AbuseIPDB » 85.203.47.116
85.203.47.116 was found in our database!
This IP was reported 68 times. Confidence of
Abuse
is 35% : ?
ISP
Falco Networks B.V.
Usage Type
Data Center/Web Hosting/Transit
ASN
AS42708
Domain Name
falco-networks.com
Country
π©π°
Denmark
City
Copenhagen, Capital Region
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 85.203.47.116 :
This IP address has been reported a total of
68
times from
27 distinct
sources.
85.203.47.116 was first reported on
January 28th 2024 , and the most recent report was
1 day ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
πΊπΈ
TPI-Abuse
2024-07-01 14:34:09
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 85.203.47.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 85.203.47.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 01 10:33:54.634551 2024] [security2:error] [pid 27945] [client 85.203.47.116:16069] [client 85.203.47.116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.crypto-stamps.com"] [uri "/restore/sftp-config.json"] [unique_id "ZoK-UiHy85HFZNckPcNF8QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-06-24 21:56:04
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 85.203.47.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.47.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 24 17:55:40.927011 2024] [security2:error] [pid 11485] [client 85.203.47.116:6391] [client 85.203.47.116] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||uppermotradingco.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "uppermotradingco.com"] [uri "/back/mysql.sql"] [unique_id "ZnnrXN9dGKST-rM5zEBhHQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
MAGIC
2024-05-23 12:04:16
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
π¦πΊ
oncord
2024-05-07 09:41:51
(2 years ago)
Form spam
Web Spam
πΊπΈ
TPI-Abuse
2024-04-15 02:34:57
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 85.203.47.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.47.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 14 22:34:40.634547 2024] [security2:error] [pid 6963:tid 47423649011456] [client 85.203.47.116:1273] [client 85.203.47.116] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||blastfuturepress.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blastfuturepress.com"] [uri "/back/wallet.dat"] [unique_id "ZhySQDtEGyunLIw6SmnqhwAAARU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-03-14 10:51:39
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 85.203.47.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.47.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 14 06:51:24.463593 2024] [security2:error] [pid 9931] [client 85.203.47.116:2795] [client 85.203.47.116] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sailingcharterburma.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sailingcharterburma.com"] [uri "/old/mysql.sql"] [unique_id "ZfLWrBobtA4sf13BNODTAgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-02-09 09:26:07
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 85.203.47.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.47.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 09 04:25:50.535668 2024] [security2:error] [pid 5150] [client 85.203.47.116:36165] [client 85.203.47.116] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bitcoinpornhub.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bitcoinpornhub.com"] [uri "/restore/mysql.sql"] [unique_id "ZcXvnhlzd0jET1XahhPD_wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-01-28 07:38:50
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 85.203.47.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 85.203.47.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 28 02:38:33.718571 2024] [security2:error] [pid 17407] [client 85.203.47.116:46733] [client 85.203.47.116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "entertainmentpublicblockchain.com"] [uri "/backup/.env"] [unique_id "ZbYEeamqZ0dd9Bryv5x8FQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Showing 61 to
68
of 68 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown π©
Recently Reported IPs: