πΊπΈ
TPI-Abuse
2026-09-02 19:48:06
(14 minutes ago)
(mod_security) mod_security (id:210730) triggered by 206.232.2.92 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.2.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 15:47:55.790166 2026] [security2:error] [pid 11334:tid 11334] [client 206.232.2.92:32109] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aph9az_MPmSA_wD-m5z1tQAAABQ"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 08:10:38
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 206.232.2.92 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.2.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 04:10:32.099830 2026] [security2:error] [pid 30868:tid 30868] [client 206.232.2.92:53225] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||constructionloansfunding.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "constructionloansfunding.com"] [uri "/mailto:[email protected] "] [unique_id "apFCeCk5hVQ4R13bpViffwAAAA8"], referer: http://constructionloansfunding.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 03:34:15
(1 month ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-14 13:08:23
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.2.92 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.2.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 09:08:15.195457 2026] [security2:error] [pid 9230:tid 9230] [client 206.232.2.92:39161] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.cayman-islands-real-estate.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.cayman-islands-real-estate.com"] [uri "/mailto:[email protected] "] [unique_id "ai6nv8HLzp_PT7VFHn3l9gAAAAw"], referer: https://www.cayman-islands-real-estate.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
rsa
2026-05-28 19:18:00
(3 months ago)
excessive crawling ddos
DDoS Attack
Bad Web Bot
Web App Attack
π±π»
garmtech.com
2026-05-28 05:46:31
(3 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 08-46.206.232.2.92.web-spammer ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 08-46.206.232.2.92.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
π±π»
garmtech.com
2026-04-19 10:00:55
(4 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 13-00.206.232.2.92.web-spammer ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 13-00.206.232.2.92.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
π±π»
garmtech.com
2026-04-15 20:40:07
(4 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 23-40.206.232.2.92.web-spammer ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 23-40.206.232.2.92.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
π«π·
Tilellit.PRO
2026-04-09 23:44:36
(4 months ago)
Fail2Ban banned 206.232.2.92 for security violations in jail nginx-aggressive. Log: 2026/04/09 23:44 ...
show more
Fail2Ban banned 206.232.2.92 for security violations in jail nginx-aggressive. Log: 2026/04/09 23:44:33 [crit] SSL_read() failed (SSL: error:0A00010B:SSL routines::wrong version number error:0A000139:SSL routines::record layer failure) while keepalive, client: 206.232.2.92, server: [REDACTED]
2026/04/09 23:44:36 [crit] SSL_read() failed (SSL: error:0A00010B:SSL routines::wrong version number error:0A000139:SSL routines::record layer failure) while keepalive, client: 206.232.2.92, server: [REDACTED]
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-28 07:12:20
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.2.92 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.2.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 03:12:15.122513 2026] [security2:error] [pid 30181:tid 30181] [client 206.232.2.92:47709] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "acd_TyC5tIZgejz2qeMm8QAAAA4"], referer: http://www.capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-03 08:03:50
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.2.92 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.2.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 03 03:03:43.965383 2026] [security2:error] [pid 12712:tid 12712] [client 206.232.2.92:38123] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aVjNX4vfe9VZlH4_JXHjYwAAAAY"], referer: http://capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-03 06:50:57
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 206.232.2.92 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 206.232.2.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 03 01:50:52.235616 2025] [security2:error] [pid 31199:tid 31199] [client 206.232.2.92:44521] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rogerbrooks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rogerbrooks.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQhQzJVvAbd-2PJnOARScgAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-03 04:04:36
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 206.232.2.92 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 206.232.2.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 02 23:04:32.122833 2025] [security2:error] [pid 14421:tid 14421] [client 206.232.2.92:45189] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||insidepublications.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "insidepublications.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQgp0Da2C1a7woo1VpHzPQAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
backslash
2025-11-03 01:40:07
(9 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
π¦πΊ
MAGIC
2025-10-30 02:21:56
(10 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot