๐บ๐ธ
TPI-Abuse
2026-07-22 19:28:46
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 204.217.131.2 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.131.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 15:28:37.854713 2026] [security2:error] [pid 1231966:tid 1231966] [client 204.217.131.2:55735] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pharmaceuticalsalescertifications.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pharmaceuticalsalescertifications.com"] [uri "/mailto:[email protected] "] [unique_id "amEZ5bdwiYFMa4_OI7vfnwAAAAQ"], referer: http://www.pharmaceuticalsalescertifications.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-25 18:16:41
(3 weeks ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 21-16.204.217.131.2.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 21-16.204.217.131.2.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2026-04-19 09:34:00
(3 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 12-33.204.217.131.2.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 12-33.204.217.131.2.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-19 07:43:23
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.131.2 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.131.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 19 03:43:15.825892 2026] [security2:error] [pid 1727447:tid 1727447] [client 204.217.131.2:65291] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com:80|F|2"] [data "[email protected] "] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aeSHk9BT5qwp-EJhhW8dLAAAAAc"], referer: http://capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 02:45:18
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.131.2 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.131.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 22:45:13.498086 2026] [security2:error] [pid 12326:tid 12326] [client 204.217.131.2:43689] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aciSOaLL86VZSM1cvJq4AAAAAAc"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 16:08:44
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.131.2 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.131.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 12:08:40.101096 2026] [security2:error] [pid 13294:tid 13294] [client 204.217.131.2:35973] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||daveweisman.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "daveweisman.com"] [uri "/mailto:[email protected] "] [unique_id "acVaCMMEkhuveour0cayTAAAABI"], referer: https://daveweisman.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 06:00:22
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.131.2 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.131.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 01:00:17.667322 2026] [security2:error] [pid 1487:tid 1487] [client 204.217.131.2:59161] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aY698WSgja1Dp9dCU9drDQAAAAs"], referer: http://www.CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-10-03 00:35:06
(9 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐บ๐ธ
octageeks.com
2025-09-21 04:07:57
(10 months ago)
Wordpress malicious attack:[octa404]
Web App Attack
๐ช๐ธ
robotstxt
2025-08-06 23:51:12
(11 months ago)
204.217.131.2 - - [06/Aug/2025:23:50:11 +0000] "GET /mailto:[email protected] HTTP/1.1" 404 14195 "h ...
show more
204.217.131.2 - - [06/Aug/2025:23:50:11 +0000] "GET /mailto:[email protected] HTTP/1.1" 404 14195 "http://fundaciopacopuerto.cat" rt="0.423" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36" "-" h="fundaciopacopuerto.cat" sn="fundaciopacopuerto.cat" ru="/mailto:[email protected] " u="/index.php" ucs="-" ua="unix:/var/run/php/fundacio82.sock" us="404" uct="0.000" urt="0.422"
204.217.131.2 - - [06/Aug/2025:23:50:13 +0000] "GET /mailto:[email protected] HTTP/1.1" 404 14195 "http://fundaciopacopuerto.cat" rt="0.353" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36" "-" h="fundaciopacopuerto.cat" sn="fundaciopacopuerto.cat" ru="/mailto:[email protected] " u="/index.php" ucs="-" ua="unix:/var/run/php/fundacio82.sock" us="404" uct="0.000" urt="0.353"
204.217.131.2 - - [06/Aug/2025:23:50:15 +0000] "GET /mailto:[email protected] HTTP/1.1" 404 14195 "http://fundacio
...
show less
Bad Web Bot
๐บ๐ธ
Psycho Solutions LLC
2025-04-08 11:20:48
(1 year ago)
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N ...
show more
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N/A - Timestamp: 4/8/2025 11:20 am (UTC-6)
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2025-04-07 05:48:39
(1 year ago)
Accessed trap at '/wp-login.php'
Web App Attack
Anonymous
2025-02-28 17:10:36
(1 year ago)
wordpress-trap
Web App Attack
Anonymous
2025-02-23 14:47:58
(1 year ago)
wordpress-trap
Web App Attack
๐บ๐ธ
SiliSoftware
2024-10-31 21:32:19
(1 year ago)
/usr/share/nginx/html/adminer.php
Web App Attack