๐ฉ๐ช
palzer.IT
2026-09-03 17:27:11
(43 minutes ago)
Fail2ban automatic report for plesk-apache-badbot: 47.128.26.252 - - [03/Sep/2026:19:26:57 +0200] GE ...
show more
Fail2ban automatic report for plesk-apache-badbot: 47.128.26.252 - - [03/Sep/2026:19:26:57 +0200] GET /service/termine/eventsnachtag/2025/8/22/43 [DOMAIN_REMOVED] 200 17137 - Mozilla/5.0 (compatible; Bytespider; spider-feedback@[DOMAIN_REMOVED]) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.0.0 Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-24 18:17:36
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 47.128.26.252 (ec2-47-128-26-252.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.26.252 (ec2-47-128-26-252.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 14:17:32.963568 2026] [security2:error] [pid 1130788:tid 1130788] [client 47.128.26.252:12036] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.med-engineering.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.med-engineering.com"] [uri "/rucaptcha.com"] [unique_id "amOsPHiU9ujbIgqyGOXGdQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-06-18 17:24:49
(2 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted]): (CF_ENABLE)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-15 12:38:55
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.26.252 (ec2-47-128-26-252.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.26.252 (ec2-47-128-26-252.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 08:38:48.040103 2026] [security2:error] [pid 1037:tid 1037] [client 47.128.26.252:31678] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.med-engineering.com|F|2"] [data ".agdj.med-engineering.com.avl.db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.med-engineering.com"] [uri "/biu.agdj.med-engineering.com.avl.db"] [unique_id "agcT2JZM--ohkI4143dkrQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-13 14:13:34
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.26.252 (ec2-47-128-26-252.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.26.252 (ec2-47-128-26-252.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 10:13:27.463010 2026] [security2:error] [pid 1476761:tid 1476761] [client 47.128.26.252:36038] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.med-engineering.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.med-engineering.com"] [uri "/forbesnewstoday.com"] [unique_id "abQbh83ii0dpIOwh69dmiQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
bigorre.org
2026-03-08 10:19:30
(5 months ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
๐ธ๐ฌ
anotherwatcher
2026-03-02 23:26:43
(6 months ago)
bad bot
Bad Web Bot
๐ฉ๐ช
dbmwebdesign
2026-03-01 22:57:26
(6 months ago)
Bot detected and blocked by Fail2Ban in bytespider jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-01 19:34:46
(6 months ago)
(mod_security) mod_security (id:211190) triggered by 47.128.26.252 (ec2-47-128-26-252.ap-southeast-1 ...
show more
(mod_security) mod_security (id:211190) triggered by 47.128.26.252 (ec2-47-128-26-252.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 01 14:34:22.229042 2026] [security2:error] [pid 30928:tid 30928] [client 47.128.26.252:34686] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||heuristicbooks.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /Heuristic Books -- Algorithms for Better Living_files/ccx/?dir=%2Fhome%2Frbanis%2Fetc%2Fearlyeditionbooks.banis-associates.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "heuristicbooks.com"] [uri "/Heuristic Books -- Algorithms for Better Living_files/ccx/"] [unique_id "aaSUvis1_Cq7ZXE_9wvj5wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-03-01 09:51:28
(6 months ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
๐ซ๐ท
bigorre.org
2026-02-24 16:18:42
(6 months ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
๐ฉ๐ช
filstal.org
2026-02-24 09:19:25
(6 months ago)
Aggressive Web Bot/Crawler detected by Fail2ban.
Bad Web Bot
๐ซ๐ท
bigorre.org
2026-02-07 15:01:00
(6 months ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
๐ช๐ธ
librebit
2026-01-20 14:49:27
(7 months ago)
Brute force
Brute-Force
๐ช๐ธ
librebit
2026-01-08 04:05:35
(7 months ago)
Brute force
Brute-Force