๐จ๐ฟ
Countryman
2026-03-02 19:12:00
(3 months ago)
repeated unauthorized connection attempts, host sweep, port scan
Port Scan
๐ฏ๐ต
shimizu
2026-02-28 15:00:01
(3 months ago)
1 times SMTP brute-force
Hacking
Brute-Force
๐ฆ๐ฑ
cheatmaster.store
2026-02-27 01:50:43
(3 months ago)
Automated report: This IP address has been identified as an active public open proxy.
Classification ...
show more
Automated report: This IP address has been identified as an active public open proxy.
Classification: Open Proxy | Spoofing | VPN/Anonymizer | Bad Web Bot.
Country: China
Threat level: High. This host is listed across multiple public proxy databases and poses a risk of abuse, credential stuffing, scraping, and spoofed traffic.
Reported by automated threat intelligence pipeline. Do not whitelist without manual verification.
show less
Web Spam
Port Scan
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2026-02-21 17:35:28
(3 months ago)
2026-02-21 18:35:28 (CET) ~ Blocked by abusescan risk assessment
Web App Attack
๐จ๐ฆ
1gz
2026-02-20 11:23:35
(3 months ago)
Triggered Cloudflare WAF (firewallCustom) from CN.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from CN.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /lifestyle/
UA: manager(+internet-surf)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ช๐ธ
el-brujo
2026-02-20 04:00:43
(3 months ago)
Cloudflare WAF: Request Path: /blackryubushido5seconds Request Query: Host: elhacker.net userAgent: ...
show more
Cloudflare WAF: Request Path: /blackryubushido5seconds Request Query: Host: elhacker.net userAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 Action: block Source: l7ddos ASN Description: CHINANET-IDC-GD China Telecom Group Country: CN Method: GET Timestamp: 2026-02-20T04:00:43Z ruleId: b1ca921c11ab473da3bb04b54b1a2f09. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ช๐ธ
el-brujo
2026-02-20 03:59:09
(3 months ago)
Cloudflare WAF: Request Path: /blackryubushido5seconds Request Query: Host: elhacker.net userAgent: ...
show more
Cloudflare WAF: Request Path: /blackryubushido5seconds Request Query: Host: elhacker.net userAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 Action: block Source: l7ddos ASN Description: CHINANET-IDC-GD China Telecom Group Country: CN Method: GET Timestamp: 2026-02-20T03:59:09Z ruleId: b1ca921c11ab473da3bb04b54b1a2f09. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ต๐ฑ
sefinek.net
2026-02-19 02:22:59
(3 months ago)
Triggered Cloudflare WAF (firewallCustom) from CN.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (G ...
show more
Triggered Cloudflare WAF (firewallCustom) from CN.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (GET) | Endpoint: /genshin-stella-mod | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Edg/114.0.1264.71 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฎ๐ณ
liveaspankaj
2026-02-14 11:29:11
(4 months ago)
DDoS attack: 65 requests in 5m (GET / or repair.php).
DDoS Attack
Anonymous
2026-02-12 14:59:48
(4 months ago)
SMTP brute force - auth failed
Brute-Force
Exploited Host
๐ฎ๐ณ
liveaspankaj
2026-02-12 12:04:28
(4 months ago)
DDoS attack on learngeeta.com: 180 requests of GET / HTTP/1.1 over plain HTTP with no referrer. Auto ...
show more
DDoS attack on learngeeta.com: 180 requests of GET / HTTP/1.1 over plain HTTP with no referrer. Automated bot attack with randomized User-Agents (outdated Chrome 127-129).
show less
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-02-11 11:02:37
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 103.236.64.247 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 103.236.64.247 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 06:02:29.465674 2026] [security2:error] [pid 2427:tid 2427] [client 103.236.64.247:58244] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.designamb.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.designamb.com"] [uri "/"] [unique_id "aYxhxTwXlV5x05ImW1UuEAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
IROK
2026-02-10 18:20:13
(4 months ago)
Firewall Blocked - Unauthorized Port Scanning
...
Port Scan
๐ฎ๐น
VHosting
2026-02-09 03:11:45
(4 months ago)
Detected mail brute force attack from 4 different servers
Brute-Force
๐ต๐น
tiagozip
2022-10-06 14:56:52
(3 years ago)
open proxy
Open Proxy