๐ฆ๐บ
MAGIC
2026-06-17 04:00:25
(1 month ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ญ๐บ
bcsaba
2026-06-17 02:53:06
(1 month ago)
Joomla spam
45.130.81.44 - - [17/Jun/2026:04:53:04 +0200] "GET /index.php?option=com_easyblog&view=d ...
show more
Joomla spam
45.130.81.44 - - [17/Jun/2026:04:53:04 +0200] "GET /index.php?option=com_easyblog&view=dashboard&layout=write HTTP/1.1" 404 789 "https://*REDACTED*" "Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0"
show less
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-05-28 14:31:33
(1 month ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
NL/Netherlands/-
Web App Attack
๐ฏ๐ต
demonsword
2026-05-28 13:18:49
(1 month ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: cute-potato.com:80
show less
Open Proxy
Port Scan
Anonymous
2026-05-03 04:04:58
(2 months ago)
Forum/form spam
Web Spam
๐ช๐จ
icp77
2026-03-23 15:15:00
(4 months ago)
Abuse DDoS
DDoS Attack
Port Scan
Brute-Force
Exploited Host
Web App Attack
SSH
FTP Brute-Force
Hacking
SQL Injection
๐บ๐ธ
r3versedk
2026-03-14 04:33:52
(4 months ago)
๐ก๏ธ Automated Threat Report from maxjensen.dk
๐ฏ Attack Type: Botnet Fingerprint
๐จ Severity: CRITICAL ...
show more
๐ก๏ธ Automated Threat Report from maxjensen.dk
๐ฏ Attack Type: Botnet Fingerprint
๐จ Severity: CRITICAL
๐ Threat Score: 95/100
๐ Total Attacks: 398 (database verified, seen over today)
๐ Peak Score: 95/100
๐ฏ Common Types: Botnet Fingerprint(1x)
๐ Fingerprint: 9f96b00ce11bc787
๐ค AI/ML: ๐ค Multi-Model Consensus (neural-network, q-learning, gpt) - ๐ง NN (55%): block (95.9%) | ๐ฎ QL (23%): block (75.0%) | ๐ค Claude (23%): monitor (70.0%) | โ๏ธ dynamic+boosted weights...
Detected: 2026-03-14T04:33:52.498Z
show less
Bad Web Bot
๐บ๐ธ
Penny Packer
2026-03-08 17:49:00
(4 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐ฌ๐ง
pinguin
2026-03-03 14:07:07
(4 months ago)
Triggered Cloudflare WAF (firewallManaged) from UA.
Action taken: LOG
Protocol: HTTP/2 (HEAD method) ...
show more
Triggered Cloudflare WAF (firewallManaged) from UA.
Action taken: LOG
Protocol: HTTP/2 (HEAD method)
Endpoint: /backup/wallet.dat
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-02-23 19:08:37
(5 months ago)
[redacted] 45.130.81.44 - - [23/Feb/2026:20:08:33 +0100] "GET /wp-admin/js/widgets/ HTTP/1.1" 404 23 ...
show more
[redacted] 45.130.81.44 - - [23/Feb/2026:20:08:33 +0100] "GET /wp-admin/js/widgets/ HTTP/1.1" 404 236 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95"
[redacted] 45.130.81.44 - - [23/Feb/2026:20:08:33 +0100] "GET /wp-content/plugins/wp-file-manager/admin/ HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36"
[redacted] 45.130.81.44 - - [23/Feb/2026:20:08:33 +0100] "GET /wp-admin/js/widget/ HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3"
[redacted] 45.130.81.44 - - [23/Feb/2026:20:08:34 +0100] "GET /wp-admin/ HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36"
zirkus-re
...
show less
Hacking
Web App Attack
๐จ๐ฆ
polycoda
2026-02-23 14:25:23
(5 months ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based)
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-23 11:31:40
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 45.130.81.44 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.130.81.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 06:31:36.179408 2026] [security2:error] [pid 12450:tid 12450] [client 45.130.81.44:34157] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||russiacoin.info|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "russiacoin.info"] [uri "/old/www.sql"] [unique_id "aZw6mIdodrIIcAxGnAi36AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-07 10:42:35
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 45.130.81.44 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.130.81.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 07 05:42:31.097217 2026] [security2:error] [pid 29311:tid 29311] [client 45.130.81.44:46877] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||3dsportschannel.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "3dsportschannel.com"] [uri "/dump.sql"] [unique_id "aYcXF4hY_0DJ3j-YbLP61gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-05 23:55:48
(5 months ago)
[redacted] 45.130.81.44 - - [06/Feb/2026:00:55:43 +0100] "GET /.well-known/pki-validation/admin.php ...
show more
[redacted] 45.130.81.44 - - [06/Feb/2026:00:55:43 +0100] "GET /.well-known/pki-validation/admin.php HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36"
[redacted] 45.130.81.44 - - [06/Feb/2026:00:55:43 +0100] "GET /wp-includes/IXR/admin.php HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95"
[redacted] 45.130.81.44 - - [06/Feb/2026:00:55:43 +0100] "GET /wp-admin/js/index.php HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36"
[redacted] 45.130.81.44 - - [06/Feb/2026:00:55:44 +0100] "GET /wp-admin/network/network.php HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0"
[redacted] 45.130.81.44 - - [06/Feb/2026:00:55:44 +0100] "GET /admin/upload/css.php HTTP/1.1" 40
...
show less
Hacking
Web App Attack
๐ฏ๐ต
Valhalla
2026-01-29 09:45:02
(5 months ago)
/bak/backup.sql.gz
Hacking
Web App Attack