๐บ๐ธ
TPI-Abuse
2026-06-25 10:49:13
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 85.203.20.12 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 85.203.20.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 06:49:06.303674 2026] [security2:error] [pid 12546:tid 12546] [client 85.203.20.12:37453] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.avvmarchetticollini.it|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.avvmarchetticollini.it"] [uri "/wp-json/wp/v2/users/"] [unique_id "aj0HomymPOT5o2nOCGcHZwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
Valhalla
2026-03-02 23:52:11
(6 months ago)
/bak/sql.sql
Hacking
Web App Attack
๐ฌ๐ง
Axel
2026-02-28 23:22:02
(6 months ago)
Blocked by ModSecurity. Rule ID: 210730 Message: COMODO WAF: URL file extension is restricted by pol ...
show more
Blocked by ModSecurity. Rule ID: 210730 Message: COMODO WAF: URL file extension is restricted by policy||usvi.network|F|2 Phase: 2 Severity: CRITICAL URI: /bak/www.sql Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
Penny Packer
2026-02-24 06:56:13
(6 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
Penny Packer
2026-01-19 20:05:09
(7 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-16 06:44:17
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.20.12 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.20.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 01:44:08.351172 2026] [security2:error] [pid 12485:tid 12485] [client 85.203.20.12:49917] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mpaexchangeinc.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mpaexchangeinc.com"] [uri "/backup/wallet.dat"] [unique_id "aWneOIdB_3R3ewJhl3Q8pwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-09 02:03:07
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.20.12 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.20.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 08 21:03:04.678660 2026] [security2:error] [pid 23413:tid 23413] [client 85.203.20.12:61773] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||casinoaffiliateprogramsonline.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "casinoaffiliateprogramsonline.com"] [uri "/back/sql.sql"] [unique_id "aWBh2OGR3UqDmZcHrARLlQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
Valhalla
2026-01-01 06:09:24
(8 months ago)
/backups/website.tar
Hacking
Web App Attack
๐ฏ๐ต
Valhalla
2025-12-30 13:10:46
(8 months ago)
/restore/website.rar
Hacking
Web App Attack
๐บ๐ธ
Penny Packer
2025-12-28 06:06:31
(8 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐ฉ๐ช
Hazzard
2025-12-28 01:26:57
(8 months ago)
(apache-empty-ua) Failed empty apache-ua trigger with match [redacted])
Hacking
Anonymous
2025-12-09 11:39:07
(9 months ago)
ALFA.TEaM.Web.Shell
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-09 00:45:40
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.20.12 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.20.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 19:45:37.104428 2025] [security2:error] [pid 27325:tid 27325] [client 85.203.20.12:31437] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bitcoinsquaretrader.com|F|2"] [data ".com.sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bitcoinsquaretrader.com"] [uri "/bitcoinsquaretrader.com.sql"] [unique_id "aTdxMY_q2b_mZhYhWpNbRQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2025-12-03 22:05:09
(9 months ago)
2025-12-03 @ 23:05:09 (CET) ~ Blocked based on risk assessment and prior abuse reports
Web App Attack
๐ซ๐ท
dynamix
2025-12-02 23:06:26
(9 months ago)
Multiple WAF Violations
Web App Attack