This IP is part of an automated SQL Injection campaign targeting a web application.
The payload us ...
show moreThis IP is part of an automated SQL Injection campaign targeting a web application.
The payload uses boolean-based blind SQLi techniques with CASE WHEN, CAST, and obfuscation methods.
High request frequency indicates active scanning and exploitation attempts.
show less
This IP is part of an automated SQL Injection campaign targeting a web application.
The payload us ...
show moreThis IP is part of an automated SQL Injection campaign targeting a web application.
The payload uses boolean-based blind SQLi techniques with CASE WHEN, CAST, and obfuscation methods.
High request frequency indicates active scanning and exploitation attempts.
show less
This IP is part of an automated SQL Injection campaign targeting a web application.
The payload us ...
show moreThis IP is part of an automated SQL Injection campaign targeting a web application.
The payload uses boolean-based blind SQLi techniques with CASE WHEN, CAST, and obfuscation methods.
High request frequency indicates active scanning and exploitation attempts.
show less
This IP is performing active exploitation attempts against a web application, including SQL Injectio ...
show moreThis IP is performing active exploitation attempts against a web application, including SQL Injection, Cross-Site Scripting (XSS), and Command Injection techniques. The payload includes UNION SELECT, information_schema enumeration, and xp_cmdshell execution attempts. This behavior is clearly malicious and automated.
show less
This IP attempted a highly crafted SQL Injection attack against a production website. The request in ...
show moreThis IP attempted a highly crafted SQL Injection attack against a production website. The request included dynamic SQL, table enumeration via INFORMATION_SCHEMA, and multiple EXECUTE statements. The activity was clearly malicious and blocked by the WAF.
show less
This IP attempted to establish an encrypted outbound connection consistent with command‑and‑control ...
show moreThis IP attempted to establish an encrypted outbound connection consistent with command‑and‑control activity, indicating potential backdoor or malware behavior.
show less
Detected multiple SQL Injection attempts from IP 171.6.13.243 Payload includes SELECT, INFORMATION_S ...
show moreDetected multiple SQL Injection attempts from IP 171.6.13.243 Payload includes SELECT, INFORMATION_SCHEMA, RAND() with obfuscation.
show less
Malicious activity detected from IP 23.234.93.117. Attempted SQL Injection on e-commerce site via cr ...
show moreMalicious activity detected from IP 23.234.93.117. Attempted SQL Injection on e-commerce site via crafted GET request with obfuscated payload.
show less
Malicious request from IP 147.45.116.123 attempting directory traversal to access SSL key file. Used ...
show moreMalicious request from IP 147.45.116.123 attempting directory traversal to access SSL key file. Used encoded traversal pattern. Server closed connection (444). No legitimate reason for this behavior.
show less
Malicious request from IP 147.45.116.187 attempting directory traversal to access wp-config.php via ...
show moreMalicious request from IP 147.45.116.187 attempting directory traversal to access wp-config.php via vulnerable plugin path. Server denied access (403). No legitimate reason for this behavior.
show less
Suspicious activity detected from IP 78.153.151.5. Attempted directory traversal targeting sensitive ...
show moreSuspicious activity detected from IP 78.153.151.5. Attempted directory traversal targeting sensitive SSL key paths. Request used encoded traversal patterns and outdated user-agent. No legitimate reason for this behavior.
show less
Suspicious activity detected from sorvetenopote.com. Endpoint attempted to execute obfuscated PowerS ...
show moreSuspicious activity detected from sorvetenopote.com. Endpoint attempted to execute obfuscated PowerShell commands to connect, download, and run potentially malicious content. Behavior matches known downloader patterns (CL.Downloader!gen9).
show less
Suspicious activity detected from expansiveuser.com. Endpoint attempted to execute obfuscated PowerS ...
show moreSuspicious activity detected from expansiveuser.com. Endpoint attempted to execute obfuscated PowerShell commands to connect, download, and run potentially malicious content. Behavior matches known downloader patterns (CL.Downloader!gen9).
show less
Suspicious activity detected from zapgrande.com. Endpoint attempted to execute obfuscated PowerShell ...
show moreSuspicious activity detected from zapgrande.com. Endpoint attempted to execute obfuscated PowerShell commands to connect, download, and run potentially malicious content. Behavior matches known downloader patterns (CL.Downloader!gen9).
show less
Suspicious activity detected from IP 181.41.201.158. Attempted SQL Injection via crafted GET request ...
show moreSuspicious activity detected from IP 181.41.201.158. Attempted SQL Injection via crafted GET request targeting a public-facing web endpoint. Request contained UNION SELECT and MD5 hash injection patterns.
show less
Suspicious SQL Injection attempt detected targeting a public website. The payload used time-based te ...
show moreSuspicious SQL Injection attempt detected targeting a public website. The payload used time-based techniques (PG_SLEEP) to test for vulnerabilities.
show less
SQL Injection attempt detected from IP 85.192.49.158 targeting a public API endpoint. Payload includ ...
show moreSQL Injection attempt detected from IP 85.192.49.158 targeting a public API endpoint. Payload included time-based injection using PG_SLEEP(15).
show less
Suspicious activity detected from IP 147.45.116.177. Attempted Log4Shell exploitation via HTTP heade ...
show moreSuspicious activity detected from IP 147.45.116.177. Attempted Log4Shell exploitation via HTTP headers.
show less
The IP attempted a SQL Injection attack targeting a public-facing web application. The payload used ...
show moreThe IP attempted a SQL Injection attack targeting a public-facing web application. The payload used a UNION SELECT statement with an MD5 hash function, commonly employed to test for SQLi vulnerabilities.
show less
SQL Injection
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.