๐ช๐ธ
librebit
2026-09-02 00:25:27
(22 hours ago)
Brute force
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-27 16:04:07
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 204.217.128.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.128.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:04:00.571197 2026] [security2:error] [pid 13566:tid 13566] [client 204.217.128.12:59597] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.customhumanrobots.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.customhumanrobots.com"] [uri "/mailto:[email protected] "] [unique_id "apBf8PeEyOQon9FwONi7FQAAAAI"], referer: https://www.customhumanrobots.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
librebit
2026-08-20 13:50:12
(1 week ago)
Brute force
Brute-Force
Anonymous
2026-08-04 09:54:48
(4 weeks ago)
FortiWeb WAF: 28 attacks detected. Threat Score: 11310755. Types: Client Management(14), Signature D ...
show more
FortiWeb WAF: 28 attacks detected. Threat Score: 11310755. Types: Client Management(14), Signature Detection(14). Origin: United States.
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-23 07:08:00
(2 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 10-07.204.217.128.12.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 10-07.204.217.128.12.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
dtorrer
2026-05-30 23:34:22
(3 months ago)
Client attempted to submit spam on a website post.
Blog Spam
๐ฑ๐ป
garmtech.com
2026-05-18 03:11:28
(3 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 06-11.204.217.128.12.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 06-11.204.217.128.12.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-05 05:24:33
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.128.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.128.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 05 01:24:29.574046 2026] [security2:error] [pid 16027:tid 16027] [client 204.217.128.12:35545] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holgerfeld.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "afl_DbwLkrXxFa8QX5_69gAAAAQ"], referer: http://holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-04-20 13:53:57
(4 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 16-53.204.217.128.12.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 16-53.204.217.128.12.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2026-04-01 21:03:03
(5 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 00-03.204.217.128.12.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 00-03.204.217.128.12.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-28 23:02:47
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.128.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.128.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 19:02:39.955554 2026] [security2:error] [pid 12826:tid 12826] [client 204.217.128.12:38125] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "acheD6m56CfSPdz47qSc_AAAAAI"], referer: http://www.capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-22 17:39:36
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.128.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.128.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 13:39:32.281420 2026] [security2:error] [pid 16748:tid 16748] [client 204.217.128.12:25075] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||HOLGERFELD.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "acApVI2XWqyXjtiV_Ss9IwAAAA4"], referer: http://HOLGERFELD.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
gnom4ik
2026-02-22 06:18:49
(6 months ago)
ban-reviewer auto report; ip=204.217.128.12; scenario=http:scan; verdict=valid_ban; confidence=0.85; ...
show more
ban-reviewer auto report; ip=204.217.128.12; scenario=http:scan; verdict=valid_ban; confidence=0.85; categories=14,15,18; active_decisions=1; lookback_decisions=1; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=IP flagged for 'Port Scan' (category 14) in abuseipdb context; Scan behavior detected via http:scan scenario; Decision was placed within a short time window indicating immediate threat response
show less
Port Scan
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-02-16 16:44:49
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.128.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.128.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 16 11:44:44.083246 2026] [security2:error] [pid 25795:tid 25795] [client 204.217.128.12:53223] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aZNJfMWjqn9lRSrpERWSPwAAABU"], referer: http://capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-12 20:13:55
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.128.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.128.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 15:13:48.169390 2026] [security2:error] [pid 10691:tid 10691] [client 204.217.128.12:51147] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||HOLGERFELD.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "aY40fNAmJKLkKGLkQoolzwAAABA"], referer: http://HOLGERFELD.com
show less
Brute-Force
Bad Web Bot
Web App Attack