Anonymous
2026-07-23 01:40:10
(1 month ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2026-07-21 23:58:20
(1 month ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐จ๐ฆ
1gz
2026-07-08 00:59:42
(1 month ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.127 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐จ๐ฆ
1gz
2026-07-08 00:59:42
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: CHALLENGE
Protocol: HTTP/1.1 (HEAD ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: CHALLENGE
Protocol: HTTP/1.1 (HEAD method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.127 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
todix
2026-06-25 23:44:07
(1 month ago)
WebAttack or semilar from 206.232.1.33
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-20 02:14:49
(2 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 05-14.206.232.1.33.web-spammer ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 05-14.206.232.1.33.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2026-04-18 01:13:59
(4 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 04-13.206.232.1.33.web-spammer ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 04-13.206.232.1.33.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 05:39:37
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.1.33 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.1.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:39:29.229997 2026] [security2:error] [pid 21514:tid 21514] [client 206.232.1.33:41775] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "abzdkcSLb_RFrVJMqAiocAAAABU"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-18 05:55:45
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 206.232.1.33 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 206.232.1.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 01:55:38.207419 2026] [security2:error] [pid 8589:tid 8589] [client 206.232.1.33:63825] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||friendlyfarm4fun.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "friendlyfarm4fun.com"] [uri "/company-profile"] [unique_id "abo-WnmZmS5fm6kEKeT3sQAAAAs"], referer: https://friendlyfarm4fun.com/company-profile
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-23 11:32:41
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.1.33 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.1.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 06:32:36.263049 2026] [security2:error] [pid 19820:tid 19820] [client 206.232.1.33:31013] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aZw61NVW1Ux2wh-xhfezoAAAABg"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
IROK
2026-01-27 01:31:18
(6 months ago)
Firewall Blocked - Unauthorized Port Scanning
...
Port Scan
๐ฑ๐ป
garmtech.com
2025-12-10 09:46:15
(8 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 11-46.206.232.1.33.web-spammer ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 11-46.206.232.1.33.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ณ๐ฑ
exxos
2025-10-25 19:03:02
(9 months ago)
HTTP1.x attacks
DDoS Attack
๐ฌ๐ง
Globe2
2025-10-03 07:28:47
(10 months ago)
[03/Oct/2025:08:28:41 +0100] YRVEhYLTQp3rYeYaxQ4qkniG 206.232.1.33 53264 91.212.212.13 443
[03/Oct/2 ...
show more
[03/Oct/2025:08:28:41 +0100] YRVEhYLTQp3rYeYaxQ4qkniG 206.232.1.33 53264 91.212.212.13 443
[03/Oct/2025:08:28:44 +0100] kgk52MprPlsJdOXsfRZVe2Qb 206.232.1.33 13766 91.212.212.13 443
[03/Oct/2025:08:28:45 +0100] zT7-2rnkgssflYYZcMX0PXjE 206.232.1.33 13766 91.212.212.13 443
...
show less
Web App Attack
๐จ๐ญ
backslash
2025-07-02 05:50:08
(1 year ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot