This IP address has been reported a total of
438
times from
26 distinct
sources.
185.15.56.29 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[MonSep2101:18:27.1628952026][security2:error][pid2690339:tid2690433][client185.15.56.29:0]ModSecuri ...
show more[MonSep2101:18:27.1628952026][security2:error][pid2690339:tid2690433][client185.15.56.29:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"autoeuro.lv\"][uri\"/zinas/autosports/slegelmilha-komanda-super-trofeo-debija-monca-izcina-12-vietu-873\"][unique_id\"arBpw01rRvzI0McN9AOJ7AAAAQU\"]
show less
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show moreAsking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: HEAD (+1 more) | path: /patrimoine.html | 2026-09-20 02:29 UTC
show less
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show moreAsking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: HEAD (+1 more) | path: /patrimoine.html | ua: IABot/2.0 (+https://meta.wikimedia.org/wiki/InternetArchiveBot/FAQ_for_sysadmins) (Checking if link from Wikipedia is broken and | 2026-09-14 04:01 UTC
show less
[SunSep1308:54:24.8118942026][security2:error][pid81023:tid81126][client185.15.56.29:0]ModSecurity:A ...
show more[SunSep1308:54:24.8118942026][security2:error][pid81023:tid81126][client185.15.56.29:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"autoeuro.lv\"][uri\"/zinas/autosports/slegelmilha-komanda-super-trofeo-debija-monca-izcina-12-vietu-873\"][unique_id\"aqZIoHcRpC2f3HgT95D-zQAAARI\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
"Security violation, excess traffic against library/education infrastructure"
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show moreAsking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: HEAD (+1 more) | path: /patrimoine.html | ua: IABot/2.0 (+https://meta.wikimedia.org/wiki/InternetArchiveBot/FAQ_for_sysadmins) (Checking if link from Wikipedia is broken and | 2026-09-11 02:40 UTC
show less
[Tue Sep 08 23:40:51.351025 2026] [php:error] [pid 261652] [client 185.15.56.29:12145] script '/var/ ...
show more[Tue Sep 08 23:40:51.351025 2026] [php:error] [pid 261652] [client 185.15.56.29:12145] script '/var/www/html/page.php' not found or unable to stat
...
show less
[06/Sep/2026:07:43:41 +0300] -- 185.15.56.29 Ban reason: Scanner [CMS_GENERIC] | Request: HEAD /wp-c ...
show more[06/Sep/2026:07:43:41 +0300] -- 185.15.56.29 Ban reason: Scanner [CMS_GENERIC] | Request: HEAD /wp-content/uploads/sites/58/2017/05/20-68.pdf HTTP/1.1
show less
[SunSep0602:18:12.3654742026][security2:error][pid2192272:tid2192324][client185.15.56.29:0]ModSecuri ...
show more[SunSep0602:18:12.3654742026][security2:error][pid2192272:tid2192324][client185.15.56.29:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"autoeuro.lv\"][uri\"/zinas/autosports/slegelmilha-komanda-super-trofeo-debija-monca-izcina-12-vietu-873\"][unique_id\"apyxRDlVRKCQskwIt_lYjwAAAU4\"]
show less
HTTP application-layer DoS / botnet traffic from 185.15.56.29: repeated high-cost dynamic page and f ...
show moreHTTP application-layer DoS / botnet traffic from 185.15.56.29: repeated high-cost dynamic page and feed requests (profile/tag views, forums, tracker, RSS) at abusive rates via completed TCP/HTTPS. Likely compromised end-user host.
show less