๐ฑ๐ป
garmtech.com
2026-03-25 23:54:58
(2 months ago)
IM360 WAF: Interaction with fake plugin MV:/wp-content/plugins/easy-themes-manager/script.js
Web App Attack
๐ซ๐ท
Sklurk
2026-03-25 02:48:14
(2 months ago)
Web App Attack
Web App Attack
๐ธ๐ฌ
mypatricks
2026-03-01 16:32:37
(3 months ago)
43.163.92.92 | Port: 9382 | DNS: 43.163.92.92 2026-03-02T00:32:36+08:00 Asia/Singapore | Apple Ident ...
show more
43.163.92.92 | Port: 9382 | DNS: 43.163.92.92 2026-03-02T00:32:36+08:00 Asia/Singapore | Apple Identity Spoofing | UA: Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.0 Mobile/15E148 Safari/604.1 HTTP/1.1 443 GET | URL: /customer-self-service/order-returns-policy/?9c4ee4d53c1d49fc8b=ms-my | Ref: - | Country: SG/Singapore/+08:00 IP City: Singapore iOS Mobile 9d598ef43a34fd8d-SIN/Singapore, Singapore 1 hits/0 secs Browser 2
show less
Brute-Force
Web App Attack
Blog Spam
Web Spam
Exploited Host
Anonymous
2026-02-28 07:27:41
(3 months ago)
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show more
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in printer-friendly.asp
show less
Exploited Host
Bad Web Bot
๐ณ๐ฑ
exxos
2025-08-28 17:03:01
(9 months ago)
Attacks with Bad user agents
Hacking
๐ฎ๐ช
Jim Keir
2025-08-28 14:22:36
(9 months ago)
2025-08-28 14:22:35 43.163.92.92 File scanning, blocking 43.163.92.92 for 5 minutes
Web App Attack
๐ฉ๐ช
bescared
2025-08-27 13:43:32
(9 months ago)
F2B - Malicious activity detected. URL Probing.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-27 06:10:47
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 43.163.92.92 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 43.163.92.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 27 02:10:40.296511 2025] [security2:error] [pid 12970:tid 12970] [client 43.163.92.92:54975] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||frightlibrary.org|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "frightlibrary.org"] [uri "/citizen/medievaltimes.com"] [unique_id "aK6hYNCP5IE1forYt-M8xAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Sklurk
2025-08-27 05:58:09
(9 months ago)
Web App Attack
Web App Attack
๐ต๐ฑ
sefinek.net
2025-08-26 11:44:46
(9 months ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /about
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฎ๐ฉ
hermawan
2025-08-26 10:20:32
(9 months ago)
[Tue Aug 26 17:18:45.585134 2025] [security2:error] [pid 120690:tid 140703043675840] [client 43.163. ...
show more
[Tue Aug 26 17:18:45.585134 2025] [security2:error] [pid 120690:tid 140703043675840] [client 43.163.92.92:39731] ModSecurity: Access denied with code 403 (phase 1). Match of "pm matomo.staklim-malang.info " against "SERVER_NAME" required. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "164"] [id "440235"] [msg "BAD REQUEST Bro"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: format=opensearch found within SERVER_NAME: staklim-jatim.bmkg.go.id request_line = GET /index.php/component/search/?Itemid=1751&format=opensearch HTTP/2.0 Request URI RAW = /index.php/component/search/?Itemid=1751&format=opensearch Request Basename = "] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/component/search/"] [unique_id "aK2KBRmMGKxFFVv4jP51hAACxAE"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[120692] [JfhK/4Ftfw8] [aK2KBRmMGKxFFVv4jP51hAACxAE] keep_alive=[1] [2025-08-2
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
Burayot
2025-08-26 06:02:41
(9 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 43.163.92.92 (SG/Singapore/-): 1 in ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 43.163.92.92 (SG/Singapore/-): 1 in the last 3600 secs
show less
Web App Attack
๐ณ๐ฑ
exxos
2025-08-22 01:03:01
(9 months ago)
Attacks with Bad user agents
Hacking
๐จ๐ญ
backslash
2025-08-21 18:35:09
(9 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot