๐ฉ๐ช
big-cloud.nl
2026-10-07 13:12:14
(4 hours ago)
Try to access /huisje-huren/.git/HEAD
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 10:45:17
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 206.232.0.111 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.0.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 06:45:11.709799 2026] [security2:error] [pid 30408:tid 30408] [client 206.232.0.111:35687] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||HOLGERFELD.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "asN_t8-Th2MbipcbfkxfiwAAAA0"], referer: http://HOLGERFELD.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 11:06:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 206.232.0.111 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 206.232.0.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 07:06:27.914855 2026] [security2:error] [pid 10723:tid 10723] [client 206.232.0.111:46263] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eaglespiritproductions.net"] [uri "/.git/HEAD"] [unique_id "arj4s6pOb5Q-TvPLrv2HVwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-20 00:36:11
(2 weeks ago)
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 206.232.0.111 - - [20/Sep/2026:02:36:00 +0200] "GET /.git/HEAD HTTP/1.1" 404 12711 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:153.0) Gecko/20100101 Firefox/153.0"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-17 05:23:29
(2 weeks ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: /occitanie | 2026-09-17 05:23 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-11 12:52:55
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 206.232.0.111 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.0.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 08:52:48.687180 2026] [security2:error] [pid 15270:tid 15270] [client 206.232.0.111:54297] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.investorsfundingusa.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.investorsfundingusa.com"] [uri "/mailto:[email protected] "] [unique_id "aqP5oO0cycCuhmSUfzXI9wAAAAI"], referer: http://www.InvestorsFundingUSA.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฎ
administrator
2026-09-04 22:12:32
(1 month ago)
2026-08-30 00:10:22,970 fail2ban.actions [1074]: NOTICE [error-bots] Ban 206.232.0.111
2026- ...
show more
2026-08-30 00:10:22,970 fail2ban.actions [1074]: NOTICE [error-bots] Ban 206.232.0.111
2026-08-30 00:10:22,970 fail2ban.actions [1074]: NOTICE [error-bots] Ban 206.232.0.111
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 20:28:00
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 206.232.0.111 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.0.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 16:27:50.984696 2026] [security2:error] [pid 24849:tid 24849] [client 206.232.0.111:44755] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "apc1Rh7JGGDJQTCDyxTjAwAAAAU"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 19:40:15
(1 month ago)
| SQL injection attempt.
Web App Attack
Hacking
SQL Injection
Anonymous
2026-08-04 11:39:05
(2 months ago)
FortiWeb WAF: 20 attacks detected. Threat Score: 10509080. Types: Client Management(10), Signature D ...
show more
FortiWeb WAF: 20 attacks detected. Threat Score: 10509080. Types: Client Management(10), Signature Detection(10). Origin: United States.
show less
Web App Attack
Anonymous
2026-07-22 02:42:24
(2 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
dtorrer
2026-06-03 05:44:31
(4 months ago)
Client attempted to submit spam on a website post.
Blog Spam
๐บ๐ธ
TPI-Abuse
2026-04-08 04:56:29
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.0.111 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.0.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 00:56:21.015964 2026] [security2:error] [pid 2235017:tid 2235017] [client 206.232.0.111:59461] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.americanexportimport.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.americanexportimport.com"] [uri "/mailto:[email protected] "] [unique_id "adXf9feDjQIvwG6GEUVExAAAAAI"], referer: http://www.americanexportimport.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-23 03:20:16
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.0.111 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.0.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 23:20:08.002729 2026] [security2:error] [pid 20618:tid 20618] [client 206.232.0.111:43557] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "acCxZ2c3x22XYtzpNPnxXwAAAAc"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-22 19:09:07
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.0.111 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.0.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 14:09:04.704604 2026] [security2:error] [pid 16152:tid 16152] [client 206.232.0.111:61355] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aZtUUOxtWEp5wWaprMMSngAAABI"], referer: http://www.capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack