Anonymous
2026-06-11 17:30:58
(2 days ago)
Botnet activity. Attribution: Angara Technologies Group / mikhail-smirnov-79830322 | Attack Signatur ...
show more
Botnet activity. Attribution: Angara Technologies Group / mikhail-smirnov-79830322 | Attack Signature Blocked: /wishlist/index/add/product/10970/form_key/i7dXpB8HWZFSaF4J/ | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like G...
show less
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-06-10 03:01:04
(3 days ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after obfuscated redirect. Vegas Security
DDoS Attack
Hacking
Exploited Host
๐บ๐ธ
stechusa
2026-05-27 09:15:23
(2 weeks ago)
[Askari] | country=KE | Behavior: Targeting specific pages, Concurrent page load during attack, HTTP ...
show more
[Askari] | country=KE | Behavior: Targeting specific pages, Concurrent page load during attack, HTTP/1.1 over TLS
show less
Bad Web Bot
DDoS Attack
๐บ๐ธ
stechusa
2026-05-27 09:15:23
(2 weeks ago)
ELEVATED_THREAT | country=KE | ASN=EDN-AS | AbuseIPDB=30% | 19 IPs targeting /category/light-fixture ...
show more
ELEVATED_THREAT | country=KE | ASN=EDN-AS | AbuseIPDB=30% | 19 IPs targeting /category/light-fixtures.html | Facet request during elevated threat (facet_ratio=0.79, unique_ips=226) | HTTP/1.1 over TLS (elevated=True)
show less
Bad Web Bot
DDoS Attack
๐ฉ๐ช
SMARTNET
2026-05-27 06:03:53
(2 weeks ago)
Aisuru(Mirai variant) DDoS | Incident ID: f9eee327-63b9-4c70-8845-0c5f5dde9bdb
DDoS Attack
๐บ๐ธ
kosada.com
2026-05-19 16:25:39
(3 weeks ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
๐บ๐ธ
MPL
2026-04-24 11:19:30
(1 month ago)
tcp/17001 (6 or more attempts)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-20 06:12:28
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 102.220.12.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 102.220.12.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 20 02:12:18.857461 2026] [security2:error] [pid 2634002:tid 2634002] [client 102.220.12.94:58928] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||med-engineering.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "med-engineering.com"] [uri "/400dt.com"] [unique_id "aeXDwuwO0ZkpKOYtVXtLsAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-18 09:23:21
(1 month ago)
Automated bot traffic โ residential proxy, fake browser fingerprint. UA="Mozilla/5.0 (Windows NT 10. ...
show more
Automated bot traffic โ residential proxy, fake browser fingerprint. UA="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/111.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐ธ๐ฌ
mypatricks
2026-04-13 11:50:48
(2 months ago)
102.220.12.94 | Port: 13963 | DNS: 102.220.12.94 2026-04-13T19:50:47+08:00 Africa/Nairobi | FETCH Sp ...
show more
102.220.12.94 | Port: 13963 | DNS: 102.220.12.94 2026-04-13T19:50:47+08:00 Africa/Nairobi | FETCH Sproofing Activity Detetced. | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 HTTP/1.1 443 GET | URL: /?999ddcae98dbfedeaeb=674&1754792435 | Ref: - | Country: KE/Kenya/+03:00 IP City: Ruiru 9eba41506eb3e1a6-MRS/Marseille, France 1 hits/0 secs Robots 2
show less
Brute-Force
Web App Attack
Blog Spam
Web Spam
Exploited Host
๐บ๐ธ
MPL
2026-04-03 20:38:12
(2 months ago)
tcp/52869 (2 or more attempts)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-03 05:13:02
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 102.220.12.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 102.220.12.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 01:12:55.831555 2026] [security2:error] [pid 5176:tid 5176] [client 102.220.12.94:34682] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.phantomkennels.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.phantomkennels.com"] [uri "/[email protected] "] [unique_id "ac9MV66b2sTukthKAc7A1QAAAAs"], referer: https://www.phantomkennels.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
quilla
2026-04-03 03:20:35
(2 months ago)
Botnet infected device observed in honeypot (Vector: TCP)
DDoS Attack
๐บ๐ธ
xmission.com
2026-03-23 10:06:48
(2 months ago)
Blocked by UFW (TCP on 9101)
Source port: 50984
TTL: 104
Packet length: 52
TOS: 0x08
This report (f ...
show more
Blocked by UFW (TCP on 9101)
Source port: 50984
TTL: 104
Packet length: 52
TOS: 0x08
This report (for 102.220.12.94) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
matt
2026-03-04 00:43:17
(3 months ago)
DDOS attack with query parameters attempting to overload WordPress site.
DDoS Attack