๐ซ๐ท
Sklurk
2026-08-20 10:46:11
(50 minutes ago)
Web App Attack
Web App Attack
Anonymous
2026-06-18 08:15:50
(2 months ago)
Large-scale coordinated botnet (200+k IPs). Attacker: mikhail-smirnov-79830323 (LinkedIn/profile ID) ...
show more
Large-scale coordinated botnet (200+k IPs). Attacker: mikhail-smirnov-79830323 (LinkedIn/profile ID) employed by Angara Technologies Group (Explicitly identified himself as enemy a week before attack began) | Attack Signature Blocked: /wishlist/index/add/product/9486/form_key/T1tiwxvhUiUIxqBr/ | UA: Opera/8.17.(X11; Linux x86_64; bg-BG) Presto/2.9.173 Version/12.00 | (Magento Site)
show less
Hacking
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-05-29 11:27:17
(2 months ago)
๐ฅถ Part of massive botnet scraping campaign that nearly turned into a DDoS on 2025-11-27
DDoS Attack
๐ช๐ธ
el-brujo
2026-03-01 07:08:36
(5 months ago)
Cloudflare WAF: Request Path: /css.html Request Query: ?thisclassname=1&backgroundcolor=1&bordercolo ...
show more
Cloudflare WAF: Request Path: /css.html Request Query: ?thisclassname=1&backgroundcolor=1&bordercolor=1&textcolor=1&elemtype=button&bordertype=solid&borderwidth=1%2C%28SELECT%2F%2A%2A%2F5091%2F%2A%2A%2FFROM%2F%2A%2A%2F%28SELECT%2F%2A%2A%2FEXP%28~%28SELECT%2F%2A%2A%2F%2A%2F%2A%2A%2FFROM%2F%2A%2A%2F%28SELECT%2F%2A%2A%2FCONCAT%28%27~%27%2C%28SELECT%2F%2A%2A%2F%28ELT%285091%3D5091%2C1%29%29%29%2C%27~%27%2C%27x%27%29%29x%29%29%29s%29&textsize=1&textfont=1&textweight=N Host: www.elhacker.net userAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Action: block Source: firewallManaged ASN Description: NAVEGANTE NETWORK, C.A. Country: VE Method: GET Timestamp: 2026-03-01T07:08:36Z ruleId: 4c580ea1b5174183b7f5e940b3de2e0a. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
gui-ying233
2026-03-01 00:02:20
(5 months ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
show less
Bad Web Bot
Anonymous
2026-02-28 01:16:46
(5 months ago)
Malicious activity
Bad Web Bot
Web App Attack
๐บ๐ธ
gui-ying233
2026-02-26 00:46:47
(5 months ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36
show less
Bad Web Bot
๐ฆ๐บ
MAGIC
2026-02-22 00:24:48
(5 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2026-02-12 01:32:13
(6 months ago)
scanning http requests from known botnet
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-06 00:40:33
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 38.58.191.83 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 38.58.191.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 05 19:40:28.771563 2026] [security2:error] [pid 32263:tid 32263] [client 38.58.191.83:60984] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.cincinnati.deubellzebub.com|F|2"] [data ".ini.ea3.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.cincinnati.deubellzebub.com"] [uri "/php.ini.ea3.bak"] [unique_id "aYU4fAuoHXeaQWwqtOx1DwAAAAk"], referer: http://www.cincinnati.deubellzebub.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MPL
2026-01-17 02:45:08
(7 months ago)
tcp/23 (2 or more attempts)
Port Scan
๐จ๐ญ
backslash
2026-01-16 22:00:08
(7 months ago)
block ruleset Badbot using very old user-agents 5CF3CDB778C7D82564405B86B9242E612F378C68
Bad Web Bot
Anonymous
2026-01-12 01:30:46
(7 months ago)
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show more
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in thread-skip.asp
show less
Bad Web Bot
Exploited Host
๐ฆ๐บ
MAGIC
2025-12-31 01:18:53
(7 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฎ๐น
VHosting
2025-12-23 10:47:26
(7 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH