🇨🇭
backslash
2026-09-02 00:06:07
(1 week ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
🇮🇹
VHosting
2026-09-01 23:45:03
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇯🇵
demonsword
2026-06-05 13:45:08
(3 months ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: account.jetbrains.com:443
show less
Open Proxy
Port Scan
🇯🇵
Valhalla
2026-03-15 21:19:09
(5 months ago)
/backups/www.rar
Hacking
Web App Attack
🇺🇸
myagent.site
2026-03-15 12:30:45
(5 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
🇺🇸
TPI-Abuse
2026-03-12 07:24:52
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.20.98 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.20.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 12 03:24:48.764280 2026] [security2:error] [pid 12419:tid 12419] [client 85.203.20.98:51191] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||secureonebank.net|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "secureonebank.net"] [uri "/bak/wallet.dat"] [unique_id "abJqQDexx0IwoXcC-S1XfQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-04 06:54:55
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.20.98 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.20.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 04 01:54:48.291204 2026] [security2:error] [pid 1322:tid 1339] [client 85.203.20.98:35887] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||magazineofwallstreet.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "magazineofwallstreet.com"] [uri "/wallet.dat"] [unique_id "aafXOHsc6gmXlgqifBZ1AwAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Penny Packer
2026-03-01 10:25:35
(6 months ago)
Fail2Ban apache-tripwires
Web App Attack
🇺🇸
TPI-Abuse
2026-02-26 04:07:00
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.20.98 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.20.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 23:06:54.747008 2026] [security2:error] [pid 15155:tid 15155] [client 85.203.20.98:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kryptonome.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kryptonome.com"] [uri "/wallet.dat"] [unique_id "aZ_G3vnsm4OBy7i7iuoMsQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-18 18:09:22
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.20.98 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.20.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 13:09:16.594255 2026] [security2:error] [pid 5390:tid 5390] [client 85.203.20.98:23807] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.dudleyanddudley.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.dudleyanddudley.com"] [uri "/dump.sql"] [unique_id "aZYATLDfkcSBOnxb45n_7gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-02-10 01:48:07
(7 months ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-02-09 03:10:04
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.20.98 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.20.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 08 22:09:58.452949 2026] [security2:error] [pid 26702:tid 26702] [client 85.203.20.98:49829] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||swhowell.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "swhowell.com"] [uri "/back/mysql.sql"] [unique_id "aYlQBsKXpYY9VlzpA2nZ-AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-08 06:50:01
(7 months ago)
suspicious request in access.log
Web App Attack
Anonymous
2026-02-07 12:58:22
(7 months ago)
wordpress-trap
Web App Attack
🇳🇿
Antinson
2026-02-07 10:12:51
(7 months ago)
Scraping with a high error ratio and request rate
Bad Web Bot