Anonymous
2026-05-16 16:02:18
(3 weeks ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-04-25 04:48:12
(1 month ago)
185.132.187.76 - - [25/Apr/2026:07:48:10 +0300] "GET /wp-includes/images/smilies/about.php HTTP/1.1" ...
show more
185.132.187.76 - - [25/Apr/2026:07:48:10 +0300] "GET /wp-includes/images/smilies/about.php HTTP/1.1" 404 715 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:79.0) Gecko/20100101 Firefox/79.0"
185.132.187.76 - - [25/Apr/2026:07:48:11 +0300] "GET /wp-includes/js/crop/admin.php HTTP/1.1" 404 715 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3"
...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-04-24 22:41:59
(1 month ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 16:24:01
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 185.132.187.76 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 185.132.187.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 12:23:55.833022 2026] [security2:error] [pid 32034:tid 32034] [client 185.132.187.76:22867] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||uppermotradingco.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "uppermotradingco.com"] [uri "/restore/www.sql"] [unique_id "ab7GG41gJbjzYGz0tajO2gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
TechnoSolutions CL
2026-03-21 07:50:00
(2 months ago)
185.132.187.76 - - [21/Mar/2026:07:49:58 +0000] "GET //2021/wp-includes/wlwmanifest.xml HTTP/1.1" 40 ...
show more
185.132.187.76 - - [21/Mar/2026:07:49:58 +0000] "GET //2021/wp-includes/wlwmanifest.xml HTTP/1.1" 403 45 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
185.132.187.76 - - [21/Mar/2026:07:49:59 +0000] "GET //shop/wp-includes/wlwmanifest.xml HTTP/1.1" 403 45 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐พ
armandosaucedo.me
2026-03-19 07:05:58
(2 months ago)
185.132.187.76 - - [19/Mar/2026:07:05:44 +0000] "GET /old/directory.rar HTTP/1.1" 404 196 "-" "-"
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-16 23:39:28
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 185.132.187.76 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 185.132.187.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 16 19:39:24.409423 2026] [security2:error] [pid 1966535:tid 1966535] [client 185.132.187.76:43683] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kwtlaw.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kwtlaw.com"] [uri "/wallet.dat"] [unique_id "abiUrJRiWgcO3zUu9CKu_AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-03-11 10:30:44
(2 months ago)
Triggered Cloudflare WAF (firewallManaged) from BE.
Action taken: LOG
Protocol: HTTP/1.1 (HEAD metho ...
show more
Triggered Cloudflare WAF (firewallManaged) from BE.
Action taken: LOG
Protocol: HTTP/1.1 (HEAD method)
Endpoint: /back/sftp-config.json
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
poundawebsiteltd
2026-03-09 10:35:12
(3 months ago)
Web App Attack (ModSecurity Block). Evidence: beanietools.dev:80 185.132.187.76 - - [09/Mar/2026:10: ...
show more
Web App Attack (ModSecurity Block). Evidence: beanietools.dev:80 185.132.187.76 - - [09/Mar/2026:10:35:10 +0000] HEAD /restore/backup.sql HTTP/1.1 403 124 - -
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-01 04:43:57
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 185.132.187.76 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.132.187.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 23:43:52.449990 2026] [security2:error] [pid 4152:tid 4152] [client 185.132.187.76:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kryptonome.com"] [uri "/sftp-config.json"] [unique_id "aaPECCexDfg7myuyiRCjMQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-02-23 13:40:19
(3 months ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
consul.to
2026-02-22 15:45:07
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ช๐ธ
gnom4ik
2026-02-21 11:48:04
(3 months ago)
ban-reviewer auto report; ip=185.132.187.76; scenario=http:scan; verdict=valid_ban; confidence=0.85; ...
show more
ban-reviewer auto report; ip=185.132.187.76; scenario=http:scan; verdict=valid_ban; confidence=0.85; categories=14,15,18,22; active_decisions=1; lookback_decisions=1; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=IP flagged for 'Port Scan' (category 14) in abuseipdb; IP flagged for 'Hacking' (category 15) in abuseipdb; IP flagged for 'Brute-Force' (category 18) in abuseipdb; IP flagged for 'SSH' (category 22) in abuseipdb; Scan scenario detected via CAPI
show less
Port Scan
Hacking
Brute-Force
SSH
๐ฏ๐ต
Valhalla
2026-02-16 11:17:04
(3 months ago)
/backups/latest.zip
Hacking
Web App Attack
๐ณ๐ฟ
Antinson
2026-02-08 03:12:56
(4 months ago)
Scraping with a high error ratio and request rate
Bad Web Bot