Persistent malicious bot repeatedly returning after previous bans. Uses a deceptive User-Agent to im ...
show morePersistent malicious bot repeatedly returning after previous bans. Uses a deceptive User-Agent to impersonate a legitimate crawler and performs unauthorized automated requests against website content. Temporary bans have been extended multiple times due to continued abusive activity, indicating persistent automated scanning despite previous mitigation.
show less
This IP made a brief page requests consistent with automated activity, likely probing or attempting ...
show moreThis IP made a brief page requests consistent with automated activity, likely probing or attempting to scrape content, with no signs of normal user interaction.
show less
Repeated automated requests targeting restricted endpoints. Behavior consistent with scraping or bot ...
show moreRepeated automated requests targeting restricted endpoints. Behavior consistent with scraping or bot activity. Multiple rapid access attempts and suspicious request patterns detected. Part of a wider distributed botnet infrastructure.
show less
This IP has been observed performing repeated direct access attempts to non-public application endpo ...
show moreThis IP has been observed performing repeated direct access attempts to non-public application endpoints that are not accessible through standard user navigation. The pattern of requests is consistent with automated probing or reconnaissance activity, including attempts to enumerate or interact with restricted server-side resources. As a result of this behaviour and its frequency within a short timeframe, the address was blocked to prevent potential abuse and protect service integrity.
show less
IP observed making repeated unauthorized requests to restricted web application resources, bypassing ...
show moreIP observed making repeated unauthorized requests to restricted web application resources, bypassing normal access patterns. Behavior indicates probing and enumeration of backend endpoints, consistent with reconnaissance or attempted exploitation. Requests were blocked by security controls. Activity classified as malicious and in violation of acceptable use policies.
show less
IP observed making repeated unauthorized requests to restricted web application resources, bypassing ...
show moreIP observed making repeated unauthorized requests to restricted web application resources, bypassing normal access patterns. Behavior indicates probing and enumeration of backend endpoints, consistent with reconnaissance or attempted exploitation. Requests were blocked by security controls. Activity classified as malicious and in violation of acceptable use policies.
show less
IP observed making repeated unauthorized requests to restricted web application resources, bypassing ...
show moreIP observed making repeated unauthorized requests to restricted web application resources, bypassing normal access patterns. Behavior indicates probing and enumeration of backend endpoints, consistent with reconnaissance or attempted exploitation. Requests were blocked by security controls. Activity classified as malicious and in violation of acceptable use policies.
show less
IP address 81.17.18.98 was flagged for repeatedly making direct requests to /static.cloudflareinsigh ...
show moreIP address 81.17.18.98 was flagged for repeatedly making direct requests to /static.cloudflareinsights.com/beacon.min.js without origin or referrer headers, triggering Cloudflare and EARF automated defenses. The requests cycled through multiple spoofed User-Agent strings containing distinct components such as Presto/2.7.62, Konqueror/4.14.10, AppleWebKit/605.1.15, Gecko/20100101, and various outdated or mismatched browser identifiers (e.g., Opera/9.80, Chrome/75.0.3770.142, Safari/537.36).
show less
This IP engaged in automated scraping behavior and triggered multiple detection systems. It accessed ...
show moreThis IP engaged in automated scraping behavior and triggered multiple detection systems. It accessed numerous routes in rapid succession using an API key, with signs of spamming and enumeration. The request pattern included repeated hits within milliseconds, lacking referrers and using a spoofed browser User-Agent. Activity suggests hostile script usage or unauthorized automation probing for data access.
show less
EARF Detection Systems recorded an unauthorized attempt from this IP address to directly access the ...
show moreEARF Detection Systems recorded an unauthorized attempt from this IP address to directly access the file path /.git/config.
show less
EARF Detection Systems detected multiple unauthorized attempts from this IP address to access our se ...
show moreEARF Detection Systems detected multiple unauthorized attempts from this IP address to access our server, including /.git/logs/HEAD, /.git/info/exclude, and /doc/.env
show less
This IP (185.177.72.179) made repeated malicious requests to our server, attempting to access sensit ...
show moreThis IP (185.177.72.179) made repeated malicious requests to our server, attempting to access sensitive files and configuration data including /.env, /.env.local, /database.sql, /dump.sql, /backup.tar.gz, /aws/credentials, and various other backup, config, and log files none of which exist. The user agent was โMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36โ.
show less
Port ScanHackingSQL InjectionBrute-ForceBad Web BotExploited HostWeb App Attack
This IP address (185.177.72.204) made repeated unauthorized attempts to access sensitive files and e ...
show moreThis IP address (185.177.72.204) made repeated unauthorized attempts to access sensitive files and endpoints on our server, including various .env files (e.g., /.env, /admin-app/.env), configuration files (such as /application.properties, /config/application.yml, /aws/credentials), PHP info scripts (e.g., /phpinfo.php, /test_info.php), and proxy endpoints (e.g., /api/proxy, /api/v1/proxy). None of these endpoints or files exist on our server, and all attempts were blocked by our security system. The activity occurred on June 30, 2025, between 10:27 and 10:29 UTC, using the user agent "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36".
show less
This IP made over 40 HTTP requests within a single second, attempting to access various API and admi ...
show moreThis IP made over 40 HTTP requests within a single second, attempting to access various API and admin-related endpoints without valid credentials. All requests bypassed normal navigation and were sent directly with an outdated or spoofed Chrome/130.0.0.0 user-agent.
show less
Port ScanHackingBad Web BotWeb App Attack
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.