|
๐บ๐ธ
r3versedk
|
|
๐ก๏ธ Automated Threat Report from maxjensen.dk
๐ฏ Attack Type: Botnet Fingerprint
๐จ Severity: CRITICAL ...
show more
๐ก๏ธ Automated Threat Report from maxjensen.dk
๐ฏ Attack Type: Botnet Fingerprint
๐จ Severity: CRITICAL
๐ Threat Score: 95/100
๐ Total Attacks: 404 (database verified, seen over today)
๐ Peak Score: 95/100
๐ฏ Common Types: Botnet Fingerprint(1x)
๐ Fingerprint: 9f96b00ce11bc787
๐ค AI/ML: ๐ค Multi-Model Consensus (neural-network, q-learning, gpt) - ๐ง NN (55%): block (95.9%) | ๐ฎ QL (23%): block (75.0%) | ๐ค Claude (23%): monitor (70.0%) | โ๏ธ dynamic+boosted weights...
Detected: 2026-03-15T08:55:40.933Z
show less
|
Bad Web Bot
|
|
|
๐ฏ๐ต
Valhalla
|
|
/bak/public_html.zip
|
Hacking
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 66.56.86.18 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 66.56.86.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 11:12:58.783569 2026] [security2:error] [pid 687:tid 687] [client 66.56.86.18:61903] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pcga.golf|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pcga.golf"] [uri "/old/wallet.dat"] [unique_id "abGGehXoXRCxjVoh4AAHCQAAAAU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฏ๐ต
Valhalla
|
|
/backups/public_html.gz
|
Hacking
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 66.56.86.18 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 66.56.86.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 01 18:34:06.112833 2026] [security2:error] [pid 16096:tid 16096] [client 66.56.86.18:46575] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bitcointradingsquare.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bitcointradingsquare.com"] [uri "/bak/www.sql"] [unique_id "aaTM7ksIJ_phHPSAVj9XmAAAAAM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
Sylvyon
|
|
Triggered Cloudflare WAF (firewallCustom) from SK.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint ...
show more
Triggered Cloudflare WAF (firewallCustom) from SK.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: / | UA: Empty string โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
|
Bad Web Bot
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 66.56.86.18 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 66.56.86.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 27 01:03:49.660116 2026] [security2:error] [pid 13443:tid 13443] [client 66.56.86.18:26201] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||jussetcotradinglimited.co|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jussetcotradinglimited.co"] [uri "/restore/backup.sql"] [unique_id "aaEzxVuNB5NdMBsORcu8XAAAAAU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 66.56.86.18 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 66.56.86.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 16 05:32:36.857173 2026] [security2:error] [pid 9957:tid 9957] [client 66.56.86.18:61809] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kwtlaw.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kwtlaw.com"] [uri "/backup.sql"] [unique_id "aZLyRLfgIRvoqY9nKgtWAAAAAA4"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐จ๐ญ
blinx
|
|
Suspicious activity detected by Modsecurity
|
Web Spam
Port Scan
Hacking
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 66.56.86.18 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 66.56.86.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 08:36:18.328958 2026] [security2:error] [pid 878:tid 878] [client 66.56.86.18:25829] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cryptofructo.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cryptofructo.com"] [uri "/restore/backup.sql"] [unique_id "aZB6UmKKjeNoevGH_KyctwAAAAA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ท๐บ
DZBOT
|
|
Website Scanning / Scraping
|
Bad Web Bot
Exploited Host
Web App Attack
|
|
|
๐ฉ๐ช
bescared
|
|
F2B - Malicious activity detected. URL Probing.
|
Hacking
Bad Web Bot
Web App Attack
|
|
|
๐ฏ๐ต
Valhalla
|
|
/back/wallet.dat
|
Hacking
Web App Attack
|
|
|
๐ฉ๐ช
FeG Deutschland
|
|
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
|
Exploited Host
Web App Attack
|
|
|
๐บ๐ธ
Penny Packer
|
|
Fail2Ban apache-tripwires
|
Web App Attack
|
|