๐บ๐ธ
TPI-Abuse
2026-06-26 01:18:17
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 85.203.20.4 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 85.203.20.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 21:18:10.383398 2026] [security2:error] [pid 2779:tid 2779] [client 85.203.20.4:44081] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.azcrittergetter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.azcrittergetter.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aj3TUi19TGZ2VHjOVjtBJwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
SentinalX by uzumaru
2026-06-04 09:37:57
(2 months ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: account.jetbrains.com:443
show less
Open Proxy
Port Scan
๐บ๐ธ
TPI-Abuse
2026-03-10 22:45:50
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.20.4 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.20.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 10 18:45:46.280439 2026] [security2:error] [pid 17727:tid 17727] [client 85.203.20.4:51879] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bitcointoolshop.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bitcointoolshop.com"] [uri "/back/wallet.dat"] [unique_id "abCfGgbc3RIT3DF2Oq5nwQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-01 10:25:59
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.20.4 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.20.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 01 05:25:55.507417 2026] [security2:error] [pid 4692:tid 4692] [client 85.203.20.4:30145] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dudleyanddudley.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dudleyanddudley.com"] [uri "/old/backup.sql"] [unique_id "aaQUM8iMFje9c-zGEfWRoQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
Valhalla
2026-02-27 15:25:28
(5 months ago)
/back/full_backup.zip
Hacking
Web App Attack
๐บ๐ธ
Penny Packer
2026-02-24 06:56:46
(5 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-11 03:00:39
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 85.203.20.4 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 85.203.20.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 22:00:34.556170 2026] [security2:error] [pid 20513:tid 20513] [client 85.203.20.4:28695] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3dsportschannel.com"] [uri "/backups/sftp-config.json"] [unique_id "aYvw0hBjJ_saSmq-e1s6EQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Penny Packer
2026-01-24 20:54:29
(6 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 18:06:19
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.20.4 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.20.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 13:06:13.046386 2026] [security2:error] [pid 24883:tid 24883] [client 85.203.20.4:44181] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.hodlmoser.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.hodlmoser.com"] [uri "/backup/wallet.dat"] [unique_id "aXJnFdJ2-AizWT0Je3ogugAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-01-10 09:46:34
(7 months ago)
F2B - Malicious activity detected. URL Probing.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-09 02:03:13
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.20.4 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.20.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 08 21:03:07.622536 2026] [security2:error] [pid 28293:tid 28293] [client 85.203.20.4:54961] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||casinoaffiliateprogramsonline.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "casinoaffiliateprogramsonline.com"] [uri "/backups/dump.sql"] [unique_id "aWBh22c54dS_pPYzW5JTbQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-06 18:23:11
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.20.4 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.20.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 06 13:23:07.843586 2026] [security2:error] [pid 32194:tid 32194] [client 85.203.20.4:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ccamp.dev|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ccamp.dev"] [uri "/wallet.dat"] [unique_id "aV1TC7A4Njn4TVkkx-SZSAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-10 22:40:26
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.20.4 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.20.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 17:40:19.820187 2025] [security2:error] [pid 6650:tid 6650] [client 85.203.20.4:34971] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bitcointoolfair.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bitcointoolfair.com"] [uri "/backup/sql.sql"] [unique_id "aTn20wxmpCmqiQ5oWVFn1AAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2025-12-03 22:08:22
(8 months ago)
2025-12-03 @ 23:08:22 (CET) ~ Blocked based on risk assessment and prior abuse reports
Web App Attack
Anonymous
2025-12-03 12:47:21
(8 months ago)
wordpress-trap
Web App Attack