๐บ๐ธ
TPI-Abuse
2026-08-28 11:25:48
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 204.217.131.187 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.131.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:25:44.036189 2026] [security2:error] [pid 25925:tid 25925] [client 204.217.131.187:56609] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holgerfeld.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "apFwOJ8eRCIj5YmPkFk-4QAAABk"], referer: http://holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-04 11:43:02
(4 weeks ago)
FortiWeb WAF: 24 attacks detected. Threat Score: 10461880. Types: Client Management(12), Signature D ...
show more
FortiWeb WAF: 24 attacks detected. Threat Score: 10461880. Types: Client Management(12), Signature Detection(12). Origin: United States.
show less
Web App Attack
Anonymous
2026-07-22 00:34:15
(1 month ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-27 14:21:47
(3 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 17-21.204.217.131.187.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 17-21.204.217.131.187.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-25 06:34:35
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.131.187 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.131.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 02:34:27.702155 2026] [security2:error] [pid 18727:tid 18727] [client 204.217.131.187:54647] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.GarantaConsulting.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.garantaconsulting.com"] [uri "/mailto:[email protected] "] [unique_id "ahPtcwlSi2fhT3QBustGMQAAACQ"], referer: http://www.GarantaConsulting.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-13 08:24:20
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.131.187 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.131.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 13 04:24:14.278529 2026] [security2:error] [pid 2242273:tid 2242273] [client 204.217.131.187:40481] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "adyoLhDWSJucKiigreuk9wAAAAc"], referer: http://www.CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-23 01:54:09
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.131.187 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.131.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 20:54:01.703022 2026] [security2:error] [pid 11207:tid 11207] [client 204.217.131.187:27277] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aZuzObT-rxyx0-SzB4pPxAAAAA4"], referer: http://www.capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-02-20 06:07:16
(6 months ago)
block ruleset SQL-Injections: typical patterns B00691C2B3660FF27FABC58C19A75B50EDEC4A5E
SQL Injection
๐บ๐ธ
TPI-Abuse
2025-12-31 10:26:06
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.131.187 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.131.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 31 05:26:00.996913 2025] [security2:error] [pid 30443:tid 30443] [client 204.217.131.187:52655] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.TransCapitalSolutions.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.transcapitalsolutions.com"] [uri "/mailto:[email protected] "] [unique_id "aVT6OGND29fkWGMqjOD-UAAAACI"], referer: http://www.TransCapitalSolutions.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2025-12-10 13:32:22
(8 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 15-32.204.217.131.187.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 15-32.204.217.131.187.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
octageeks.com
2025-11-02 04:09:30
(9 months ago)
Wordpress malicious attack:[octa404]
Web App Attack
๐บ๐ธ
Psycho Solutions LLC
2025-04-24 08:47:58
(1 year ago)
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N ...
show more
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N/A - Timestamp: 4/24/2025 8:47 am (UTC-6)
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-03-24 09:35:06
(1 year ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
Anonymous
2025-02-27 14:23:33
(1 year ago)
wordpress-trap
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-02-24 12:01:21
(1 year ago)
WP Login Scan Activities
Web App Attack