This IP address has been reported a total of
38
times from
30 distinct
sources.
185.248.85.21 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[SunJun1421:50:26.6567612026][security2:error][pid3694095:tid3694253][client185.248.85.21:0]ModSecur ...
show more[SunJun1421:50:26.6567612026][security2:error][pid3694095:tid3694253][client185.248.85.21:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.fimka-icp.com\"][uri\"/api/file/formimage\"][unique_id\"ai8GAmhQC0-kvAhF4A0FrwAAABE\"]
show less
[FeelAutom Auto-Ban] AI Analyst: Tentatives rรฉpรฉtรฉes d'exploitation de UEditor via des chemins PHP s ...
show more[FeelAutom Auto-Ban] AI Analyst: Tentatives rรฉpรฉtรฉes d'exploitation de UEditor via des chemins PHP suspects (5 requรชtes)
show less
[FriJun1217:07:21.4617782026][security2:error][pid701246:tid701769][client185.248.85.21:0]ModSecurit ...
show more[FriJun1217:07:21.4617782026][security2:error][pid701246:tid701769][client185.248.85.21:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"aid-web.com\"][uri\"/\"][unique_id\"aiwgqZg1lO-IrYuMcSvnbAAAAQ0\"]
show less
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 185.248.85.21 (GB/United Kingdom/-): ...
show moreLF_MODSEC: (mod_security) mod_security (id:949110) triggered by 185.248.85.21 (GB/United Kingdom/-): 1 in the last 3600 secs
show less
[WedJun1004:56:02.4698872026][security2:error][pid4384:tid4730][client185.248.85.21:0]ModSecurity:Ac ...
show more[WedJun1004:56:02.4698872026][security2:error][pid4384:tid4730][client185.248.85.21:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"4-server.com\"][uri\"/\"][unique_id\"aijSQky4lRzPf3iNk15GigAAAQI\"]
show less
ThreatBook Intelligence: Zombie,Scanner more details on https://threatbook.io/ip/185.248.85.21
2026- ...
show moreThreatBook Intelligence: Zombie,Scanner more details on https://threatbook.io/ip/185.248.85.21
2026-04-04 18:54:32 /
2026-04-04 18:54:21 /
2026-04-04 18:54:22 /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php,{"body":"\u003c?php echo \"NightAgent\";?\u003e","content_type":"","header":{"Accept":["*/*"],"Accept-Encoding":["gzip, deflate"],"Connection":["keep-alive"],"Content-Length":["26"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"]},"host":"43.133.146.120","method":"POST","proto":"HTTP/1.1","remote_addr":"185.248.85.21:37798","status_code":200,"url":"/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36"}
show less
Tanner Honeypot hit, Event Type: , HTTP Method: POST, User Agent: , URI: /vendor/phpunit/phpunit/src ...
show moreTanner Honeypot hit, Event Type: , HTTP Method: POST, User Agent: , URI: /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
show less
(mod_security) mod_security (id:949110) triggered by 185.248.85.21 (GB/United Kingdom/-): N in the l ...
show more(mod_security) mod_security (id:949110) triggered by 185.248.85.21 (GB/United Kingdom/-): N in the last X secs
show less
Web App Attack
Showing 1 to
15
of 38 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ