Anonymous
2026-07-26 22:49:24
(18 hours ago)
Attack detected: 206.232.2.152 [2026-07-26]
Categories: 21
--- wp2shell/batch exploit (1 hits) ---
2 ...
show more
Attack detected: 206.232.2.152 [2026-07-26]
Categories: 21
--- wp2shell/batch exploit (1 hits) ---
206.232.2.152 - - [26/Jul/2026:22:30:13 +0000] "GET /wp-json/ HTTP/1.1" 200 1482050 "-" "wp2shell"
show less
Web App Attack
Anonymous
2026-07-23 01:42:25
(4 days ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2026-07-22 01:08:56
(5 days ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-12 05:15:30
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 206.232.2.152 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.2.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 01:15:24.083772 2026] [security2:error] [pid 3040:tid 3040] [client 206.232.2.152:29867] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holgerfeld.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "aiuV7C1khUkP_wMfopXD6wAAAA0"], referer: http://holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
MAGIC
2026-05-23 01:07:55
(2 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
π±π»
garmtech.com
2026-05-01 09:32:31
(2 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 12-32.206.232.2.152.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 12-32.206.232.2.152.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-29 03:56:42
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.2.152 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.2.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 23:56:34.846070 2026] [security2:error] [pid 3183:tid 3183] [client 206.232.2.152:47009] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "acii8klDdWAVanuPXEXeGwAAAAw"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
kranem
2026-02-13 09:00:41
(5 months ago)
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 174 (COGENT-174 - Cogent Communications, ...
show more
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 174 (COGENT-174 - Cogent Communications, LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-02-13T08:45:27Z
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.93 Safari/537.36
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-02-12 19:48:47
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.2.152 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.2.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 14:48:40.989374 2026] [security2:error] [pid 22604:tid 22604] [client 206.232.2.152:55141] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||HOLGERFELD.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "aY4umLrHlTHBixhoXm27JQAAAAA"], referer: http://HOLGERFELD.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-10 19:15:52
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.2.152 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.2.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 14:15:46.118343 2026] [security2:error] [pid 2043:tid 2043] [client 206.232.2.152:48913] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aYuD4lqS45G683WoOHOc3gAAAAA"], referer: http://www.CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-06 04:02:29
(9 months ago)
Web attack
Bad Web Bot
Web App Attack
π¬π§
Nucuta
2025-09-30 11:40:32
(9 months ago)
2025-09-30 11:40:32 UTC | vorbelutrioperbir | Noeldner47855@gmail. | http://www.vorbelutrioperbir.co ...
show more
2025-09-30 11:40:32 UTC | vorbelutrioperbir | Noeldner47855@gmail. | http://www.vorbelutrioperbir.com | 206.232.2.152 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36 | Pretty great post. I simply stumbled upon your weblog and wished to mention that I\'ve truly loved browsing your blog posts. After all I will be subscribing on your rss feed and I\'m hoping you write once more very soon! | comment
show less
Blog Spam
π¨π
backslash
2025-07-16 09:45:10
(1 year ago)
block ruleset Scripted User Agents D354E26D7B65FC5B6A63DC32B9B81A1BEDFEB309
Bad Web Bot
π¨π
backslash
2025-05-23 20:00:15
(1 year ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
π«π·
tecnicorioja
2025-04-25 22:00:54
(1 year ago)
wp-login attack [25/Apr/2025:22:38:15
Brute-Force
Web App Attack