This IP address has been reported a total of
6
times from
2 distinct
sources.
196.197.25.108 was first reported on
September 28th 2026 , and the most recent report was
9 hours ago .
In the last 60 days, the top reporter locations were:
United States of America
with 5
reports;
Switzerland
with 1
report.
The most common categories in these recent reports were:
Bad Web Bot
6
times;
Web App Attack
5
times;
Brute-Force
5
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
π¨π
backslash
2026-10-03 04:06:00
(9 hours ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-10-02 07:41:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 196.197.25.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.197.25.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 03:40:54.269317 2026] [security2:error] [pid 263598:tid 263598] [client 196.197.25.108:41530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coinbracelet.com"] [uri "/.git/HEAD"] [unique_id "ar9gBr4mYdCOTkgWV3WvIgAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 03:56:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 196.197.25.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.197.25.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 23:55:50.312172 2026] [security2:error] [pid 30090:tid 30090] [client 196.197.25.108:59989] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.icoinedthewordironesty.com"] [uri "/.git/HEAD"] [unique_id "ar8rRrSdzxeF5LmTkbtMlwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 01:43:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 196.197.25.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.197.25.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 21:42:57.669168 2026] [security2:error] [pid 3600:tid 3600] [client 196.197.25.108:57849] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.crazycoin.net"] [uri "/.git/HEAD"] [unique_id "ar8MIe_a6aUKUOpKo0-KFAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 10:47:51
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 196.197.25.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 196.197.25.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:47:40.455406 2026] [security2:error] [pid 28614:tid 28614] [client 196.197.25.108:56820] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.motonaonaobookings.hamiltonbookings.com"] [uri "/.git/HEAD"] [unique_id "ar46THR00Q0TYpVPIraq_wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 09:27:17
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 196.197.25.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.197.25.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 05:26:48.405490 2026] [security2:error] [pid 26227:tid 26227] [client 196.197.25.108:38181] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blushhairstyling.com.piratecostumesonline.com"] [uri "/.git/HEAD"] [unique_id "aroy2Bo4jpl3nXPlxUsa5AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Showing 1 to
6
of 6 reports