Mendip_Defender
2025-03-20 02:54:30
(6 days ago)
47.128.112.172 - - [20/Mar/2025:02:54:26 +0000] "GET /?page=4&pp=25&searchid=1786286 HTTP/1.0" 301 9 ... show more 47.128.112.172 - - [20/Mar/2025:02:54:26 +0000] "GET /?page=4&pp=25&searchid=1786286 HTTP/1.0" 301 928 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] )"
... show less
Bad Web Bot
TPI-Abuse
2025-03-18 10:54:17
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 47.128.112.172 (ec2-47-128-112-172.ap-southeast ... show more (mod_security) mod_security (id:210730) triggered by 47.128.112.172 (ec2-47-128-112-172.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 18 06:54:13.072738 2025] [security2:error] [pid 264131:tid 264131] [client 47.128.112.172:60696] [client 47.128.112.172] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||med-engineering.com|F|2"] [data ".pacificcrestservices.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "med-engineering.com"] [uri "/www.pacificcrestservices.com"] [unique_id "Z9lQ1e4ROrLb4YFU_i5JjAAAABM"] show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-03-11 06:22:46
(2 weeks ago)
Ports: 80,443; Direction: 1; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-03-07 15:14:39
(2 weeks ago)
Excessive crawling/scraping
Hacking
Brute-Force
Steve
2025-03-05 04:08:54
(3 weeks ago)
Excessive crawling - not obeying robots.txt
Bad Web Bot
Mendip_Defender
2025-02-26 09:56:34
(1 month ago)
47.128.112.172 - - [26/Feb/2025:09:56:31 +0000] "GET /?faq=vb3_user_profile&s=0c9967e3e19558de6ac2a8 ... show more 47.128.112.172 - - [26/Feb/2025:09:56:31 +0000] "GET /?faq=vb3_user_profile&s=0c9967e3e19558de6ac2a82e0ecc76eb HTTP/1.0" 200 10099 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] )"
... show less
Bad Web Bot
backslash
2025-02-25 02:40:11
(1 month ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
Steve
2025-02-19 01:37:39
(1 month ago)
Excessive crawling - not obeying robots.txt
Bad Web Bot
MAGIC
2025-02-18 08:00:38
(1 month ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Mendip_Defender
2025-02-16 08:21:48
(1 month ago)
47.128.112.172 - - [16/Feb/2025:08:21:45 +0000] "GET /?%3Fs=0b61db050f0fe523eea5511d7957259b HTTP/1. ... show more 47.128.112.172 - - [16/Feb/2025:08:21:45 +0000] "GET /?%3Fs=0b61db050f0fe523eea5511d7957259b HTTP/1.0" 301 824 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] )"
... show less
Bad Web Bot
Séfora Srl
2025-02-15 09:17:56
(1 month ago)
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache ... show more Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache-badbot jail show less
Bad Web Bot
Mendip_Defender
2025-02-11 18:24:38
(1 month ago)
47.128.112.172 - - [11/Feb/2025:18:24:35 +0000] "GET /?pp=25&searchid=1812556 HTTP/1.0" 200 12346 "- ... show more 47.128.112.172 - - [11/Feb/2025:18:24:35 +0000] "GET /?pp=25&searchid=1812556 HTTP/1.0" 200 12346 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] )"
... show less
Bad Web Bot
Mangelot Hosting
2025-02-08 21:27:16
(1 month ago)
(BADBOT) ModSecurity BAD BOT Detected 47.128.112.172 (SG/Singapore/ec2-47-128-112-172.ap-southeast-1 ... show more (BADBOT) ModSecurity BAD BOT Detected 47.128.112.172 (SG/Singapore/ec2-47-128-112-172.ap-southeast-1.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: show less
Web App Attack
Anonymous
2025-02-03 10:53:02
(1 month ago)
Malicious activity detected
Hacking
Web App Attack
librebit
2025-02-02 12:41:34
(1 month ago)
Brute force
Brute-Force