๐ท๐ด
Fn4ticHz
2026-05-30 15:42:10
(1 week ago)
DDoS blocked via ZeroGuard.ID
DDoS Attack
Exploited Host
๐ซ๐ท
MatStef132
2026-05-22 14:05:57
(2 weeks ago)
MatShield L7: blocked on mathost.eu (ua-quarantined)
Bad Web Bot
๐ณ๐ฑ
ByeByte API
2026-05-16 20:05:42
(3 weeks ago)
byebyte.space auth: Rate-limit escalation at 2026-05-16T20:05:42Z: 5 rejections in 300s. Firewall au ...
show more
byebyte.space auth: Rate-limit escalation at 2026-05-16T20:05:42Z: 5 rejections in 300s. Firewall auto-banned IP for 900s. UA: 'Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36'. Accept-Language: 'en-US,en;q=0.9'. Accept-Encoding: 'gzip, br'. Country (CF): PK. TLS info: {"scheme":"https"}.
show less
Web App Attack
DDoS Attack
๐ท๐ด
Fn4ticHz
2026-05-09 14:14:29
(4 weeks ago)
Repeated DDoS targeted -- ZeroGuard X ManagedSRV
DDoS Attack
Exploited Host
๐น๐ญ
anurak.org
2026-04-29 04:50:00
(1 month ago)
HTTP DDOS attack of 1.98k requests
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 14:37:49
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 116.0.53.34 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 116.0.53.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 10:37:41.165101 2026] [security2:error] [pid 21305:tid 21314] [client 116.0.53.34:41400] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bbpuertadelsol.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bbpuertadelsol.com"] [uri "/greenpanelscr.com"] [unique_id "adEiNfY3mOCX6UCzJRkliAAAAIY"], referer: https://bbpuertadelsol.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-02-22 18:30:03
(3 months ago)
4810 limiting connections by zone (2h48m59s)
DDoS Attack
๐ณ๐ฑ
ConsulHosting
2026-02-15 16:03:59
(3 months ago)
Part of an HTTP Flood DDoS attack and had sent at least 2 requests.
DDoS Attack
Exploited Host
Anonymous
2026-02-09 01:39:25
(3 months ago)
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show more
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in printer-friendly.asp
show less
Bad Web Bot
Exploited Host
๐บ๐ธ
COMPLEX
2026-01-26 01:07:23
(4 months ago)
Triggered Cloudflare WAF (l7ddos) from PK.
Action taken: BLOCK
ASN: undefined (undefined)
Protocol: ...
show more
Triggered Cloudflare WAF (l7ddos) from PK.
Action taken: BLOCK
ASN: undefined (undefined)
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Android 12; Mobile; rv:146.0) Gecko/146.0 Firefox/146.0
show less
DDoS Attack
Bad Web Bot
๐จ๐ญ
Modules
2026-01-17 06:42:47
(4 months ago)
Open proxy http://116.0.53.34:8080 (RT:4925ms,Loc:Pakistan,ASN:AS24435)
Open Proxy
๐ฎ๐ณ
Bharat Datacenter
2026-01-11 14:01:37
(4 months ago)
1: date=2026-01-11 time=19:30:11 eventtime=1768140012063431550 tz="+0530" logid="0720018432" type="u ...
show more
1: date=2026-01-11 time=19:30:11 eventtime=1768140012063431550 tz="+0530" logid="0720018432" type="utm" subtype="anomaly" eventtype="anomaly" level="alert" vd="root" severity="critical" srcip=116.0.53.34 srccountry="Pakistan" dstip=157.10.99.34 dstcountry="India" srcintf="x2" srcintfrole="wan" sessionid=0 action="clear_session" proto=6 service="HTTPS" count=114401 attack="tcp_syn_flood" srcport=41796 dstport=443 attackid=100663396 policyid=1 policytype="DoS-policy" ref="http://www.fortinet.com/ids/VID100663396" msg="anomaly: tcp_syn_flood, 3276 > threshold 2000, repeats 114401 times since last log, pps 3308 of prior second" crscore=50 craction=4096 crlevel="critical"
show less
Brute-Force
๐ฎ๐น
VHosting
2025-12-30 13:28:21
(5 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
๐จ๐ญ
backslash
2025-12-28 04:30:13
(5 months ago)
block ruleset 1E8A9918B1655D0828F2EEF05553DD2681055C9A
Web Spam
๐จ๐ฆ
1gz
2025-12-14 21:26:13
(5 months ago)
Triggered Cloudflare WAF (firewallManaged) from PK.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from PK.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /nigger
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot