🇺🇸
TPI-Abuse
2026-09-11 12:19:58
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 206.232.1.118 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.1.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 08:19:50.650231 2026] [security2:error] [pid 30026:tid 30026] [client 206.232.1.118:42217] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||campnecon.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "campnecon.com"] [uri "/mailto: [email protected] "] [unique_id "aqPx5twX0WWfhl6MtYB9dQAAAAk"], referer: http://campnecon.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-11 03:44:15
(1 day ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: HEAD | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: HEAD | path: /mailto:[email protected] | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36 | 2026-09-11 03:44 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:02:49
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 206.232.1.118 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.1.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:02:43.380880 2026] [security2:error] [pid 29247:tid 29247] [client 206.232.1.118:53013] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.garantaconsulting.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.garantaconsulting.com"] [uri "/mailto:[email protected] "] [unique_id "apptE1T6fSxqQAjGZcPWrwAAAAs"], referer: http://www.GarantaConsulting.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-04 10:25:36
(1 month ago)
FortiWeb WAF: 24 attacks detected. Threat Score: 11129180. Types: Client Management(12), Signature D ...
show more
FortiWeb WAF: 24 attacks detected. Threat Score: 11129180. Types: Client Management(12), Signature Detection(12). Origin: United States.
show less
Web App Attack
Anonymous
2026-07-22 23:54:28
(1 month ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2026-07-21 22:53:04
(1 month ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
🇱🇻
garmtech.com
2026-06-28 02:18:52
(2 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 05-18.206.232.1.118.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 05-18.206.232.1.118.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
🇱🇻
garmtech.com
2026-05-19 02:42:55
(3 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 05-42.206.232.1.118.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 05-42.206.232.1.118.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
🇱🇻
garmtech.com
2026-05-14 16:51:45
(3 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 19-51.206.232.1.118.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 19-51.206.232.1.118.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
🇱🇻
garmtech.com
2026-04-19 03:41:40
(4 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 06-41.206.232.1.118.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 06-41.206.232.1.118.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-04-10 21:41:48
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 206.232.1.118 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 206.232.1.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 10 17:41:41.207356 2026] [security2:error] [pid 2481961:tid 2481961] [client 206.232.1.118:28425] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||accinternational.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "accinternational.net"] [uri "/company-profile"] [unique_id "adlulZw96AxbKlwrX1hkyQAAAAk"], referer: https://accinternational.net/company-profile
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-09 02:05:42
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 206.232.1.118 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 206.232.1.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 22:05:32.942985 2026] [security2:error] [pid 3814199:tid 3814199] [client 206.232.1.118:30767] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||albrittonmcclain.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "albrittonmcclain.com"] [uri "/who-we-are"] [unique_id "adcJbCmHC2a1k_urmBI27QAAABA"], referer: https://albrittonmcclain.com/who-we-are
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-20 01:10:35
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 206.232.1.118 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 206.232.1.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 21:10:28.319283 2026] [security2:error] [pid 5254:tid 5254] [client 206.232.1.118:62921] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.serranoscoffee.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.serranoscoffee.com"] [uri "/"] [unique_id "abyehFu1LL6O_ETj77GoiwAAAAQ"], referer: https://www.serranoscoffee.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-14 12:50:10
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 206.232.1.118 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 206.232.1.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 08:49:25.292127 2026] [security2:error] [pid 10632:tid 10647] [client 206.232.1.118:63137] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||citydentalclinic.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "citydentalclinic.com"] [uri "/contact-us"] [unique_id "abVZVZjIQAnMsg1zHMIdIwAAAMo"], referer: https://citydentalclinic.com/contact-us
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-04 08:03:45
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 206.232.1.118 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 206.232.1.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 04 03:03:40.364506 2026] [security2:error] [pid 4981:tid 5001] [client 206.232.1.118:63545] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||certifiedpoliticalscientist.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "certifiedpoliticalscientist.com"] [uri "/contact"] [unique_id "aafnXBae0hLreeJnhWBcBQAAAVE"], referer: https://certifiedpoliticalscientist.com/contact
show less
Brute-Force
Bad Web Bot
Web App Attack