] triggered WAF (l7ddos).
Action: managed_challenge
ASN: 135463 (IDNIC-S ...
show more
IP: 103.70.79.3 [Country: ID] triggered WAF (l7ddos).
Action: managed_challenge
ASN: 135463 (IDNIC-SUKOHARJOKAB-AS-ID PDE Setda Kabupaten Sukoharjo)
Protocol: HTTP/2 (method GET)
Endpoint: /
Time: 2025-09-15T10:18:21Z
User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36
---
Report generated by CFWAF2AbuseIPDB.
show less
DDoS Attack
Web Spam
Web App Attack
Anonymous
2025-08-24 16:11:21
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_APACHE_403
Brute-Force
SSH
Anonymous
2025-08-18 15:35:06
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_APACHE_403
Brute-Force
SSH
Anonymous
2025-08-17 14:21:08
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_APACHE_403
Brute-Force
SSH
๐ฉ๐ช
Packets-Decreaser.NET
2025-08-16 23:10:45
(1 year ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam