Anonymous
2026-07-22 00:06:32
(1 month ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐ต๐ฑ
sefinek.net
2026-06-28 03:13:42
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (H ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (HEAD) | Endpoint: /genshin-stella-mod | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
Steve
2026-04-07 02:04:03
(4 months ago)
Forum Spam
Web Spam
๐บ๐ธ
TPI-Abuse
2026-03-22 20:33:56
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.0.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.0.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 16:33:47.938271 2026] [security2:error] [pid 25147:tid 25147] [client 206.232.0.5:44797] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "acBSK3pCEatAasgDQUSHwQAAABk"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-03-21 06:49:34
(5 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:08-49.206.232.0.5
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-02-21 08:40:17
(6 months ago)
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 5.0.232.206.rbl.malware ...
show more
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 5.0.232.206.rbl.malware.expert succeeded at REQUEST_HEADERS:x-forwarded-for. (1001000-mnz6-3)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-01-12 02:08:00
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.0.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.0.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 11 21:07:53.718957 2026] [security2:error] [pid 12907:tid 12907] [client 206.232.0.5:63583] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||panierduvillage.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "panierduvillage.com"] [uri "/mysql.sql"] [unique_id "aWRXefAkjHORqk0-VuiW2AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-03 03:53:56
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.0.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.0.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 02 22:53:49.924749 2026] [security2:error] [pid 27481:tid 27481] [client 206.232.0.5:26551] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aViSzRnoW6oFUabI61Va1gAAAAg"], referer: http://capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2025-11-27 04:16:42
(8 months ago)
Critical web app attack detected. Illegal Accept header: charset parameter
Web App Attack
๐ฑ๐ป
garmtech.com
2025-09-30 13:38:26
(10 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 16-38.206.232.0.5.web-spammers ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 16-38.206.232.0.5.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
Psycho Solutions LLC
2025-04-12 17:03:05
(1 year ago)
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N ...
show more
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N/A - Timestamp: 4/12/2025 5:03 pm (UTC-6)
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-04-04 09:03:17
(1 year ago)
WP Login Scan Activities
Web App Attack
Anonymous
2025-02-25 07:16:45
(1 year ago)
wordpress-trap
Web App Attack