๐บ๐ธ
TPI-Abuse
2026-08-26 11:04:31
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 206.232.1.109 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.1.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 07:04:25.668871 2026] [security2:error] [pid 4384:tid 4384] [client 206.232.1.109:48241] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holgerfeld.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "ao7IOWzNMrcKJRvIZ2buNgAAAAg"], referer: http://holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
IRT@Unisi
2026-08-03 01:35:35
(3 weeks ago)
Multiple web server 400 error codes from same source ip.
Bad Web Bot
Anonymous
2026-07-21 22:57:57
(1 month ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 22:25:17
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.1.109 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.1.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 18:25:13.767113 2026] [security2:error] [pid 32001:tid 32001] [client 206.232.1.109:32795] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.cayman-islands-real-estate.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.cayman-islands-real-estate.com"] [uri "/mailto:[email protected] "] [unique_id "ajB7yae0PKaFVxYp0aLrJgAAAAk"], referer: https://www.cayman-islands-real-estate.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-06-12 00:36:43
(2 months ago)
Fail2Ban banned 206.232.1.109 for security violations in jail nginx-aggressive. Log: 2026/06/12 00:3 ...
show more
Fail2Ban banned 206.232.1.109 for security violations in jail nginx-aggressive. Log: 2026/06/12 00:36:40 [crit] SSL_read() failed (SSL: error:0A00010B:SSL routines::wrong version number error:0A000139:SSL routines::record layer failure) while keepalive, client: 206.232.1.109, server: [REDACTED]
2026/06/12 00:36:42 [crit] SSL_read() failed (SSL: error:0A00010B:SSL routines::wrong version number error:0A000139:SSL routines::record layer failure) while keepalive, client: 206.232.1.109, server: [REDACTED]
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 01:17:35
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.1.109 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.1.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 21:17:30.383567 2026] [security2:error] [pid 4427:tid 4427] [client 206.232.1.109:40505] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.holgerfeld.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "aii7KiulE_o3FSOl_zCHswAAAAM"], referer: http://www.holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Steve
2026-06-03 20:24:59
(2 months ago)
Forum Spam
Web Spam
๐ต๐ฑ
sefinek.net
2026-05-03 02:51:41
(3 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (H ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (HEAD) | Endpoint: / | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฑ๐ป
garmtech.com
2026-04-17 19:46:18
(4 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 22-46.206.232.1.109.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 22-46.206.232.1.109.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-23 00:02:09
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.1.109 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.1.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 20:02:02.819995 2026] [security2:error] [pid 3123:tid 3123] [client 206.232.1.109:56861] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "acCC-loJOwlvUYHpKKS-TQAAABI"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
gnom4ik
2026-02-22 04:24:35
(6 months ago)
ban-reviewer auto report; ip=206.232.1.109; scenario=http:scan; verdict=valid_ban; confidence=0.90; ...
show more
ban-reviewer auto report; ip=206.232.1.109; scenario=http:scan; verdict=valid_ban; confidence=0.90; categories=14,15,18; active_decisions=1; lookback_decisions=1; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=IP flagged for HTTP scanning activity; Decision based on port scan detection (category 14); Single IP with no prior active decisions suggests new threat
show less
Port Scan
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-01-03 08:34:33
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.1.109 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.1.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 03 03:34:29.140135 2026] [security2:error] [pid 6813:tid 6813] [client 206.232.1.109:63169] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aVjUlclcik8ayPSwHI7CMQAAACE"], referer: http://capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2025-12-21 07:51:09
(8 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 09-51.206.232.1.109.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 09-51.206.232.1.109.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-17 21:09:28
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.1.109 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.1.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 17 16:09:20.801622 2025] [security2:error] [pid 6002:tid 6002] [client 206.232.1.109:32951] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||constructionloansfunding.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "constructionloansfunding.com"] [uri "/mailto:[email protected] "] [unique_id "aUMcAJWcRx5LBclWuC_bxQAAAAg"], referer: http://constructionloansfunding.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-04-04 17:50:04
(1 year ago)
WP Login Scan Activities
Web App Attack