๐บ๐ธ
threatintelligence_bvc
2026-06-28 07:41:08
(1 month ago)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-25 08:01:05
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 85.203.20.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 85.203.20.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 04:00:56.739771 2026] [security2:error] [pid 16079:tid 16079] [client 85.203.20.13:50405] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.avaliantlife.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.avaliantlife.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajzgOKRwtwYZuW02NqaY7gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
threatintelligence_bvc
2026-04-16 01:52:45
(4 months ago)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-03-01 02:40:51
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.20.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.20.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 21:40:47.101896 2026] [security2:error] [pid 20681:tid 20681] [client 85.203.20.13:47127] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pcga.golf|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pcga.golf"] [uri "/wallet.dat"] [unique_id "aaOnL2Ot40d7Ypy043bEfQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-27 10:59:51
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.20.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.20.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 27 05:59:45.336706 2026] [security2:error] [pid 566:tid 566] [client 85.203.20.13:35285] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||russiacoin.info|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "russiacoin.info"] [uri "/bak/backup.sql"] [unique_id "aaF5IayaxYuQJUOMYKKLLQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 08:38:23
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.20.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.20.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 03:38:16.089532 2026] [security2:error] [pid 30032:tid 30046] [client 85.203.20.13:30821] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dpscsde.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dpscsde.com"] [uri "/restore/wallet.dat"] [unique_id "aZGF-B3sE4iDKNoMMPl3AwAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-02-12 23:47:45
(6 months ago)
Brute-Force
Web App Attack
๐น๐ท
rtbh.com.tr
2026-02-12 20:11:31
(6 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ซ๐ท
SpaceHost-Server
2026-02-11 23:41:39
(6 months ago)
Brute-Force
Web App Attack
๐น๐ท
rtbh.com.tr
2026-02-11 20:11:31
(6 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ฉ๐ช
hbrks
2026-02-11 03:04:50
(6 months ago)
1 attack(s) detected, such as these: {"event":"web_block","ip":"85.203.20.13","host":"marche-be.com" ...
show more
1 attack(s) detected, such as these: {"event":"web_block","ip":"85.203.20.13","host":"marche-be.com","request":"GET / HTTP/1.1","user_agent":"","reason":"service:unknow","timestamp":"2026-02-11T03:04:50 00:00","logentry":"marche-be.com 85.203.20.13 - - [11/Feb/2026:03:04:50 0000] GET / HTTP/1.1 444 0 - - - matched:service:unknow"} * Report Details *: https://p4u.xyz/PX8MFI9XZ59/1* IP Details *: https://p4u.xyz/PX8MFI9XZ59/2
show less
Web Spam
Hacking
Bad Web Bot
๐บ๐ธ
Penny Packer
2026-02-05 22:02:37
(6 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
WizardsToolkit
2026-01-31 06:42:38
(6 months ago)
attempted to access /old/www.zip
Web App Attack
๐ฉ๐ช
bescared
2026-01-29 04:27:34
(6 months ago)
F2B - Malicious activity detected. URL Probing.
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-01-10 09:46:33
(7 months ago)
F2B - Malicious activity detected. URL Probing.
Hacking
Bad Web Bot
Web App Attack