๐บ๐ธ
Penny Packer
2026-02-25 00:32:44
(3 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐ฉ๐ช
Lino Project
2026-02-19 10:11:30
(3 months ago)
85.203.47.175 - - [19/Feb/2026:11:11:27 +0100] "GET /admin.php HTTP/1.1" 301 734 "-" "Mozilla/5.0 (W ...
show more
85.203.47.175 - - [19/Feb/2026:11:11:27 +0100] "GET /admin.php HTTP/1.1" 301 734 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95"
85.203.47.175 - - [19/Feb/2026:11:11:30 +0100] "GET /admin/uploads/bn_1_1754420677.phtml HTTP/1.1" 301 786 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-16 06:35:25
(3 months ago)
Unauthorized connection attempt detected in the last 24 hours
Hacking
๐ฌ๐ง
consul.to
2026-02-07 06:59:50
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-03 22:05:27
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.47.175 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.47.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 03 17:05:09.316230 2026] [security2:error] [pid 30948:tid 30948] [client 85.203.47.175:46033] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.domainexecs.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.domainexecs.com"] [uri "/backup.sql"] [unique_id "aYJxFf5W9mCVG7_7_7tihAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-01-28 17:05:55
(4 months ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-28 02:01:33
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.47.175 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.47.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 27 21:01:18.108758 2026] [security2:error] [pid 3541:tid 3541] [client 85.203.47.175:36543] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bitcointoolfair.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bitcointoolfair.com"] [uri "/bak/mysql.sql"] [unique_id "aXlt7uOMJDK6SiXO9ZEuGgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Penny Packer
2026-01-27 18:45:37
(4 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐ณ๐ฑ
maxxsense
2026-01-19 03:20:41
(4 months ago)
(wordpress) Failed wordpress login from 85.203.47.175 (DK/Denmark/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-01-16 18:02:52
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.47.175 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.47.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 13:02:35.994268 2026] [security2:error] [pid 23015:tid 23015] [client 85.203.47.175:62885] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||medicalexchangeasinc.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "medicalexchangeasinc.com"] [uri "/old/sql.sql"] [unique_id "aWp9O8rozVhI9svTTPc4vQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-01-15 22:14:58
(4 months ago)
(apache-empty-ua) Failed empty apache-ua trigger with match [redacted]): (CF_ENABLE)
Hacking
๐บ๐ฆ
URAN Publishing Service
2026-01-05 06:43:03
(4 months ago)
85.203.47.175 - - [05/Jan/2026:08:42:01 +0200] "GET /wp-content/plugins/advanced-llms-txt-generator/ ...
show more
85.203.47.175 - - [05/Jan/2026:08:42:01 +0200] "GET /wp-content/plugins/advanced-llms-txt-generator/assets/css/css_json.php HTTP/1.1" 404 2873 "http://journal.sops.gov.ua//wp-content/plugins/advanced-llms-txt-generator/assets/css/css_json.php" "Go-http-client/1.1"
85.203.47.175 - - [05/Jan/2026:08:43:02 +0200] "GET /wp-content/themes/admin.php HTTP/1.1" 404 2873 "http://journal.sops.gov.ua//wp-content/themes/admin.php" "Go-http-client/1.1"
...
show less
Web App Attack
๐บ๐ธ
Dolphi
2026-01-03 02:41:19
(5 months ago)
POST //xmlrpc.php
Brute-Force
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2025-12-27 16:51:26
(5 months ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐จ๐ญ
backslash
2025-12-27 06:45:09
(5 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot