๐บ๐ธ
TPI-Abuse
2026-09-16 16:34:30
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 12:34:23.764146 2026] [security2:error] [pid 19315:tid 19362] [client 204.217.130.240:46317] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spectresails.com"] [uri "/.env"] [unique_id "aqrFD-WeGsfxJItZAzOdjQAAAcw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 10:48:52
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 06:48:48.570671 2026] [security2:error] [pid 2513523:tid 2513523] [client 204.217.130.240:34571] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "engineeringarts.com"] [uri "/.env"] [unique_id "aqp0ENqAXuEFmGC6BBKSBgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 18:57:10
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 14:56:59.051496 2026] [security2:error] [pid 15782:tid 15782] [client 204.217.130.240:59691] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.xcarsubscription.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.xcarsubscription.com"] [uri "/mailto:[email protected] "] [unique_id "aqhDe9SFq9Z3jb1poYiFXAAAAAo"], referer: https://www.xcarsubscription.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 08:39:20
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 04:39:11.869503 2026] [security2:error] [pid 6192:tid 6192] [client 204.217.130.240:36955] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "apfgr7WBgtyBaX0odQkRtwAAAA4"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 04:18:05
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 00:18:00.115538 2026] [security2:error] [pid 20358:tid 20358] [client 204.217.130.240:48601] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holgerfeld.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "ao-6eIpMhg9XQc_JP-yA_QAAAAw"], referer: http://holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 01:51:38
(2 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-11 09:39:16
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 11 05:39:11.632393 2026] [security2:error] [pid 18759:tid 18823] [client 204.217.130.240:61129] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||woofnrose.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "woofnrose.com"] [uri "/mailto:[email protected] "] [unique_id "alIPP4tBRVO0tOpFkqa1oAAAAcw"], referer: https://woofnrose.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 02:40:41
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 22:40:35.242716 2026] [security2:error] [pid 6827:tid 6827] [client 204.217.130.240:63817] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holgerfeld.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "aizDI6dgasZwPUMjdY0jggAAABI"], referer: http://holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-03 09:23:42
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 05:23:37.016723 2026] [security2:error] [pid 23407:tid 23407] [client 204.217.130.240:41581] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holgerfeld.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "afcUGUepwpohwos0NawXtQAAABU"], referer: http://holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2026-05-03 02:51:40
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (H ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (HEAD) | Endpoint: / | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
london2038.com
2026-04-02 16:46:52
(5 months ago)
Malformed or malicious web request
204.217.130.240 - - [02/Apr/2026:18:46:49 +0200] "\x16\x03\x01\x0 ...
show more
Malformed or malicious web request
204.217.130.240 - - [02/Apr/2026:18:46:49 +0200] "\x16\x03\x01\x01.\x01\x00\x01*\x03\x03\xDC\xD1`}m\xD6\x92+\x93\x0B\x92\x1A\x19\xDA\xB7fB\x89\xC4\x03~3\x13`\xC2\xB8\xE4i\xA92\xC7\xE2\x00\x00\xAC\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 157 "-" "-"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-21 18:45:19
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 21 13:45:14.156706 2026] [security2:error] [pid 19501:tid 19501] [client 204.217.130.240:65091] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aZn9On8nP9prIWY5XhTx1AAAAB0"], referer: http://www.capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-24 19:34:40
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 24 14:34:34.018600 2026] [security2:error] [pid 3716:tid 3716] [client 204.217.130.240:61985] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holgerfeld.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "aXUeypRgNtARXePNI-ayggAAABo"], referer: http://holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-09 06:14:39
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.130.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 09 01:14:32.219799 2026] [security2:error] [pid 13944:tid 13944] [client 204.217.130.240:33709] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aWCcyM6oUfkBIZ2ufjj1BAAAAAg"], referer: http://www.capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2025-12-20 13:17:59
(9 months ago)
204.217.130.240 - - [20/Dec/2025:13:16:56 +0000] "GET /mailto:[email protected] HTTP/1.1" 404 44267 "http ...
show more
204.217.130.240 - - [20/Dec/2025:13:16:56 +0000] "GET /mailto:[email protected] HTTP/1.1" 404 44267 "https://fundaciopacopuerto.cat" rt="0.387" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36" "-" h="fundaciopacopuerto.cat" sn="fundaciopacopuerto.cat" ru="/mailto:[email protected] " u="/index.php" ucs="-" ua="unix:/var/run/php/fundacio82.sock" us="404" uct="0.000" urt="0.387"
204.217.130.240 - - [20/Dec/2025:13:16:56 +0000] "GET /mailto:[email protected] HTTP/1.1" 404 44267 "https://fundaciopacopuerto.cat" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36" "-"
204.217.130.240 - - [20/Dec/2025:13:16:58 +0000] "GET /mailto:[email protected] HTTP/1.1" 404 44270 "https://fundaciopacopuerto.cat" rt="0.380" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36" "-" h="fundaciopacopuerto.cat" sn="fundaciopacopuerto.cat"
...
show less
Bad Web Bot