Anonymous
2026-07-22 02:52:20
(12 hours ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-19 22:34:10
(1 month ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 01-34.204.217.131.79.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 01-34.204.217.131.79.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฆ๐บ
MAGIC
2026-05-28 02:06:13
(1 month ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-15 13:43:31
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.131.79 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.131.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 15 09:43:23.350661 2026] [security2:error] [pid 1861472:tid 1861472] [client 204.217.131.79:55921] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "ad-V-xUWujoUk5NZEBMc5QAAAAw"], referer: http://www.CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-04-13 05:44:13
(3 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 08-44.204.217.131.79.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 08-44.204.217.131.79.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-12 06:41:27
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.131.79 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.131.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 12 02:41:22.340359 2026] [security2:error] [pid 3838340:tid 3838340] [client 204.217.131.79:40189] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.holgerfeld.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "ads-knDz9YC-kbOdERhUvAAAABU"], referer: http://www.holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 07:30:12
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.131.79 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.131.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 03:30:02.016637 2026] [security2:error] [pid 4978:tid 4978] [client 204.217.131.79:26233] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "acjU-q9J5YUTNDN0nq-18AAAAAA"], referer: http://www.capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-03-24 02:47:26
(3 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 04-47.204.217.131.79.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 04-47.204.217.131.79.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-24 07:50:10
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.131.79 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.131.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 24 02:50:03.474222 2026] [security2:error] [pid 15029:tid 15029] [client 204.217.131.79:35691] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.holgerfeld.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "aZ1YKxW0cdPtQEAfRnxm7AAAAAY"], referer: http://www.holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-22 12:27:22
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 204.217.131.79 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 204.217.131.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 07:27:18.049814 2026] [security2:error] [pid 8010:tid 8010] [client 204.217.131.79:37969] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aZr2JiU77OnGKwMC0M76CwAAABs"], referer: http://www.capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
gnom4ik
2026-02-21 18:53:58
(5 months ago)
ban-reviewer auto report; ip=204.217.131.79; scenario=http:scan; verdict=valid_ban; confidence=0.85; ...
show more
ban-reviewer auto report; ip=204.217.131.79; scenario=http:scan; verdict=valid_ban; confidence=0.85; categories=14,15,18; active_decisions=1; lookback_decisions=1; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=IP flagged for HTTP scanning activity; Decision made by CAPI with 7920m duration; Appears in abuseipdb port scan category (14)
show less
Port Scan
Hacking
Brute-Force
๐ฌ๐ง
Globe2
2025-10-03 08:53:06
(9 months ago)
[03/Oct/2025:09:53:01 +0100] PDGYeUBahAV7L-MdYbJOPMKJ 204.217.131.79 54008 91.212.212.13 443
[03/Oct ...
show more
[03/Oct/2025:09:53:01 +0100] PDGYeUBahAV7L-MdYbJOPMKJ 204.217.131.79 54008 91.212.212.13 443
[03/Oct/2025:09:53:03 +0100] hGp2gvD-Uz1rrdxV1No8xV1Q 204.217.131.79 59696 91.212.212.13 443
[03/Oct/2025:09:53:04 +0100] gOQ6GMdfvHNqga2tqOkfYp3j 204.217.131.79 59696 91.212.212.13 443
...
show less
Web App Attack
๐ฆ๐บ
MAGIC
2025-05-18 10:00:34
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
Psycho Solutions LLC
2025-04-11 11:56:35
(1 year ago)
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N ...
show more
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N/A - Timestamp: 4/11/2025 11:56 am (UTC-6)
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-04-02 12:48:58
(1 year ago)
WP Login Scan Activities
Web App Attack