๐ช๐ธ
gnom4ik
2026-02-20 20:05:53
(5 months ago)
ban-reviewer auto report; ip=42.236.101.237; scenario=http:scan; verdict=valid_ban; confidence=0.85; ...
show more
ban-reviewer auto report; ip=42.236.101.237; scenario=http:scan; verdict=valid_ban; confidence=0.85; categories=14,15,18,22; active_decisions=1; lookback_decisions=1; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=IP flagged for 'http:scan' scenario; Port Scan (category 14) is in default categories; Hacking (category 15) is in default categories; Brute-Force (category 18) is in default categories; SSH (category 22) is in default categories
show less
Port Scan
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-01-29 09:43:22
(5 months ago)
(mod_security) mod_security (id:210831) triggered by 42.236.101.237 (hn.kd.ny.adsl): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210831) triggered by 42.236.101.237 (hn.kd.ny.adsl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 29 04:43:13.885763 2026] [security2:error] [pid 19635:tid 19635] [client 42.236.101.237:48005] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||forsythfixit.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "forsythfixit.com"] [uri "/index.htm"] [unique_id "aXsrsRmAEq35g22Vx0QIwwAAAAo"], referer: http://forsythfixit.com/index.htm
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-29 09:01:09
(5 months ago)
(mod_security) mod_security (id:210831) triggered by 42.236.101.237 (hn.kd.ny.adsl): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210831) triggered by 42.236.101.237 (hn.kd.ny.adsl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 29 04:01:00.781175 2026] [security2:error] [pid 23337:tid 23337] [client 42.236.101.237:60778] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||lynellejonsson.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "lynellejonsson.com"] [uri "/"] [unique_id "aXshzN2bIC9HjbTCn2YkxQAAAAM"], referer: http://lynellejonsson.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-29 08:20:27
(5 months ago)
(mod_security) mod_security (id:210831) triggered by 42.236.101.237 (hn.kd.ny.adsl): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210831) triggered by 42.236.101.237 (hn.kd.ny.adsl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 29 03:20:22.932646 2026] [security2:error] [pid 20959:tid 20959] [client 42.236.101.237:40042] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||valbreniscrivalbo.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "valbreniscrivalbo.com"] [uri "/"] [unique_id "aXsYRqVd41OIcFC7csy8sQAAAAA"], referer: http://valbreniscrivalbo.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-29 06:51:11
(5 months ago)
(mod_security) mod_security (id:210831) triggered by 42.236.101.237 (hn.kd.ny.adsl): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210831) triggered by 42.236.101.237 (hn.kd.ny.adsl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 29 01:51:07.091002 2026] [security2:error] [pid 2105502:tid 2105502] [client 42.236.101.237:11292] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.grhall.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.grhall.com"] [uri "/"] [unique_id "aXsDW4S4y7hLUo9Y4NBbYwAAAAA"], referer: http://www.grhall.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-28 14:28:07
(5 months ago)
(mod_security) mod_security (id:210831) triggered by 42.236.101.237 (hn.kd.ny.adsl): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210831) triggered by 42.236.101.237 (hn.kd.ny.adsl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 28 09:28:01.013951 2026] [security2:error] [pid 25581:tid 25581] [client 42.236.101.237:12690] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||vanessalends.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "vanessalends.com"] [uri "/"] [unique_id "aXoc8e6KTerlq5lHlWX6ugAAAA4"], referer: http://vanessalends.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ณ
ThreatBook.io
2026-01-27 22:02:44
(5 months ago)
ThreatBook Intelligence: IDC more details on http://threatbook.io/ip/42.236.101.237
2026-01-27 17:23 ...
show more
ThreatBook Intelligence: IDC more details on http://threatbook.io/ip/42.236.101.237
2026-01-27 17:23:51 /group.html
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-27 03:28:54
(5 months ago)
(mod_security) mod_security (id:210831) triggered by 42.236.101.237 (hn.kd.ny.adsl): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210831) triggered by 42.236.101.237 (hn.kd.ny.adsl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 26 22:28:49.761682 2026] [security2:error] [pid 23744:tid 23806] [client 42.236.101.237:46520] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.heworeblack.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.heworeblack.com"] [uri "/"] [unique_id "aXgw8WCnSCn9fR9zp0b4KwAAAQo"], referer: http://www.heworeblack.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-26 07:05:15
(5 months ago)
(mod_security) mod_security (id:210831) triggered by 42.236.101.237 (hn.kd.ny.adsl): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210831) triggered by 42.236.101.237 (hn.kd.ny.adsl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 26 02:05:09.511749 2026] [security2:error] [pid 28687:tid 28687] [client 42.236.101.237:27039] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.praiseworthy.info|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.praiseworthy.info"] [uri "/"] [unique_id "aXcSJX-dl343lOsdGKWQIwAAABA"], referer: http://www.praiseworthy.info/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-10-21 22:02:06
(9 months ago)
ThreatBook Intelligence: Zombie,IDC more details on https://threatbook.io/ip/42.236.101.237
2025-10- ...
show more
ThreatBook Intelligence: Zombie,IDC more details on https://threatbook.io/ip/42.236.101.237
2025-10-21 04:23:58 /dfdfd
show less
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-10-17 22:07:44
(9 months ago)
ThreatBook Intelligence: Zombie,IDC more details on https://threatbook.io/ip/42.236.101.237
2025-10- ...
show more
ThreatBook Intelligence: Zombie,IDC more details on https://threatbook.io/ip/42.236.101.237
2025-10-17 00:13:39 /robots.txt
show less
Web App Attack
๐ฉ๐ช
Hazzard
2025-10-12 06:19:04
(9 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐จ๐ฆ
Mediashaker
2025-10-09 10:39:33
(9 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 42.236.101.237 (CN/C ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 42.236.101.237 (CN/China/hn.kd.ny.adsl)
show less
Bad Web Bot
๐ฉ๐ช
rh24
2025-10-09 07:23:08
(9 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 42.236.101.237 (CN/C ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 42.236.101.237 (CN/China/hn.kd.ny.adsl)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-10-03 06:15:54
(9 months ago)
(mod_security) mod_security (id:243420) triggered by 42.236.101.237 (hn.kd.ny.adsl): 1 in the last 3 ...
show more
(mod_security) mod_security (id:243420) triggered by 42.236.101.237 (hn.kd.ny.adsl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 03 02:15:48.428513 2025] [security2:error] [pid 19605:tid 19605] [client 42.236.101.237:12126] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Cookie" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.iclpost.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.iclpost.com"] [uri "/index.php"] [unique_id "aN9qEgfCzH2dR6-YnWhUNwAAAAE"], referer: https://www.iclpost.com/
show less
Brute-Force
Bad Web Bot
Web App Attack