๐ฎ๐น
CoreTech srl
2026-09-23 00:16:34
(6 days ago)
cloudlinux2 fail2ban: 2026-09-23 01:54:07,073 fail2ban.filter [1598]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-23 01:54:07,073 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 160.250.130.168 - 2026-09-23 01:54:06cloudlinux2 fail2ban: 2026-09-23 01:54:26,111 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 129.152.3.116 - 2026-09-23 01:54:25cloudlinux2 fail2ban: 2026-09-23 01:54:37,432 fail2ban.actions [1598]: NOTICE [plesk-modsecurity] Unban 34.154.196.228cloudlinux2 fail2ban: 2026-09-23 01:54:51,086 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 104.219.251.64 - 2026-09-23 01:54:50cloudlinux2 fail2ban: 2026-09-23 01:54:52,585 fail2ban.filter [1598]: INFO [plesk-apache] Found 185.132.186.16 - 2026-09-23 01:54:52cloudlinux2 fail2ban: 2026-09-23 01:54:58,686 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 204.217.130.8 - 2026-09-23 01:54:58cloudlinux2 fail2ban: 2026-09-23 01:54:58,694 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 185.89.108.227 - 2026-09-23 01:54:58cloudlinux2 fail2ban:
show less
Web App Attack
๐ฉ๐ช
LRob
2026-09-09 16:10:42
(2 weeks ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: HEAD | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: HEAD | path: /tel:33687261284 | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36 | 2026-09-09 16:10 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 10:22:59
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 204.217.130.8 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.130.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 06:22:54.261476 2026] [security2:error] [pid 24428:tid 24428] [client 204.217.130.8:47679] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.garantaconsulting.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.garantaconsulting.com"] [uri "/mailto:[email protected] "] [unique_id "ap0-_qai40wBAwD3PL4DnwAAADM"], referer: http://www.garantaconsulting.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 18:11:38
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 204.217.130.8 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.130.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 14:11:30.818976 2026] [security2:error] [pid 23979:tid 23979] [client 204.217.130.8:40193] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aphm0lEn2Vd4YMmPcsv5qgAAAAg"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-07-25 00:28:00
(2 months ago)
IPBlock protected site ID [4055-d][s=01].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 01:53:08
(2 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-19 16:20:20
(3 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 19-20.204.217.130.8.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 19-20.204.217.130.8.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-18 03:05:38
(4 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 06-05.204.217.130.8.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 06-05.204.217.130.8.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 16:24:55
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.130.8 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.130.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 12:24:47.727490 2026] [security2:error] [pid 1600772:tid 1600772] [client 204.217.130.8:48599] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.americanexportimport.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.americanexportimport.com"] [uri "/mailto:[email protected] "] [unique_id "adUvz-ar57fzHIUB__O4dQAAABE"], referer: http://www.americanexportimport.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 04:07:16
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.130.8 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.130.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 00:07:10.889430 2026] [security2:error] [pid 8011:tid 8011] [client 204.217.130.8:58903] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "acilbtohPP5W9VjKslWYwgAAAAo"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-02-20 14:02:48
(7 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 16-02.204.217.130.8.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 16-02.204.217.130.8.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 05:22:40
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.130.8 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.130.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 00:22:34.106281 2026] [security2:error] [pid 9816:tid 9816] [client 204.217.130.8:27523] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aYrAmpnkTkK-RjdPikMzeAAAABU"], referer: http://www.CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dtorrer
2026-01-21 03:27:18
(8 months ago)
Client attempted to submit spam on a website post.
Blog Spam
๐บ๐ธ
TPI-Abuse
2026-01-12 05:15:30
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.130.8 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.130.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 12 00:15:26.497664 2026] [security2:error] [pid 2327998:tid 2327998] [client 204.217.130.8:29375] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.caferutadelaseda.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.caferutadelaseda.com"] [uri "/mysql.sql"] [unique_id "aWSDbhby7gpZjuQkVM03dAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-03 08:05:56
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.130.8 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.130.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 03 03:05:48.716180 2026] [security2:error] [pid 951:tid 951] [client 204.217.130.8:61751] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||americanexportimport.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "americanexportimport.com"] [uri "/mailto:[email protected] "] [unique_id "aVjN3Mg4pcJXi8tUb2b5swAAAAQ"], referer: http://americanexportimport.com
show less
Brute-Force
Bad Web Bot
Web App Attack