๐จ๐ญ
backslash
2026-05-20 22:36:02
(3 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ท๐บ
Agrohim
2026-03-18 20:05:26
(5 months ago)
Gate Inet blocked for categories:
DDoS Attack
Ping of Death
Port Scan
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-03-18 07:30:30
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.44.75 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.44.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 03:30:24.079622 2026] [security2:error] [pid 12667:tid 12667] [client 85.203.44.75:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||eddysgroup.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "eddysgroup.com"] [uri "/wallet.dat"] [unique_id "abpUkEJuXXLL4RBiOkflkwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
Agrohim
2026-03-13 01:11:49
(6 months ago)
Gate Inet blocked for categories:
DDoS Attack
Ping of Death
Port Scan
Hacking
Brute-Force
๐ฌ๐ง
pinguin
2026-03-10 17:40:41
(6 months ago)
Triggered Cloudflare WAF (linkMaze) from SE.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/2 (HEAD ...
show more
Triggered Cloudflare WAF (linkMaze) from SE.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/2 (HEAD method)
Endpoint: /backups/backup.zip
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ท
Octopuce
2026-03-09 23:38:36
(6 months ago)
Aggressive web search of vulnerable pages: //3PJcpMFsD8B.php //function.php //wp-admin.php //dropdow ...
show more
Aggressive web search of vulnerable pages: //3PJcpMFsD8B.php //function.php //wp-admin.php //dropdown.php //content.php //default.php //bypass. ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-24 08:08:34
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.44.75 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.44.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 24 03:08:27.953046 2026] [security2:error] [pid 19790:tid 19790] [client 85.203.44.75:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ccamp.dev|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ccamp.dev"] [uri "/www.sql"] [unique_id "aZ1ce31G0wLXgqIFAROiOwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 21:41:06
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.44.75 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.44.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 16:41:01.808941 2026] [security2:error] [pid 3000428:tid 3000504] [client 85.203.44.75:36737] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nobletitles.org|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nobletitles.org"] [uri "/old/wallet.dat"] [unique_id "aY-abQnAHZBQLYcp83SGDwAAAcg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-02-10 10:11:46
(7 months ago)
F2B - Malicious activity detected. URL Probing.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-02-09 14:36:05
(7 months ago)
Blocking for trying to access an exploit file: /themes/pridmag/
Hacking
๐จ๐ญ
Origon
2026-02-09 13:52:12
(7 months ago)
http-crawl-non_statics - IP: 85.203.44.75 - time="2026-02-09T14:52:12+01:00" level=info msg="(555f6 ...
show more
http-crawl-non_statics - IP: 85.203.44.75 - time="2026-02-09T14:52:12+01:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-crawl-non_statics by ip 85.203.44.75 (SE/42708) : 4h ban on Ip 85.203.44.75" module=db
show less
Bad Web Bot
๐ฉ๐ช
ghostwarriors
2026-02-09 13:20:25
(7 months ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-04 01:17:03
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.44.75 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.44.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 03 20:16:56.571383 2026] [security2:error] [pid 28422:tid 28422] [client 85.203.44.75:39567] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pathpa.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pathpa.org"] [uri "/bak/backup.sql"] [unique_id "aYKeCJhwh0JEN8Oc5eRXjgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-01-30 09:39:17
(7 months ago)
IM360 WAF: Block access to the shell MV://xleet.php
Hacking
๐ฑ๐ป
garmtech.com
2026-01-30 09:38:56
(7 months ago)
IM360 WAF: Interaction with fake plugin MV://wp-content/plugins/WordPressCore/include.php
Web App Attack