Fake iOS 26.4.2 (OS doesn't exist), fbclid cover, POST on /, simultaneous admin-ajax calls โ part of ...
show moreFake iOS 26.4.2 (OS doesn't exist), fbclid cover, POST on /, simultaneous admin-ajax calls โ part of ongoing coordinated botnet attack since 2026-04-29
show less
fbclid cover without referrer (fake), POST on /, simultaneous admin-ajax and BetterDocs REST API cal ...
show morefbclid cover without referrer (fake), POST on /, simultaneous admin-ajax and BetterDocs REST API calls โ part of ongoing coordinated botnet attack since 2026-04-29
show less
Headless browser, POST on /, simultaneous admin-ajax calls โ part of ongoing coordinated botnet atta ...
show moreHeadless browser, POST on /, simultaneous admin-ajax calls โ part of ongoing coordinated botnet attack since 2026-04-29. Previous DDoS participation confirmed.
show less
PHP webshell enumeration, scanning for uploaded shells in wp-admin subdirectories โ automated scanne ...
show morePHP webshell enumeration, scanning for uploaded shells in wp-admin subdirectories โ automated scanner
show less
Credential stuffing attack, systematic login enumeration including password reset endpoint /einlogge ...
show moreCredential stuffing attack, systematic login enumeration including password reset endpoint /einloggen-2/?action=lostpassword โ part of ongoing coordinated attack since 2026-04-29
show less
Headless browser mimicking outdated Firefox/Windows 7, POST on / after every GET โ part of ongoing c ...
show moreHeadless browser mimicking outdated Firefox/Windows 7, POST on / after every GET โ part of ongoing coordinated botnet attack since 2026-04-29
show less
Fake Android 16 (OS doesn't exist), fbclid cover, simultaneous POST on / and admin-ajax โ part of on ...
show moreFake Android 16 (OS doesn't exist), fbclid cover, simultaneous POST on / and admin-ajax โ part of ongoing coordinated botnet attack since 2026-04-29
show less
Headless browser, POST on /, multiple simultaneous admin-ajax calls, fake Safari version (26.4 doesn ...
show moreHeadless browser, POST on /, multiple simultaneous admin-ajax calls, fake Safari version (26.4 doesn't exist) โ part of ongoing coordinated botnet attack since 2026-04-29
show less
Fake ChatGPT-User bot from Azure Phoenix, sequential participant ID enumeration โ identical attack p ...
show moreFake ChatGPT-User bot from Azure Phoenix, sequential participant ID enumeration โ identical attack pattern to 2026-05-12 campaign
show less
Automated forum search with double-encoded UTF-8 (encoding error typical of bots), targeted thematic ...
show moreAutomated forum search with double-encoded UTF-8 (encoding error typical of bots), targeted thematic search term without prior page visit โ part of ongoing coordinated attack against alkohol-ade.com since 2026-04-29
show less
Fake meta-externalagent crawler from Meta IP range, systematic forum crawling with multiple parallel ...
show moreFake meta-externalagent crawler from Meta IP range, systematic forum crawling with multiple parallel IPs from same /24, confirmed by multiple independent sources (CrowdSec, Fail2Ban). Not legitimate Meta crawler โ no correlation with actual Facebook page activity.
show less
Fake crawler with non-existent contact URL (crawler.example), probing security.txt โ not a legitimat ...
show moreFake crawler with non-existent contact URL (crawler.example), probing security.txt โ not a legitimate security researcher
show less
Automated wpForo signup endpoint probing, direct navigation to /aa-login/?wpforo=signup without huma ...
show moreAutomated wpForo signup endpoint probing, direct navigation to /aa-login/?wpforo=signup without human browsing pattern
show less
BASE64-encoded PHP webshell upload attempt, CRITICAL severity, identical payload to ongoing attack c ...
show moreBASE64-encoded PHP webshell upload attempt, CRITICAL severity, identical payload to ongoing attack campaign
show less
Compromised device (hotel network Salzburg AT), headless browser with fbclid cover, simultaneous POS ...
show moreCompromised device (hotel network Salzburg AT), headless browser with fbclid cover, simultaneous POST on / and multiple admin-ajax calls โ part of ongoing coordinated botnet attack since 2026-04-29
show less
Systematic site reconnaissance, targeting all login endpoints and content structure โ proxy IP Weeha ...
show moreSystematic site reconnaissance, targeting all login endpoints and content structure โ proxy IP Weehawken NJ
show less
HackingWeb App Attack
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.