๐จ๐ญ
backslash
2026-08-26 05:27:01
(2 hours ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
๐ฎ๐น
VHosting
2026-08-26 04:20:04
(3 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-25 18:03:24
(13 hours ago)
[25/Aug/2026:21:03:24 +0300] -- 85.203.45.149 Ban reason: User-Agent Go-http-client
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-07-07 08:27:13
(1 month ago)
Aggressive web search of vulnerable pages: /dropdown.php /wp-admin.php /license.php /content.php /in ...
show more
Aggressive web search of vulnerable pages: /dropdown.php /wp-admin.php /license.php /content.php /install.php /inputs.php /style2.php /simple.p ...
show less
Web App Attack
๐ฉ๐ช
todix
2026-04-17 07:58:09
(4 months ago)
Web App Attack Exploid from 85.203.45.149
Web App Attack
๐ฌ๐ง
consul.to
2026-04-17 06:55:36
(4 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ฒ๐พ
Rizzy
2026-04-17 01:41:32
(4 months ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-13 09:32:14
(4 months ago)
(mod_security) mod_security (id:234930) triggered by 85.203.45.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:234930) triggered by 85.203.45.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 13 05:32:05.755209 2026] [security2:error] [pid 1513896:tid 1513896] [client 85.203.45.149:62335] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||powerkiteforum.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "powerkiteforum.com"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "ady4FSzqUlcrV-aFGWamLAAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-04-13 06:06:02
(4 months ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-17 13:10:47
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 85.203.45.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 85.203.45.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 17 09:10:38.655755 2026] [security2:error] [pid 19122:tid 19122] [client 85.203.45.149:32851] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wendeenicole.com"] [uri "/bak/sftp-config.json"] [unique_id "ablSztgAJ8EuxU5VUfrX3gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-03-11 06:32:50
(5 months ago)
Triggered Cloudflare WAF (firewallManaged) from CH.
Action taken: LOG
Protocol: HTTP/2 (HEAD method) ...
show more
Triggered Cloudflare WAF (firewallManaged) from CH.
Action taken: LOG
Protocol: HTTP/2 (HEAD method)
Endpoint: /bak/config.js
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-28 14:45:08
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.45.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.45.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 09:45:01.855684 2026] [security2:error] [pid 6249:tid 6249] [client 85.203.45.149:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kryptonome.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kryptonome.com"] [uri "/backup/backup.sql"] [unique_id "aaL_bfOFPiFrF5hAYnk2GwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-27 16:39:59
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.45.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.45.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 27 11:39:53.314778 2026] [security2:error] [pid 3086:tid 3086] [client 85.203.45.149:64593] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nationalenq.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nationalenq.com"] [uri "/backup.sql"] [unique_id "aaHI2a_LGRz4JKs3divQtgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-02-26 10:51:29
(5 months ago)
85.203.45.149 - - [26/Feb/2026:12:51:27 +0200] "GET //wp-admin/maint/index.php HTTP/1.1" 404 297 "-" ...
show more
85.203.45.149 - - [26/Feb/2026:12:51:27 +0200] "GET //wp-admin/maint/index.php HTTP/1.1" 404 297 "-" "Go-http-client/1.1"
85.203.45.149 - - [26/Feb/2026:12:51:28 +0200] "GET //wp-admin/css/index.php HTTP/1.1" 404 297 "-" "Go-http-client/1.1"
...
show less
Web App Attack
๐ฒ๐พ
Rizzy
2026-02-26 08:28:03
(5 months ago)
Multiple WAF Violations
Brute-Force
Web App Attack