This IP address has been reported a total of
269
times from
33 distinct
sources.
104.250.53.254 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show moreTriggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /english/himara-secretary-general-fire-reached-apocalyptic-proportions-and-spread-within-20-minutes/999691
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
FortiWeb WAF: 24 attacks detected. Threat Score: 8000. Types: Client Management(12), GEO IP(12). Ori ...
show moreFortiWeb WAF: 24 attacks detected. Threat Score: 8000. Types: Client Management(12), GEO IP(12). Origin: Singapore.
show less
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show moreAsking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: /wp-content/uploads/2017/01/picto-produits-benefices-pyx4-gestion-des-risques.png | 2026-09-14 05:11 UTC
show less
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /wp-content/uploads/2020 ...
show more[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /wp-content/uploads/2020/07/google_has_blocked_our_entire_domain_for_spamming-1.png via rule: /wp-content
show less
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show moreTriggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /kerko.php
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
LF_MODSEC: (mod_security) mod_security (id:10000003) triggered by 104.250.53.254 (SG/Singapore/-): 2 ...
show moreLF_MODSEC: (mod_security) mod_security (id:10000003) triggered by 104.250.53.254 (SG/Singapore/-): 2 in the last 3600 secs
show less
Repeated exploit attempts, for example: /hybridauth/window/OpenID?destination=community&destination_ ...
show moreRepeated exploit attempts, for example: /hybridauth/window/OpenID?destination=community&destination_error=comment/reply/2150%3F%23comment-form (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36")
show less
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /wp-content/uploads/2023 ...
show more[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /wp-content/uploads/2023/12/Edit-Users-And-Select-Email-Address-Virtualmin.png via rule: /wp-content
show less
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show moreAsking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: /blog | 2026-09-09 05:03 UTC
show less
Repeated exploit attempts, for example: /hybridauth/window/Twitter?destination=community&destination ...
show moreRepeated exploit attempts, for example: /hybridauth/window/Twitter?destination=community&destination_error=hybridauth/endpoint%3Fhauth_start%3DGoogle%26hauth_time%3D1643276648 (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36")
show less
Web App Attack
Showing 1 to
15
of 269 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ