๐บ๐ธ
TPI-Abuse
2026-08-22 14:28:34
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 206.232.1.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.1.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 10:28:28.502519 2026] [security2:error] [pid 28858:tid 28858] [client 206.232.1.96:64727] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||energycapitalinvestments.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "energycapitalinvestments.com"] [uri "/mailto:[email protected] "] [unique_id "aomyDC6f6_TrwmLzPj_vrQAAAA0"], referer: http://EnergyCapitalInvestments.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-04 11:22:52
(2 weeks ago)
FortiWeb WAF: 32 attacks detected. Threat Score: 10685680. Types: Client Management(16), Signature D ...
show more
FortiWeb WAF: 32 attacks detected. Threat Score: 10685680. Types: Client Management(16), Signature Detection(16). Origin: United States.
show less
Web App Attack
Anonymous
2026-07-22 04:02:32
(1 month ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 12:17:48
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.1.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.1.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 08:17:41.066885 2026] [security2:error] [pid 28831:tid 28831] [client 206.232.1.96:33163] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "acu7ZXesTiJiqnD7_2QD2wAAACI"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-26 03:33:17
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.1.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.1.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 22:33:13.442163 2026] [security2:error] [pid 8359:tid 8359] [client 206.232.1.96:43345] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.holgerfeld.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "aZ---dVLG3OUM705oiQTqAAAAC0"], referer: http://www.holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-17 17:48:19
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.1.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.1.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 17 12:48:16.100015 2026] [security2:error] [pid 20593:tid 20593] [client 206.232.1.96:49687] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aZSp4PngrK9w787-Q_5hmgAAABw"], referer: http://capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
octageeks.com
2025-11-02 04:08:08
(9 months ago)
Wordpress malicious attack:[octa404]
Web App Attack
๐ณ๐ฑ
exxos
2025-10-26 20:03:01
(9 months ago)
Attacks with Bad user agents
Hacking
๐ต๐ฑ
sefinek.net
2025-10-25 01:22:05
(9 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (HEAD method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
Nucuta
2025-09-29 13:31:01
(10 months ago)
2025-09-29 13:31:01 UTC | vorbelutr ioperbir | [email protected] | http://www.vorbelutrioperbir.co ...
show more
2025-09-29 13:31:01 UTC | vorbelutr ioperbir | [email protected] | http://www.vorbelutrioperbir.com | 206.232.1.96 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36 | Rattling superb info can be found on weblog. | comment
show less
Blog Spam
๐บ๐ธ
Psycho Solutions LLC
2025-04-06 17:20:36
(1 year ago)
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N ...
show more
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N/A - Timestamp: 4/6/2025 5:20 pm (UTC-6)
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
Psycho Solutions LLC
2025-04-04 05:33:34
(1 year ago)
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N ...
show more
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N/A - Timestamp: 4/4/2025 5:33 am (UTC-6)
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
ph
2025-04-04 03:20:14
(1 year ago)
Bad web bot attempting to run wp-login.php on non-WP site
Hacking
Bad Web Bot
Web App Attack
Anonymous
2025-03-01 06:21:09
(1 year ago)
wordpress-trap
Web App Attack
๐น๐ผ
kk_it_man
2022-05-30 10:09:41
(4 years ago)
hack
Hacking