Anonymous
2026-07-23 01:02:30
(7 hours ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2026-07-22 00:55:35
(1 day ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 10:08:46
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 206.232.2.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.2.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 06:08:42.890986 2026] [security2:error] [pid 4580:tid 4580] [client 206.232.2.67:54275] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holgerfeld.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "aiFOqp4VoChKngkFJcZyiAAAABQ"], referer: http://holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2026-06-02 00:06:22
(1 month ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฑ๐ป
garmtech.com
2026-05-18 07:50:42
(2 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 10-50.206.232.2.67.web-spammer ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 10-50.206.232.2.67.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-17 20:51:19
(2 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 23-51.206.232.2.67.web-spammer ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 23-51.206.232.2.67.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-15 00:00:32
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.2.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.2.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 14 20:00:28.323437 2026] [security2:error] [pid 888035:tid 888035] [client 206.232.2.67:47133] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "ad7VHB0E7NmYFmkLFDXt2wAAAAE"], referer: http://www.CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-28 06:58:37
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.2.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.2.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 02:58:29.776380 2026] [security2:error] [pid 16910:tid 16910] [client 206.232.2.67:34383] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "acd8FZXOhcMLW7wrkrJouwAAAAs"], referer: http://www.capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-03-22 20:50:38
(4 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:22-50.206.232.2.67
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-22 07:02:06
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 206.232.2.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 206.232.2.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 03:01:05.188649 2026] [security2:error] [pid 28125:tid 28125] [client 206.232.2.67:45351] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||cayman-islands-real-estate.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "cayman-islands-real-estate.com"] [uri "/about"] [unique_id "ab-TsbQ4PpEAOCY-kfeGCQAAAA4"], referer: https://cayman-islands-real-estate.com/about
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-03-21 12:06:35
(4 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:14-06.206.232.2.67
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-11 01:39:07
(4 months ago)
(mod_security) mod_security (id:210350) triggered by 206.232.2.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 206.232.2.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 10 21:39:01.611955 2026] [security2:error] [pid 21287:tid 21302] [client 206.232.2.67:44591] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||adprospb.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "adprospb.com"] [uri "/"] [unique_id "abDHtRXUX1TrgS4LoX2MYwAAAAk"], referer: https://adprospb.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-03-09 09:35:12
(4 months ago)
Fail2Ban banned 206.232.2.67 for security violations in jail nginx-aggressive. Log: 2026/03/09 09:35 ...
show more
Fail2Ban banned 206.232.2.67 for security violations in jail nginx-aggressive. Log: 2026/03/09 09:35:10 [crit] SSL_read() failed (SSL: error:0A00010B:SSL routines::wrong version number error:0A000139:SSL routines::record layer failure) while keepalive, client: 206.232.2.67, server: [REDACTED]
2026/03/09 09:35:11 [crit] SSL_read() failed (SSL: error:0A00010B:SSL routines::wrong version number error:0A000139:SSL routines::record layer failure) while keepalive, client: 206.232.2.67, server: [REDACTED]
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-22 08:13:15
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.2.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.2.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 03:13:12.817514 2026] [security2:error] [pid 7317:tid 7317] [client 206.232.2.67:51197] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.americanexportimport.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.americanexportimport.com"] [uri "/mailto:[email protected] "] [unique_id "aZq6mHLmz9kgt3YlcFEksAAAAA4"], referer: http://www.americanexportimport.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-02-08 15:25:45
(5 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 17-25.206.232.2.67.web-spammer ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 17-25.206.232.2.67.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack