๐บ๐ธ
r3versedk
2026-03-15 19:13:54
(4 months ago)
๐ก๏ธ Automated Threat Report from maxjensen.dk
๐ฏ Attack Type: Botnet Fingerprint
๐จ Severity: CRITICAL ...
show more
๐ก๏ธ Automated Threat Report from maxjensen.dk
๐ฏ Attack Type: Botnet Fingerprint
๐จ Severity: CRITICAL
๐ Threat Score: 95/100
๐ Total Attacks: 408 (database verified, seen over today)
๐ Peak Score: 95/100
๐ฏ Common Types: Botnet Fingerprint(1x)
๐ Fingerprint: 9f96b00ce11bc787
๐ค AI/ML: ๐ค Multi-Model Consensus (neural-network, q-learning, gpt) - ๐ง NN (55%): block (99.4%) | ๐ฎ QL (23%): block (75.0%) | ๐ค Claude (23%): monitor (70.0%) | โ๏ธ dynamic+boosted weights...
Detected: 2026-03-15T19:13:54.033Z
show less
Bad Web Bot
๐ฌ๐ง
poundawebsiteltd
2026-03-14 22:56:59
(4 months ago)
Web App Attack (ModSecurity Block). Evidence: beanietools.dev:80 66.56.86.1 - - [14/Mar/2026:22:56:5 ...
show more
Web App Attack (ModSecurity Block). Evidence: beanietools.dev:80 66.56.86.1 - - [14/Mar/2026:22:56:57 +0000] HEAD /backup/wallet.dat HTTP/1.1 403 124 - -
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-12 11:43:47
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 66.56.86.1 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 66.56.86.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 12 07:43:39.675157 2026] [security2:error] [pid 16010:tid 16031] [client 66.56.86.1:53075] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||liquido.cocoonprojects.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "liquido.cocoonprojects.com"] [uri "/back/backup.sql"] [unique_id "abKm653fRAi7PkIPqulDNQAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-04 16:03:05
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 66.56.86.1 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 66.56.86.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 04 11:02:57.512196 2026] [security2:error] [pid 5011:tid 5011] [client 66.56.86.1:47547] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.spectorworld.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.spectorworld.com"] [uri "/back/dump.sql"] [unique_id "aahXsQ3GBiy6RVhP6SMg0QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-01 01:30:17
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 66.56.86.1 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 66.56.86.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 20:30:13.028270 2026] [security2:error] [pid 16975:tid 16975] [client 66.56.86.1:25401] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mapleleaf-marketing.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mapleleaf-marketing.com"] [uri "/mysql.sql"] [unique_id "aaOWpaD5XzEo4YC38-MVNAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-02-14 01:15:23
(5 months ago)
Triggered Cloudflare WAF (firewallManaged) from SK.
Action taken: LOG
Protocol: HTTP/2 (HEAD method) ...
show more
Triggered Cloudflare WAF (firewallManaged) from SK.
Action taken: LOG
Protocol: HTTP/2 (HEAD method)
Endpoint: /back/www.gz
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-07 08:57:53
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 66.56.86.1 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 66.56.86.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 07 03:57:48.629572 2026] [security2:error] [pid 16312:tid 16312] [client 66.56.86.1:63067] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cryptofructo.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cryptofructo.com"] [uri "/restore/backup.sql"] [unique_id "aYb-jPOTRPeKffk1iIX_fQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Axel
2026-02-04 16:30:11
(5 months ago)
Blocked by ModSecurity. Rule ID: 210730 Message: COMODO WAF: URL file extension is restricted by pol ...
show more
Blocked by ModSecurity. Rule ID: 210730 Message: COMODO WAF: URL file extension is restricted by policy||ipvi.network|F|2 Phase: 2 Severity: CRITICAL URI: /old/dump.sql
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-26 11:43:36
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 66.56.86.1 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 66.56.86.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 26 06:43:32.340266 2026] [security2:error] [pid 4782:tid 4782] [client 66.56.86.1:55425] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bitcointoolfair.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bitcointoolfair.com"] [uri "/backups/sql.sql"] [unique_id "aXdTZIRpcIh2Nku_ohf3EwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-25 03:13:05
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 66.56.86.1 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 66.56.86.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 24 22:12:56.923228 2026] [security2:error] [pid 9195:tid 9195] [client 66.56.86.1:20389] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dudleyanddudley.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dudleyanddudley.com"] [uri "/restore/mysql.sql"] [unique_id "aXWKOHAAbIGHwiB66hG0VAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 09:03:51
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 66.56.86.1 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 66.56.86.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 04:03:44.590288 2026] [security2:error] [pid 2949:tid 2949] [client 66.56.86.1:20697] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||crypto-stamps.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "crypto-stamps.com"] [uri "/old/dump.sql"] [unique_id "aXHn8DyoUCdijJFAdoToVwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Penny Packer
2026-01-22 02:43:34
(5 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-21 13:54:07
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 66.56.86.1 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 66.56.86.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 21 08:54:04.033167 2026] [security2:error] [pid 20154:tid 20154] [client 66.56.86.1:42701] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bwill.dev|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bwill.dev"] [uri "/wallet.dat"] [unique_id "aXDafErYj4djLbNZwmNxGgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-13 18:39:08
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 66.56.86.1 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 66.56.86.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 13 13:39:03.328438 2026] [security2:error] [pid 22362:tid 22371] [client 66.56.86.1:23699] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "siestakeybch.com"] [uri "/back/sftp-config.json"] [unique_id "aWaRR-OgCi08OcvDUpv9eAAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-01-06 08:14:37
(6 months ago)
F2B - Malicious activity detected. URL Probing.
Hacking
Bad Web Bot
Web App Attack