๐ณ๐ฑ
Savvii
2026-07-22 03:20:56
(2 days ago)
20 attempts against mh-misbehave-ban on pavo
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 01:24:13
(2 days ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-07-10 06:05:34
(2 weeks ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐บ๐ธ
ipblock.com
2026-05-28 22:46:00
(1 month ago)
IPBlock protected site ID [4055-d][s=02].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-05 19:23:19
(2 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 22-23.204.217.129.199.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 22-23.204.217.129.199.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ต๐ฑ
sefinek.net
2026-05-03 02:51:40
(2 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (H ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (HEAD) | Endpoint: / | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-18 23:07:14
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.129.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.129.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 18 19:07:07.161526 2026] [security2:error] [pid 795597:tid 795597] [client 204.217.129.199:54077] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.cayman-islands-real-estate.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.cayman-islands-real-estate.com"] [uri "/mailto:[email protected] "] [unique_id "aeQOm1wbgyqYpzmaucQArwAAAAk"], referer: https://www.cayman-islands-real-estate.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-04-16 20:41:22
(3 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 23-41.204.217.129.199.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 23-41.204.217.129.199.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-16 05:46:25
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.129.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.129.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 01:46:18.082959 2026] [security2:error] [pid 251228:tid 251228] [client 204.217.129.199:36927] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.holgerfeld.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "aeB3qhCKBkRc8QuMzS9fYgAAABc"], referer: http://www.holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-03-25 09:18:00
(3 months ago)
block ruleset Badbot using very old user-agents 5CF3CDB778C7D82564405B86B9242E612F378C68
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-21 00:30:45
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.129.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.129.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 19:30:38.328884 2026] [security2:error] [pid 28062:tid 28062] [client 204.217.129.199:63361] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.capitalswisscorp.com:80|F|2"] [data "[email protected] "] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aZj8rmSGcNxzV1Nqe0dabgAAABE"], referer: http://www.capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-11 04:02:12
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.129.199 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.129.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 23:02:08.347619 2026] [security2:error] [pid 31862:tid 31862] [client 204.217.129.199:41579] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||HOLGERFELD.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "aYv_QGY9cSuReZCku1fedgAAABs"], referer: http://HOLGERFELD.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-02-03 17:39:45
(5 months ago)
Critical web app attack detected. Illegal Accept header: charset parameter
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-04-19 07:50:24
(1 year ago)
WP Login Scan Activities
Web App Attack
๐จ๐ญ
backslash
2025-03-23 01:05:05
(1 year ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot