๐บ๐ธ
mnsf
2026-06-18 01:10:13
(2 months ago)
Request Overload (120)
Brute-Force
Web App Attack
๐ฉ๐ช
Admin-Gito
2026-06-17 13:39:21
(2 months ago)
185.221.132.212 - - [17/Jun/2026:14:44:49 +0200] "GET /wp-includes/sitemaps/providers/ultra.php HTTP ...
show more
185.221.132.212 - - [17/Jun/2026:14:44:49 +0200] "GET /wp-includes/sitemaps/providers/ultra.php HTTP/1.1" 404 290753 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3"
185.221.132.212 - - [17/Jun/2026:14:44:56 +0200] "GET /wp-includes/css/dist/preferences/wp-login.php HTTP/1.1" 404 290720 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36"
185.221.132.212 - - [17/Jun/2026:14:45:00 +0200] "GET /wp-includes/phpmailer/phpmailer.php HTTP/1.1" 404 290710 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36"
185.221.132.212 - - [17/Jun/2026:14:45:12 +0200] "GET /wp-includes/blocks/latest-comments/template-loader.php HTTP/1.1" 404 290736 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36"
185.221.132.212 - - [17/Jun/2026:14:
...
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-17 04:11:39
(2 months ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-05-02 03:59:01
(3 months ago)
(mod_security) mod_security triggered on hostname [redacted] 185.221.132.212 (LU/Luxembourg/-)
SQL Injection
๐ณ๐ฟ
Antinson
2026-05-02 00:58:14
(3 months ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐บ๐ธ
threatintelligence_bvc
2026-04-14 01:48:08
(4 months ago)
Brute-Force
Anonymous
2026-04-12 11:02:45
(4 months ago)
Web App Attack
๐ฎ๐น
NonOggiCaroMio
2026-03-22 12:15:05
(5 months ago)
Arruso ca si: crowdsecurity/http-probing
Brute-Force
๐ต๐ฑ
Kitki30.com
2026-03-22 09:51:05
(5 months ago)
HTTP Probing. Log: 185.221.132.212 - - [22/Mar/2026:10:51:04 +0100] "GET //xmlrpc.php?rsd HTTP/1.1" ...
show more
HTTP Probing. Log: 185.221.132.212 - - [22/Mar/2026:10:51:04 +0100] "GET //xmlrpc.php?rsd HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-03-15 05:46:20
(5 months ago)
Triggered Cloudflare WAF (linkMaze) from LU.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/2 (HEAD ...
show more
Triggered Cloudflare WAF (linkMaze) from LU.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/2 (HEAD method)
Endpoint: /backups/backup.sql.gz
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-14 06:39:13
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 185.221.132.212 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 185.221.132.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 02:39:05.176558 2026] [security2:error] [pid 27058:tid 27058] [client 185.221.132.212:60727] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hodlmoser.com|F|2"] [data ".com.sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hodlmoser.com"] [uri "/hodlmoser.com.sql"] [unique_id "abUCiY7pd8F9nS9qkc8cnAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-14 03:02:07
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 185.221.132.212 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 185.221.132.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 23:02:04.346293 2026] [security2:error] [pid 19022:tid 19022] [client 185.221.132.212:45885] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||usbea.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "usbea.com"] [uri "/old/backup.sql"] [unique_id "abTPrBSgGzYu4jd5hP5zVQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mikekarl
2026-03-13 23:03:18
(5 months ago)
Empty or bad user-agent.
Bad Web Bot
๐ฎ๐น
alph44
2026-03-08 07:50:39
(5 months ago)
(smtpauth) Failed SMTP AUTH login from 185.221.132.212 (LU/Luxembourg/-): 5 in the last 3600 secs; P ...
show more
(smtpauth) Failed SMTP AUTH login from 185.221.132.212 (LU/Luxembourg/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_SMTPAUTH; Logs:
show less
Brute-Force
๐บ๐ธ
ph
2026-03-04 06:19:23
(5 months ago)
Bad web bot attempting to run xmlrpc.php on non-WP site
Hacking
Bad Web Bot
Web App Attack