ππΊ
bcsaba
2026-09-16 03:09:22
(2 days ago)
Probing for .env file:
206.232.0.156 - - [16/Sep/2026:05:09:20 +0200] "GET /.env HTTP/1.1" 403 548 " ...
show more
Probing for .env file:
206.232.0.156 - - [16/Sep/2026:05:09:20 +0200] "GET /.env HTTP/1.1" 403 548 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 08:25:19
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 206.232.0.156 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.0.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 04:25:15.037070 2026] [security2:error] [pid 16309:tid 16309] [client 206.232.0.156:46209] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holgerfeld.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "aqkA66wEfVJTRdzPLXH8JAAAABE"], referer: http://HOLGERFELD.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 09:23:01
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 206.232.0.156 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.0.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:22:54.738125 2026] [security2:error] [pid 1689:tid 1689] [client 206.232.0.156:30159] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "apaZbgfDIRSzY5bXJ3jX3gAAABQ"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 02:49:23
(1 month ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
π±π»
garmtech.com
2026-07-08 05:38:11
(2 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 08-38.206.232.0.156.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 08-38.206.232.0.156.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
πΊπΈ
dtorrer
2026-05-11 00:54:25
(4 months ago)
Client attempted to submit spam on a website post.
Blog Spam
πΊπΈ
TPI-Abuse
2026-05-06 10:24:18
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.0.156 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.0.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 06 06:24:10.543422 2026] [security2:error] [pid 21423:tid 21423] [client 206.232.0.156:48943] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||americanexportimport.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "americanexportimport.com"] [uri "/mailto:[email protected] "] [unique_id "afsWykQXO2LgmqV8kbhUhAAAABU"], referer: http://americanexportimport.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Tilellit.PRO
2026-05-02 23:35:44
(4 months ago)
Fail2Ban banned 206.232.0.156 for security violations in jail nginx-aggressive. Log: 2026/05/02 23:3 ...
show more
Fail2Ban banned 206.232.0.156 for security violations in jail nginx-aggressive. Log: 2026/05/02 23:35:41 [crit] SSL_read() failed (SSL: error:0A00010B:SSL routines::wrong version number error:0A000139:SSL routines::record layer failure) while keepalive, client: 206.232.0.156, server: [REDACTED]
2026/05/02 23:35:43 [crit] SSL_read() failed (SSL: error:0A00010B:SSL routines::wrong version number error:0A000139:SSL routines::record layer failure) while keepalive, client: 206.232.0.156, server: [REDACTED]
...
show less
Bad Web Bot
Web App Attack
π±π»
garmtech.com
2026-04-02 05:29:00
(5 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 08-28.206.232.0.156.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 08-28.206.232.0.156.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-09 08:05:24
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.0.156 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.0.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 09 03:05:19.040881 2026] [security2:error] [pid 13687:tid 13713] [client 206.232.0.156:63447] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.clearwaterpumpservices.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.clearwaterpumpservices.com"] [uri "/mailto:[email protected] "] [unique_id "aWC2vx2PCATlpizBfeCoOgAAANg"], referer: https://www.clearwaterpumpservices.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-08 16:29:51
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.0.156 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.0.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 08 11:29:46.634659 2026] [security2:error] [pid 25092:tid 25092] [client 206.232.0.156:34959] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||persnicketyinc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "persnicketyinc.com"] [uri "/mailto:[email protected] "] [unique_id "aV_bekpGRemCgZ3qVP6megAAAAo"], referer: http://persnicketyinc.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-03 04:57:43
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.0.156 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.0.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 02 23:57:38.585349 2026] [security2:error] [pid 6553:tid 6553] [client 206.232.0.156:50509] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aVihwolHA-HmwMsWGKy-9AAAABQ"], referer: http://capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π±π»
garmtech.com
2025-12-20 16:27:40
(8 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 18-27.206.232.0.156.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 18-27.206.232.0.156.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
π©πͺ
SCHAPPY
2025-11-30 18:24:46
(9 months ago)
Critical web app attack detected. Illegal Accept header: charset parameter
Web App Attack
π¦πΊ
MAGIC
2025-10-25 04:04:55
(10 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot