|
๐ฒ๐พ
Rizzy
|
|
Multiple WAF Violations
|
Brute-Force
Web App Attack
|
|
|
๐ซ๐ท
Hippoline
|
|
[Thu May 21 05:18:50.087385 2026] [authz_core:error] [pid 18915] [client 85.203.44.93:60201] AH01630 ...
show more
[Thu May 21 05:18:50.087385 2026] [authz_core:error] [pid 18915] [client 85.203.44.93:60201] AH01630: client denied by server configuration: /var/www/modern-art.lu/web/info.php, referer: http://modern-art.lu/info.php
[Thu May 21 05:18:50.640134 2026] [authz_core:error] [pid 18915] [client 85.203.44.93:60201] AH01630: client denied by server configuration: /var/www/modern-art.lu/web/log.php, referer: http://modern-art.lu/log.php
[Thu May 21 05:18:51.189119 2026] [authz_core:error] [pid 18915] [client 85.203.44.93:60201] AH01630: client denied by server configuration: /var/www/modern-art.lu/web/wso.php, referer: http://modern-art.lu/wso.php
[Thu May 21 05:18:52.855294 2026] [authz_core:error] [pid 18915] [client 85.203.44.93:60201] AH01630: client denied by server configuration: /var/www/modern-art.lu/web/403.php, referer: http://modern-art.lu/403.php
[Thu May 21 05:18:53.401192 2026] [authz_core:error] [pid 18915] [client 85.203.44.93:60201] AH01630: client denied by server configuratio
...
show less
|
Brute-Force
Web App Attack
|
|
|
๐ฉ๐ช
conseilgouz
|
|
ece-17 : Block hidden directories=>/.env.prod(/)
|
Hacking
|
|
|
๐บ๐ธ
integrantservices.com
|
|
(PERMBLOCK) 85.203.44.93 (SE/Sweden/-) has had more than 4 temp blocks
|
Hacking
|
|
|
๐บ๐ธ
integrantservices.com
|
|
(wordpress) Failed wordpress login from 85.203.44.93 (SE/Sweden/-)
|
Brute-Force
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 85.203.44.93 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.44.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 07:07:24.999968 2026] [security2:error] [pid 7674:tid 7674] [client 85.203.44.93:50775] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||brazilianbikinis.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brazilianbikinis.com"] [uri "/restore/www.sql"] [unique_id "abVBbB_zHaMqNHq2Lqqy5AAAAAA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
Penny Packer
|
|
Fail2Ban apache-tripwires
|
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 85.203.44.93 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.44.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 13:10:27.924762 2026] [security2:error] [pid 3582:tid 3671] [client 85.203.44.93:37467] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||siestakeybch.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "siestakeybch.com"] [uri "/wallet.dat"] [unique_id "aY4Xk5Xx_KOQi_-9TqmTeQAAAdc"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
ghostwarriors
|
|
Attempts against non-existent wp-login
|
Brute-Force
Web App Attack
|
|
|
Anonymous
|
|
Fail2Ban apache-noscript
|
Bad Web Bot
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 85.203.44.93 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.44.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 01:22:48.185835 2026] [security2:error] [pid 23534:tid 23534] [client 85.203.44.93:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ccamp.dev|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ccamp.dev"] [uri "/old/dump.sql"] [unique_id "aYWIuG3UrOhEkpn0kUkPywAAAAM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ฆ
URAN Publishing Service
|
|
85.203.44.93 - - [30/Jan/2026:15:29:25 +0200] "GET //wp-content/uploads/wpr-addons/forms/b1ack.php H ...
show more
85.203.44.93 - - [30/Jan/2026:15:29:25 +0200] "GET //wp-content/uploads/wpr-addons/forms/b1ack.php HTTP/1.1" 404 274 "-" "Go-http-client/1.1"
...
show less
|
Web App Attack
|
|
|
๐บ๐ฆ
URAN Publishing Service
|
|
85.203.44.93 - - [30/Jan/2026:05:17:15 +0200] "GET //wp-content/plugins/seoplugins/mar.php HTTP/1.1" ...
show more
85.203.44.93 - - [30/Jan/2026:05:17:15 +0200] "GET //wp-content/plugins/seoplugins/mar.php HTTP/1.1" 404 275 "-" "Go-http-client/1.1"
85.203.44.93 - - [30/Jan/2026:05:17:16 +0200] "GET //wp-content/plugins/WordPressCore/include.php HTTP/1.1" 404 275 "-" "Go-http-client/1.1"
...
show less
|
Web App Attack
|
|
|
๐ณ๐ฑ
Roderic
|
|
(apache_scanners-2) Failed apache-scanners trigger with match [redacted])
|
Port Scan
|
|
|
Anonymous
|
|
wordpress-trap
|
Web App Attack
|
|