🇨🇭
backslash
2026-09-05 02:48:01
(1 day ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
🇳🇱
Savvii
2026-03-28 11:19:42
(5 months ago)
10 attempts against mh-misc-ban on frost
Web App Attack
🇩🇪
David Ferneding
2026-03-13 17:13:09
(5 months ago)
Blocked by UFW (TCP on 80)
Source port: 55381
TTL: 55
Packet length: 60
TOS: 0x00
This report (for ...
show more
Blocked by UFW (TCP on 80)
Source port: 55381
TTL: 55
Packet length: 60
TOS: 0x00
This report (for 66.56.86.7) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-03-03 02:30:36
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 66.56.86.7 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 66.56.86.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 02 21:30:31.477528 2026] [security2:error] [pid 13769:tid 13769] [client 66.56.86.7:39013] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nationalenq.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nationalenq.com"] [uri "/bak/mysql.sql"] [unique_id "aaZHxztmJ4YCTvT-1N5FnAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
threatintelligence_bvc
2026-02-28 22:16:34
(6 months ago)
Brute-Force
🇺🇸
TPI-Abuse
2026-02-15 20:00:09
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 66.56.86.7 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 66.56.86.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 14:59:59.209202 2026] [security2:error] [pid 17964:tid 17964] [client 66.56.86.7:64305] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||3dsportschannel.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "3dsportschannel.com"] [uri "/bak/mysql.sql"] [unique_id "aZIlv8Ftidw5F8zEi6bF8wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
pinguin
2026-02-14 01:15:21
(6 months ago)
Triggered Cloudflare WAF (firewallManaged) from SK.
Action taken: LOG
Protocol: HTTP/2 (HEAD method) ...
show more
Triggered Cloudflare WAF (firewallManaged) from SK.
Action taken: LOG
Protocol: HTTP/2 (HEAD method)
Endpoint: /config.json
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-01-29 19:44:04
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 66.56.86.7 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 66.56.86.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 29 14:43:56.476992 2026] [security2:error] [pid 19468:tid 19468] [client 66.56.86.7:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kryptonome.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kryptonome.com"] [uri "/dump.sql"] [unique_id "aXu4fLS2Y1cvezpS0oKuTwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-22 09:03:51
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 66.56.86.7 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 66.56.86.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 04:03:45.382739 2026] [security2:error] [pid 20578:tid 20578] [client 66.56.86.7:26321] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crypto-stamps.com"] [uri "/bak/sftp-config.json"] [unique_id "aXHn8S_Wn3EzKlJRbxbEfwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
bescared
2026-01-06 08:14:30
(8 months ago)
F2B - Malicious activity detected. URL Probing.
Hacking
Bad Web Bot
Web App Attack
🇯🇵
Valhalla
2025-12-29 08:49:31
(8 months ago)
/back/bak.zip
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2025-12-28 22:31:43
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 66.56.86.7 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 66.56.86.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 17:31:36.597400 2025] [security2:error] [pid 19816:tid 19816] [client 66.56.86.7:29245] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pcga.golf|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pcga.golf"] [uri "/back/wallet.dat"] [unique_id "aVGvyOxedcnWzgpWupWYKAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Penny Packer
2025-12-16 10:25:48
(8 months ago)
Fail2Ban apache-tripwires
Web App Attack
🇺🇸
TPI-Abuse
2025-12-14 11:52:09
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 66.56.86.7 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 66.56.86.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 14 06:52:02.606248 2025] [security2:error] [pid 30015:tid 30015] [client 66.56.86.7:24969] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "headcount.dev"] [uri "/old/sftp-config.json"] [unique_id "aT6k4q8amknKGz0OJfVOMgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
pinguin
2025-12-11 23:36:21
(8 months ago)
Triggered Cloudflare WAF (firewallManaged) from SK.
Action taken: LOG
Protocol: HTTP/2 (HEAD method) ...
show more
Triggered Cloudflare WAF (firewallManaged) from SK.
Action taken: LOG
Protocol: HTTP/2 (HEAD method)
Endpoint: /restore/bak.rar
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot