Fake Mozlila/5.0 Android UA scanner toolkit, hitting wrpilates.com, CRS-blocked (913100 scanner-UA s ...
show moreFake Mozlila/5.0 Android UA scanner toolkit, hitting wrpilates.com, CRS-blocked (913100 scanner-UA signature + 949110 anomaly). Same /24 as a previously-reported member of this campaign.
show less
Scripted scanner UA (fake Mozlila/5.0 Android/SM-G892A Bulid/NRD90M) hitting WooCommerce sites, bloc ...
show moreScripted scanner UA (fake Mozlila/5.0 Android/SM-G892A Bulid/NRD90M) hitting WooCommerce sites, blocked by OWASP CRS (949110 anomaly + 913100 scanner-UA signature). Same toolkit/subnet as previously-reported 45.38.15.87/45.38.15.137.
show less
Scripted scanner UA (fake Mozlila/5.0 Android/SM-G892A Bulid/NRD90M) hitting WooCommerce sites, bloc ...
show moreScripted scanner UA (fake Mozlila/5.0 Android/SM-G892A Bulid/NRD90M) hitting WooCommerce sites, blocked by OWASP CRS (949110 anomaly + 913100 scanner-UA signature). Same toolkit as previously-reported 45.38.15.87/45.38.15.137/45.38.16.60.
show less
Fake Mozlila/Android scanner UA against wrpilates.com (WordPress). OWASP CRS rules 949110 (anomaly s ...
show moreFake Mozlila/Android scanner UA against wrpilates.com (WordPress). OWASP CRS rules 949110 (anomaly score) + 913100 (scanner UA signature) triggered, request blocked. Same toolkit/campaign as previously-reported 45.38.15.87 and 45.38.15.137 (different /24 in same block), rotating subnets.
show less
Sustained FTP brute-force against pure-ftpd, 30+ failed login attempts per ~900s cycling, since ~08: ...
show moreSustained FTP brute-force against pure-ftpd, 30+ failed login attempts per ~900s cycling, since ~08:33 2026-08-18 UTC-7. Alibaba Cloud (AS45102) source. Port now closed/blocked at firewall + service disabled.
show less
Scripted secrets/credential-harvest scan against WooCommerce site (volcanoswitch.com) via Cloudflare ...
show moreScripted secrets/credential-harvest scan against WooCommerce site (volcanoswitch.com) via Cloudflare-proxied traffic. Swept 35+ paths (.bash_history, docker-compose.yml, secrets.json, laravel logs, phpinfo.php, etc). CSF perm-deny + CF Rule 1 hard block applied 2026-08-17.
show less
Scripted secrets/credential-harvest scan against WooCommerce site (volcanoswitch.com) via Cloudflare ...
show moreScripted secrets/credential-harvest scan against WooCommerce site (volcanoswitch.com) via Cloudflare-proxied traffic. Hit /.npmrc, /.aws/config, /env.js, /local_settings.py, /config.json. CSF perm-deny + CF Rule 1 hard block applied 2026-08-17.
show less
Scanned wrpilates.com with spoofed/scripted Android UA (scanner-associated signature), same /24 and ...
show moreScanned wrpilates.com with spoofed/scripted Android UA (scanner-associated signature), same /24 and identical UA toolkit as a prior confirmed attacker from this range. Blocked at origin (CSF permanent deny) and Cloudflare WAF (hard block, all zones).
show less
Scanned depoteco.com for backdoor/webshell filenames (alfa-rex.PHP, zwso.php, simple.php, new.php, i ...
show moreScanned depoteco.com for backdoor/webshell filenames (alfa-rex.PHP, zwso.php, simple.php, new.php, i.php, goods.php, chosen.php) and tripped OWASP CRS scanner-detection + anomaly-score rules. Blocked at origin (CSF permanent deny) and Cloudflare WAF mitigation list.
show less
Vulnerability scan against nonexistent WordPress theme files (probing for known-vulnerable theme pat ...
show moreVulnerability scan against nonexistent WordPress theme files (probing for known-vulnerable theme paths not present on this install), plus scanner-UA signature match. OWASP CRS rules 913100 + 949110 triggered.
show less
Repeated rapid-fire requests spoofing multiple legitimate crawler user-agents (Baiduspider, ChatGPT- ...
show moreRepeated rapid-fire requests spoofing multiple legitimate crawler user-agents (Baiduspider, ChatGPT-User, OAI-SearchBot - all fake) against a single WordPress product page. Blocked each time by bad-bot signature list.
show less
Scripted scanner against WordPress site, spoofed fake Android UA (Mozlila/5.0 typo, Bulid/NRD90M typ ...
show moreScripted scanner against WordPress site, spoofed fake Android UA (Mozlila/5.0 typo, Bulid/NRD90M typo) matching known scanner signature. OWASP CRS rules 913100 (scanner UA) + 949110 (anomaly score exceeded) triggered on product page request.
show less
Bad Web BotWeb App Attack
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.