IP address 100.52.180.20 was observed conducting automated reconnaissance and exploitation activity ...
show moreIP address 100.52.180.20 was observed conducting automated reconnaissance and exploitation activity against a public-facing web application. The source generated multiple Web Application Firewall (WAF) detections consistent with malicious probing and attack attempts.
Observed attack patterns include:
Multiple SQL Injection (SQLi) attempts, including:
Basic authentication bypass attempts
Common SQL injection testing payloads
MySQL comment and space-obfuscated SQL injection techniques
Character and comment-based injection payloads
Excessive use of special characters designed to bypass input validation controls
Cross-Site Scripting (XSS) probing activity
Attempted exploitation of React2Shell Remote Code Execution (CVE-2025-55182)
PHP Injection attempts using variable function call techniques
WAF anomaly scoring thresholds exceeded due to the volume and severity of malicious requests
The activity appears to be consistent with an automated vulnerability scanning against web apps.
show less
IP address 138.197.17.142 was observed conducting automated reconnaissance and exploitation activity ...
show moreIP address 138.197.17.142 was observed conducting automated reconnaissance and exploitation activity against a public-facing web application. The source generated multiple Web Application Firewall (WAF) detections consistent with malicious probing and attack attempts.
Observed attack patterns include:
Multiple SQL Injection (SQLi) attempts, including:
Basic authentication bypass attempts
Common SQL injection testing payloads
MySQL comment and space-obfuscated SQL injection techniques
Character and comment-based injection payloads
Excessive use of special characters designed to bypass input validation controls
Cross-Site Scripting (XSS) probing activity
Attempted exploitation of React2Shell Remote Code Execution (CVE-2025-55182)
PHP Injection attempts using variable function call techniques
WAF anomaly scoring thresholds exceeded due to the volume and severity of malicious requests
The activity appears to be consistent with an automated vulnerability scanning against web apps.
show less
IP address 34.229.194.66 was observed conducting automated reconnaissance and exploitation activity ...
show moreIP address 34.229.194.66 was observed conducting automated reconnaissance and exploitation activity against a public-facing web application. The source generated multiple Web Application Firewall (WAF) detections consistent with malicious probing and attack attempts.
Observed attack patterns include:
Multiple SQL Injection (SQLi) attempts, including:
Basic authentication bypass attempts
Common SQL injection testing payloads
MySQL comment and space-obfuscated SQL injection techniques
Character and comment-based injection payloads
Excessive use of special characters designed to bypass input validation controls
Cross-Site Scripting (XSS) probing activity
Attempted exploitation of React2Shell Remote Code Execution (CVE-2025-55182)
PHP Injection attempts using variable function call techniques
WAF anomaly scoring thresholds exceeded due to the volume and severity of malicious requests
The activity appears to be consistent with an automated vulnerability scanning against internet facing apps.
show less
Web App AttackWeb SpamSQL Injection
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.