Log in to view charts and search reports for this IP.
Log In
Top Reporter Countries (Last 60 Days)
Example preview
Report Categories (Last 60 Days)
Example preview
Reports Activity
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 3.249.95.241:
This IP address has been reported a total of
35
times from
30 distinct
sources.
3.249.95.241 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 6
reports;
Netherlands
with 6
reports;
United States of America
with 4
reports.
The most common categories in these recent reports were:
Web App Attack
22
times;
Brute-Force
12
times;
Bad Web Bot
11
times;
Hacking
8
times;
SSH
2
times;
Other
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: IE, Attack patterns: Word ...
show moreBlocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: IE, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
IncogNET WAF local CrowdSec decision. Scenario=crowdsecurity/http-bad-user-agent; Action=ban; Events ...
show moreIncogNET WAF local CrowdSec decision. Scenario=crowdsecurity/http-bad-user-agent; Action=ban; Events=2; Hosts=www.incognet.io; Paths=/wp-json,/z9x8c7v6b5-debug-trigger-www.incognet.io; Country=IE; ASN=16509 AMAZON-02
show less
Hacking
Anonymous
IncogNET WAF local CrowdSec decision. Scenario=crowdsecurity/http-probing; Action=ban; Events=11; Ho ...
show moreIncogNET WAF local CrowdSec decision. Scenario=crowdsecurity/http-probing; Action=ban; Events=11; Hosts=www.incognet.io; Paths=/account/login,/admin/login,/console,/forgot-password,/graphql,/img../.env,/register,/reset-password; Country=IE; ASN=16509 AMAZON-02
show less
Port Scan
Web App Attack
Anonymous
IncogNET WAF local CrowdSec decision. Scenario=crowdsecurity/http-sensitive-files; Action=ban; Event ...
show moreIncogNET WAF local CrowdSec decision. Scenario=crowdsecurity/http-sensitive-files; Action=ban; Events=5; Hosts=incognet.io; Paths=/.env.dev,/configuration.php.bak,/public/.env,/storage/.env,/wp/.env; Country=IE; ASN=16509 AMAZON-02
show less
cloudlinux2 fail2ban: 2026-08-27 21:44:10,374 fail2ban.filter [1775]: INFO [plesk-modsecu ...
show morecloudlinux2 fail2ban: 2026-08-27 21:44:10,374 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 109.245.34.118 - 2026-08-27 21:44:10cloudlinux2 fail2ban: 2026-08-27 21:45:41,172 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 109.245.34.118 - 2026-08-27 21:45:41cloudlinux2 fail2ban: 2026-08-27 21:46:05,050 fail2ban.actions [1775]: NOTICE [plesk-modsecurity] Unban 147.182.162.94cloudlinux2 fail2ban: 2026-08-27 21:46:57,600 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 3.249.95.241 - 2026-08-27 21:46:57cloudlinux2 fail2ban: 2026-08-27 21:47:00,316 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 109.245.34.118 - 2026-08-27 21:47:00cloudlinux2 fail2ban: 2026-08-27 21:47:05,612 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 3.249.95.241 - 2026-08-27 21:47:05cloudlinux2 fail2ban: 2026-08-27 21:47:00,424 fail2ban.actions [1775]: NOTICE [plesk-modsecurity] Ban 109.245.34.118cloudlinux2 fail2ban: 2026-08-27 21:47
show less
Brute-Force
Anonymous
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: IE, Attack patterns: Word ...
show moreBlocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: IE, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Malformed or malicious web request
3.249.95.241 - - [27/Aug/2026:18:44:56 +0200] "POST /graphql HTTP ...
show moreMalformed or malicious web request
3.249.95.241 - - [27/Aug/2026:18:44:56 +0200] "POST /graphql HTTP/2.0" 404 555 "https://hellgateaus.cyou" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Mobile Safari/537.36"
show less
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show moreProbing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.aws/credentials (+4 more) | 2026-08-27 15:49 UTC
show less
Hacking
Web App Attack
Anonymous
Bot / scanning and/or hacking attempts: GET /.env HTTP/2.0, [20/15] schedule: stream 39, GET /.gitla ...
show moreBot / scanning and/or hacking attempts: GET /.env HTTP/2.0, [20/15] schedule: stream 39, GET /.gitlab-ci.yml, GET /.git/config HTTP/2.0
show less