๐ซ๐ท
masterguru
2026-06-17 13:56:24
(1 month ago)
Restricted File Access Attempt. Matched phrase "config.php" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐ฉ๐ช
Admin-Gito
2026-06-17 13:09:12
(1 month ago)
185.221.132.214 - - [17/Jun/2026:14:22:30 +0200] "GET /wp-includes/style-engine/worksec.php HTTP/1.1 ...
show more
185.221.132.214 - - [17/Jun/2026:14:22:30 +0200] "GET /wp-includes/style-engine/worksec.php HTTP/1.1" 404 290711 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
185.221.132.214 - - [17/Jun/2026:14:22:51 +0200] "GET /wp-includes/IXR/fix.php7 HTTP/1.1" 404 290699 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95"
185.221.132.214 - - [17/Jun/2026:14:22:53 +0200] "GET /wp-includes/widgets/dyqvcfqv.php HTTP/1.1" 404 290714 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0"
185.221.132.214 - - [17/Jun/2026:14:22:55 +0200] "GET /wp-includes/images/smilies/about.php HTTP/1.1" 404 290718 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36"
185.221.132.214 - - [17/Jun/2026:14:22:56 +0200] "GET /wp-includes/js/crop/admin.php HTTP/1.1" 404
...
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-17 04:11:56
(1 month ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-05-02 03:13:59
(2 months ago)
(mod_security) mod_security triggered on hostname [redacted] 185.221.132.214 (LU/Luxembourg/-)
SQL Injection
Anonymous
2026-04-12 11:03:20
(3 months ago)
Web App Attack
๐น๐ท
rtbh.com.tr
2026-03-24 20:12:15
(3 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐น๐ท
rtbh.com.tr
2026-03-23 20:12:13
(3 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ฆ๐บ
nzhost.co.nz
2026-03-22 12:48:32
(4 months ago)
$f2bV_matches
Hacking
Brute-Force
๐บ๐ธ
ipblock.com
2026-03-22 10:13:00
(4 months ago)
IPBlock protected site ID [4678-sl].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-03-22 09:27:02
(4 months ago)
10 attempts against mh-misc-ban on space
Web App Attack
๐ณ๐ฑ
Savvii
2026-03-22 07:08:21
(4 months ago)
10 attempts against mh-misc-ban on lead
Web App Attack
๐จ๐ญ
lufi
2026-03-22 06:59:37
(4 months ago)
2026-03-22T07:59:37+01:00 lufischer04 ids442 2026-03-22 07:59:37 185.221.132.214: blacklisted Patter ...
show more
2026-03-22T07:59:37+01:00 lufischer04 ids442 2026-03-22 07:59:37 185.221.132.214: blacklisted Pattern: wp-includes/
...
show less
Web Spam
Brute-Force
Hacking
Web App Attack
๐ฌ๐ง
pinguin
2026-03-15 05:46:18
(4 months ago)
Triggered Cloudflare WAF (linkMaze) from LU.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/2 (HEAD ...
show more
Triggered Cloudflare WAF (linkMaze) from LU.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/2 (HEAD method)
Endpoint: /backups/backup.gz
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-14 02:51:40
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 185.221.132.214 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 185.221.132.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 22:51:35.170259 2026] [security2:error] [pid 10529:tid 10529] [client 185.221.132.214:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sportsbookcommission.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sportsbookcommission.com"] [uri "/old/www.sql"] [unique_id "abTNNwGxjHG_6s_EwdKOGgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-13 19:16:06
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 185.221.132.214 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 185.221.132.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 15:15:59.453239 2026] [security2:error] [pid 26816:tid 26832] [client 185.221.132.214:65289] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bluetigertees.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bluetigertees.com"] [uri "/bak/dump.sql"] [unique_id "abRib487uVQX6Zaz06gVzQAAAcE"]
show less
Brute-Force
Bad Web Bot
Web App Attack