[AI Threat Score: 48/100 via Groq] [AbuseIPDB Score: 22] The IP made two rapid GET / requests to maj ...
show more[AI Threat Score: 48/100 via Groq] [AbuseIPDB Score: 22] The IP made two rapid GET / requests to majikah.solutions within 1.5 seconds, both flagged as malicious-request with high severity, repeated‑reconnaissance and aggressive‑reconnaissance tags, indicating an automated web‑bot probing the site. AbuseIPDB records 11 external reports, the most recent two days ago, giving a confidence score of 22 %. CrowdSec lists the IP as known but with low confidence and no risk, so the local aggressive behavior drives the assessment. Likely motive: Web reconnaissance and automated bot probing
show less
[AI Threat Score: 75/100 via Gemini] [AbuseIPDB Score: 71] The IP address executed 3 requests target ...
show more[AI Threat Score: 75/100 via Gemini] [AbuseIPDB Score: 71] The IP address executed 3 requests targeting the endpoints /id and /officialsite on id.majikah.solutions using browser-impersonation headers. This activity is flagged for malicious requests and repeated aggressive reconnaissance. External AbuseIPDB intelligence confirms 44 total reports with a confidence score of 71%, demonstrating active participation in ongoing attacks. Likely motive: Web application reconnaissance and automated bot probing
show less
[AI Threat Score: 69/100 via Gemini] [AbuseIPDB Score: 69] The IP 139.170.72.228 generated 1 local h ...
show more[AI Threat Score: 69/100 via Gemini] [AbuseIPDB Score: 69] The IP 139.170.72.228 generated 1 local hit accessing the endpoint GET /Alvin9999/https/fanfan1.net/daohang/ on api.majikah.solutions, triggering a rate-limit rule. This request pattern correlates with automated proxy or scraping behavior. Furthermore, AbuseIPDB telemetry shows 48 external reports with a 69% abuse confidence score and a recent report from October 6, 2026. Likely motive: Automated web scraping or proxy tunneling.
show less
[AI Threat Score: 55/100 via Gemini] [AbuseIPDB Score: 44] IP 110.179.81.88 triggered a rate-limit o ...
show more[AI Threat Score: 55/100 via Gemini] [AbuseIPDB Score: 44] IP 110.179.81.88 triggered a rate-limit on GET / at api.majikah.solutions using a standard Chrome user-agent. Historical AbuseIPDB telemetry records 29 external reports with an abuse confidence score of 44%, while CrowdSec CTI independently corroborates the threat with behaviors including http:dos and http:scan under MITRE techniques T1498 and T1595. Likely motive: Automated web scanning and denial-of-service activity.
show less
[AI Threat Score: 62/100 via Gemini] [AbuseIPDB Score: 62] IP 111.113.88.196 generated 1 local hit v ...
show more[AI Threat Score: 62/100 via Gemini] [AbuseIPDB Score: 62] IP 111.113.88.196 generated 1 local hit via a GET request to / on api.majikah.solutions using a standard Chrome user-agent, triggering a rate-limit rule. Historical AbuseIPDB telemetry records 28 external reports with an abuse confidence score of 62%, most recently active on 2026-10-07. Likely motive: Automated web scraping or crawling
show less
[AI Threat Score: 25/100 via Gemini] [AbuseIPDB Score: 17] The IP address executed 3 requests target ...
show more[AI Threat Score: 25/100 via Gemini] [AbuseIPDB Score: 17] The IP address executed 3 requests targeting /id and /officialsite on id.majikah.solutions with browser impersonation headers, flagged as repeated reconnaissance. Historical telemetry shows 8 external reports and CrowdSec CTI categorizes the behavior as http:dos under MITRE technique T1498. Likely motive: Automated web reconnaissance and bot activity
show less
[AI Threat Score: 55/100 via Gemini] [AbuseIPDB Score: 55] The IP address 121.29.149.95 triggered a ...
show more[AI Threat Score: 55/100 via Gemini] [AbuseIPDB Score: 55] The IP address 121.29.149.95 triggered a rate-limit rule by issuing a GET request to the root endpoint / on api.majikah.solutions. This activity aligns with historical AbuseIPDB telemetry showing 31 total external reports and a 55% abuse confidence score, with the most recent external report occurring on 2026-10-06. Likely motive: Automated scanning or crawling.
show less
[AI Threat Score: 81/100 via Gemini] [AbuseIPDB Score: 81] The IP address 220.197.85.48 generated 1 ...
show more[AI Threat Score: 81/100 via Gemini] [AbuseIPDB Score: 81] The IP address 220.197.85.48 generated 1 local hit targeting the root endpoint GET / on api.majikah.solutions, triggering a rate-limit rule. This aligns with external telemetry showing 80 recent abuse reports and an Abuse Confidence Score of 81%, confirming active malicious scanning and automated request behavior. Likely motive: Automated reconnaissance and web bot crawling
show less
[AI Threat Score: 100/100 via Gemini] [AbuseIPDB Score: 100] The IP address 2a0a:20c0:f001:3609:ae1f ...
show more[AI Threat Score: 100/100 via Gemini] [AbuseIPDB Score: 100] The IP address 2a0a:20c0:f001:3609:ae1f:6bff:fec9:6030 generated 5 local hits triggering rate-limit rules while requesting endpoints on api.majikah.solutions, including GET /, /favicon.ico, /robots.txt, /.well-known/security.txt, and /security.txt. This activity aligns with automated reconnaissance patterns typical of web crawlers. Furthermore, historical AbuseIPDB telemetry confirms an absolute 100 percent abuse confidence score with 37 external reports. Likely motive: Automated web crawling and reconnaissance
show less
[AI Threat Score: 64/100 via Gemini] [AbuseIPDB Score: 64] The IP address 2a0a:20c0:f001:308::4 gene ...
show more[AI Threat Score: 64/100 via Gemini] [AbuseIPDB Score: 64] The IP address 2a0a:20c0:f001:308::4 generated 5 rapid local hits against api.majikah.solutions, requesting standard reconnaissance paths including /, /favicon.ico, /robots.txt, /.well-known/security.txt, and /security.txt under the rate-limit rule. This activity aligns with external AbuseIPDB telemetry showing 18 total external reports and a recent report on 2026-10-07, resulting in an Abuse Confidence Score of 64%. Likely motive: Automated web reconnaissance and bot activity.
show less
[AI Threat Score: 87/100 via Gemini] [AbuseIPDB Score: 87] IP 182.242.169.36 generated 2 local hits ...
show more[AI Threat Score: 87/100 via Gemini] [AbuseIPDB Score: 87] IP 182.242.169.36 generated 2 local hits accessing GET / and GET /favicon.ico on api.majikah.solutions, triggering rate-limit rules via a Windows Chrome user-agent. This activity is heavily corroborated by 89 external reports on AbuseIPDB with an 87% confidence score, alongside CrowdSec CTI tracking behaviors including http:scan and http:dos under MITRE techniques T1498 and T1595. Likely motive: Automated scanning and denial of service probing.
show less
[AI Threat Score: 75/100 via Gemini] [AbuseIPDB Score: 69] This IP conducted aggressive web reconnai ...
show more[AI Threat Score: 75/100 via Gemini] [AbuseIPDB Score: 69] This IP conducted aggressive web reconnaissance using browser-impersonation headers across local endpoints including /1, /fwc, and /. This activity aligns with 43 external reports on AbuseIPDB, culminating in an Abuse Confidence Score of 69% shortly before this local session. Likely motive: Automated web reconnaissance
show less
[AI Threat Score: 95/100 via Gemini] [AbuseIPDB Score: 90] IP 110.179.80.213 generated 5 local hits ...
show more[AI Threat Score: 95/100 via Gemini] [AbuseIPDB Score: 90] IP 110.179.80.213 generated 5 local hits consisting of repeated path enumeration and aggressive reconnaissance requests targeting endpoints such as /1, /fwc, and /fzh on majikah.solutions using browser-impersonation headers. This traffic aligns with an active AbuseIPDB reputation showing an abuse confidence score of 90 percent and 82 total external reports. Likely motive: Automated web application reconnaissance and probing
show less
[AI Threat Score: 100/100 via Gemini] [AbuseIPDB Score: 100] The IP address 2602:fa59:10:253::1 targ ...
show more[AI Threat Score: 100/100 via Gemini] [AbuseIPDB Score: 100] The IP address 2602:fa59:10:253::1 targeted api.majikah.solutions by issuing a GET request to /.git/config, matching source-control-probe rules. This local activity is strongly corroborated by CrowdSec tagging the IP as malicious with high confidence and behaviors including http:exploit and http:scan, alongside an AbuseIPDB confidence score of 100% based on 182 external reports. Likely motive: Automated reconnaissance targeting exposed source control metadata.
show less
[AI Threat Score: 100/100 via Gemini] [AbuseIPDB Score: 100] IP 45.138.12.47 generated 2 local hits ...
show more[AI Threat Score: 100/100 via Gemini] [AbuseIPDB Score: 100] IP 45.138.12.47 generated 2 local hits against api.majikah.solutions (GET / and GET /blog/), triggering rate-limiting. This traffic aligns with extensive external telemetry, including 549 AbuseIPDB reports and CrowdSec CTI confirmation of malicious behavior involving http:scan, http:crawl, and http:bruteforce activities. Likely motive: Automated web scanning and crawling
show less
[AI Threat Score: 35/100 via Gemini] [AbuseIPDB Score: 35] IP 27.18.82.232 generated 2 local hits re ...
show more[AI Threat Score: 35/100 via Gemini] [AbuseIPDB Score: 35] IP 27.18.82.232 generated 2 local hits requesting GET / and GET /favicon.ico on api.majikah.solutions, triggering rate-limit rules. Historical telemetry indicates 16 external reports on AbuseIPDB with a confidence score of 35%, and CrowdSec CTI categorizes the IP with http:dos, generic:scan, and http:scan behaviors, aligning with automated scanning activity. Likely motive: Automated scanning and scraping
show less
[AI Threat Score: 55/100 via Gemini] [AbuseIPDB Score: 52] The IP 123.245.84.48 generated 2 local hi ...
show more[AI Threat Score: 55/100 via Gemini] [AbuseIPDB Score: 52] The IP 123.245.84.48 generated 2 local hits targeting GET /assets/index/kuailian/image/favicon.ico and GET /details/images/favicon.ico, triggering rate-limit rules. Historical AbuseIPDB telemetry reveals 41 external reports with an abuse confidence score of 52%, while CrowdSec CTI corroborates this malicious activity by flagging the IP with low risk, medium confidence, and behaviors including http:scan and http:dos associated with MITRE techniques T1498 and T1595. Likely motive: Automated scanning and web reconnaissance
show less
[AI Threat Score: 63/100 via Gemini] [AbuseIPDB Score: 63] The IP 112.94.253.63 generated 2 local hi ...
show more[AI Threat Score: 63/100 via Gemini] [AbuseIPDB Score: 63] The IP 112.94.253.63 generated 2 local hits targeting GET / on api.majikah.solutions, triggering rate-limiting rules. CrowdSec corroborates this activity with behaviors including http:dos, generic:exploit, and http:scan, mapping to MITRE techniques T1190, T1595, and T1498. Combined with 37 external reports on AbuseIPDB resulting in an Abuse Confidence Score of 63%, this traffic reflects automated malicious reconnaissance. Likely motive: Automated scanning and application probing
show less
[AI Threat Score: 45/100 via Gemini] [AbuseIPDB Score: 44] The IP 60.166.83.73 generated 2 local hit ...
show more[AI Threat Score: 45/100 via Gemini] [AbuseIPDB Score: 44] The IP 60.166.83.73 generated 2 local hits executing GET requests for / and /favicon.ico on api.majikah.solutions, triggering rate limits. Historical AbuseIPDB telemetry records 42 external reports with a 44% confidence score, while CrowdSec flags the IP with scanning and exploit behaviors. Likely motive: Automated web scanning and endpoint enumeration
show less
[AI Threat Score: 88/100 via Groq] [AbuseIPDB Score: 100] The IP made a single GET request to /randk ...
show more[AI Threat Score: 88/100 via Groq] [AbuseIPDB Score: 100] The IP made a single GET request to /randkeyword.PhP7 on api.majikah.solutions, flagged with a rate‑limit tag, indicating an automated probe of a random PHP endpoint. AbuseIPDB records show a 100% confidence score with 1,958 external reports and the most recent report just minutes after the local hit, confirming active, widespread abuse. Combined with the Microsoft ASN and Korean origin, the pattern aligns with a malicious web bot targeting web applications. Likely motive: Automated probing for vulnerable web applications
show less
[AI Threat Score: 77/100 via Gemini] [AbuseIPDB Score: 77] IP address 172.238.172.176 generated a ra ...
show more[AI Threat Score: 77/100 via Gemini] [AbuseIPDB Score: 77] IP address 172.238.172.176 generated a rate-limited request targeting the root endpoint GET / on api.majikah.solutions using a mobile Chrome user-agent string. Historical AbuseIPDB intelligence confirms 103 external reports, with the most recent report occurring on 2026-10-07T09:22:31.000Z and an overall abuse confidence score of 77 percent, demonstrating an active and sustained pattern of malicious automated activity. Likely motive: Automated web scraping or application probing
show less
[AI Threat Score: 90/100 via Gemini] [AbuseIPDB Score: 90] IP address 58.59.233.159 targeted the end ...
show more[AI Threat Score: 90/100 via Gemini] [AbuseIPDB Score: 90] IP address 58.59.233.159 targeted the endpoint GET /officialsite utilizing browser impersonation headers. This traffic aligns with 89 external reports on AbuseIPDB, culminating in an Abuse Confidence Score of 90% as of October 2026. Likely motive: Automated web scraping or malicious bot reconnaissance.
show less
[AI Threat Score: 60/100 via Gemini] [AbuseIPDB Score: 56] The IP 123.245.85.191 generated 2 local h ...
show more[AI Threat Score: 60/100 via Gemini] [AbuseIPDB Score: 56] The IP 123.245.85.191 generated 2 local hits requesting GET / and GET /favicon.ico on api.majikah.solutions, triggering rate-limiting rules using a standard Windows Chrome User-Agent. This activity correlates with external telemetry showing 36 AbuseIPDB reports and CrowdSec classifications including http:scan, http:dos, and generic:exploit with MITRE techniques T1190, T1595, and T1498. Likely motive: Automated scanning and vulnerability probing
show less
[AI Threat Score: 60/100 via Gemini] [AbuseIPDB Score: 55] The IP 123.178.210.30 generated 2 rapid l ...
show more[AI Threat Score: 60/100 via Gemini] [AbuseIPDB Score: 55] The IP 123.178.210.30 generated 2 rapid local hits targeting GET / and GET /favicon.ico on api.majikah.solutions, triggering rate-limiting rules. CrowdSec independently flags the IP with known malicious behaviors including http:dos, generic:scan, and http:scan associated with MITRE techniques T1595 and T1498. AbuseIPDB reports 48 total external complaints, corroborating an active threat posture. Likely motive: Automated scanning and denial of service probing
show less
[AI Threat Score: 52/100 via Gemini] [AbuseIPDB Score: 52] The IP address 36.106.167.211 generated a ...
show more[AI Threat Score: 52/100 via Gemini] [AbuseIPDB Score: 52] The IP address 36.106.167.211 generated a local request to /officialsite on majikah.solutions using browser-impersonation headers, flagged for malicious-request and repeated-reconnaissance. This aligns with historical AbuseIPDB telemetry showing 26 external reports, with the latest recorded on 2026-10-07T02:01:05.000Z and an abuse confidence score of 52%. Likely motive: Automated web scraping and reconnaissance
show less
Bad Web BotWeb App Attack
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.