๐ณ๐ฑ
tr1n
2026-09-01 21:11:43
(22 hours ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action: MANAGED_CHALLENGE | ASN: 24961 (WIIT AG) ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action: MANAGED_CHALLENGE | ASN: 24961 (WIIT AG) | Protocol: HTTP/2 (GET) | Endpoint: / | Timestamp: 2026-09-01T21:11:43Z | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Safari/537.36 Edg/91.0.864.54
show less
Bad Web Bot
๐ญ๐บ
kranem
2026-08-31 15:00:12
(2 days ago)
Triggered Cloudflare WAF from NL.
Action taken: LINK_MAZE_INJECTED
ASN: 24961 (WIIT AG)
Protocol: HT ...
show more
Triggered Cloudflare WAF from NL.
Action taken: LINK_MAZE_INJECTED
ASN: 24961 (WIIT AG)
Protocol: HTTP/2 (GET method)
Endpoint: /
Timestamp: 2026-08-31T14:09:34Z
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Safari/537.36 Edg/91.0.864.54
show less
Bad Web Bot
๐ฉ๐ช
Reinhard
2026-08-30 21:38:52
(2 days ago)
Unknown activity, but too many attacks with too many users.
Hacking
๐ฉ๐ช
HandyTreff.de
2026-08-27 21:59:50
(5 days ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -32.318 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -32.318 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.11
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-27 10:25:53
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 2001:4ba0:cafe:c13::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:4ba0:cafe:c13::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 06:25:47.897527 2026] [security2:error] [pid 29494:tid 29494] [client 2001:4ba0:cafe:c13::1:55010] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.azcrittergetter.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.azcrittergetter.com"] [uri "/csfitz.com"] [unique_id "apAQq95brHvEb35FtEw-yQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
lakered
2026-08-21 01:19:18
(1 week ago)
Detectors: [NGINX] | Reasons: Nginx: Repeat offender returning to default/inactive vhost after previ ...
show more
Detectors: [NGINX] | Reasons: Nginx: Repeat offender returning to default/inactive vhost after previous ban | Evidence: Persistent-Slow-Scanner (Strikes: 5), TCP/IP-Spoofing-Detected (bad_sw: 2), Repeat-Offender (Past Bans: 3) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Safari/537.36 Edg/91.0.864.54 | TCP Fingerprint: Unknown (Link:PPPoE, Uptime:20728m)
show less
Port Scan
Web App Attack
๐บ๐ธ
cwytech
2026-08-15 20:24:34
(2 weeks ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-geofence-sus.
Bad Web Bot
Web App Attack
๐ญ๐บ
kranem
2026-08-14 06:00:13
(2 weeks ago)
Triggered Cloudflare WAF from NL.
Action taken: LINK_MAZE_INJECTED
ASN: 24961 (WIIT AG)
Protocol: HT ...
show more
Triggered Cloudflare WAF from NL.
Action taken: LINK_MAZE_INJECTED
ASN: 24961 (WIIT AG)
Protocol: HTTP/2 (GET method)
Endpoint: /
Timestamp: 2026-08-14T05:12:52Z
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Safari/537.36 Edg/91.0.864.54
show less
Bad Web Bot
๐ซ๐ฎ
as211431.net
2026-08-11 02:48:46
(3 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Safari/537.36 Edg/91.0.864.54
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
Lezetho
2026-08-09 10:00:12
(3 weeks ago)
DDoS, WebSpam, Web Attack, and Brute-force blocked by Cloudflare
DDoS Attack
Email Spam
Hacking
Brute-Force
๐จ๐ฆ
lakered
2026-08-08 17:33:56
(3 weeks ago)
Detectors: [NGINX] | Reasons: Nginx: Default server trap hit | Evidence: Persistent-Slow-Scanner (St ...
show more
Detectors: [NGINX] | Reasons: Nginx: Default server trap hit | Evidence: Persistent-Slow-Scanner (Strikes: 4), Repeat-Offender (Past Bans: 2) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Safari/537.36 Edg/91.0.864.54
show less
Port Scan
Exploited Host
๐ฉ๐ช
Reinhard
2026-08-06 20:27:03
(3 weeks ago)
Unknown activity, but too many attacks with too many users.
Hacking
๐บ๐ธ
Lezetho
2026-08-05 05:00:21
(4 weeks ago)
DDoS, WebSpam, Web Attack, and Brute-force blocked by Cloudflare
DDoS Attack
Email Spam
Hacking
Brute-Force
๐บ๐ธ
Lezetho
2026-08-03 00:01:39
(4 weeks ago)
DDoS, WebSpam, Web Attack, and Brute-force blocked by Cloudflare
DDoS Attack
Email Spam
Hacking
Brute-Force
๐ต๐ฑ
sefinek.net
2026-07-28 15:15:41
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action: MANAGED_CHALLENGE | Protocol: HTTP/2 (GET ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action: MANAGED_CHALLENGE | Protocol: HTTP/2 (GET) | Endpoint: / | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Safari/537.36 Edg/91.0.864.54 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot