๐จ๐ฑ
SinaiCL
2026-07-22 03:55:13
(1 day ago)
WAF Multiple Hits
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 00:30:29
(1 day ago)
Attack detected: 104.28.252.172 [2026-07-22]
Categories: 21
--- wp2shell/batch exploit (9 hits) ---
...
show more
Attack detected: 104.28.252.172 [2026-07-22]
Categories: 21
--- wp2shell/batch exploit (9 hits) ---
104.28.252.172 - - [21/Jul/2026:07:22:35 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 5189 "-" "Python-urllib/3.14"
104.28.252.172 - - [21/Jul/2026:07:21:26 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 5195 "-" "Python-urllib/3.14"
104.28.252.172 - - [21/Jul/2026:07:21:52 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 503 542 "-" "Python-urllib/3.14"
104.28.252.172 - - [21/Jul/2026:07:21:31 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 1003 "-" "Python-urllib/3.14"
104.28.252.172 - - [21/Jul/2026:07:21:40 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 5194 "-" "Python-urllib/3.14"
show less
Web App Attack
Anonymous
2026-07-20 23:44:54
(2 days ago)
Attack report: 104.28.252.172 โ LMB2 [2026-07-20]
Hostname: ip-172-31-13-102
Categories: 21
--- wp2s ...
show more
Attack report: 104.28.252.172 โ LMB2 [2026-07-20]
Hostname: ip-172-31-13-102
Categories: 21
--- wp2shell/batch exploit (1 hits) ---
104.28.252.172 - - [20/Jul/2026:20:04:51 +0000] "POST /?rest_route=/batch/v1 HTTP/1.1" 207 5039 "-" "Python-urllib/3.14" 1003902
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-20 22:56:59
(2 days ago)
IM360 WAF: WordPress wp2shell REST batch endpoint before 7.0.2 or 6.9.5 (CVE-2026-63030) MV:/batch/v ...
show more
IM360 WAF: WordPress wp2shell REST batch endpoint before 7.0.2 or 6.9.5 (CVE-2026-63030) MV:/batch/v1
show less
Hacking
๐บ๐ธ
kosada.com
2026-07-17 14:17:46
(5 days ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
xmission.com
2025-11-16 21:02:44
(8 months ago)
Blocked by UFW (TCP on 9101)
Source port: 18698
TTL: 48
Packet length: 60
TOS: 0x08
This report (fo ...
show more
Blocked by UFW (TCP on 9101)
Source port: 18698
TTL: 48
Packet length: 60
TOS: 0x08
This report (for 104.28.252.172) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฉ๐ช
Packets-Decreaser.NET
2025-10-14 20:27:05
(9 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐ณ๐ฑ
exxos
2025-09-18 23:03:01
(10 months ago)
Attacks with Bad user agents
Hacking
๐ฒ๐พ
syokadmin
2024-10-18 16:18:31
(1 year ago)
104.28.252.172 (US/United States/-), 3 distributed smtpauth attacks on account [enquiryfacebook@mbin ...
show more
104.28.252.172 (US/United States/-), 3 distributed smtpauth attacks on account [[email protected] ] in the last 3600 secs
show less
Brute-Force
Anonymous
2024-10-02 00:17:30
(1 year ago)
wordpress-trap
Web App Attack
Anonymous
2024-10-01 03:59:58
(1 year ago)
wordpress-trap
Web App Attack
Anonymous
2024-09-11 00:32:16
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2024-09-10 20:12:27
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 104.28.252.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 104.28.252.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 10 16:12:22.250781 2024] [security2:error] [pid 25694:tid 25694] [client 104.28.252.172:46160] [client 104.28.252.172] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 104.28.252.172 (+1 hits since last alert)|roguetechhub.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "roguetechhub.com"] [uri "/xmlrpc.php"] [unique_id "ZuCoJuQ-vvyANS4xCeM6igAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-10 16:00:28
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 104.28.252.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.28.252.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 10 12:00:20.869708 2024] [security2:error] [pid 2409:tid 2409] [client 104.28.252.172:28511] [client 104.28.252.172] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aimer.es|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aimer.es"] [uri "/wordpress/wp-json/wp/v2/users/"] [unique_id "ZuBtFFHdv339FQUBKKVBJwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
applemooz
2024-09-10 08:11:43
(1 year ago)
<abuseipdb_matches>
...
Brute-Force
Web App Attack