🇩🇪
palzer.IT
2026-09-04 02:37:42
(1 day ago)
Fail2ban automatic report for plesk-apache-badbot: 47.128.26.40 - - [04/Sep/2026:04:37:28 +0200] GET ...
show more
Fail2ban automatic report for plesk-apache-badbot: 47.128.26.40 - - [04/Sep/2026:04:37:28 +0200] GET /service/termine/monatskalender/2023/10/45 [DOMAIN_REMOVED] 200 18078 - Mozilla/5.0 (compatible; Bytespider; spider-feedback@[DOMAIN_REMOVED]) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.0.0 Safari/537.36
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-02 17:22:50
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 47.128.26.40 (ec2-47-128-26-40.ap-southeast-1.c ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.26.40 (ec2-47-128-26-40.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 13:22:44.932876 2026] [security2:error] [pid 8119:tid 8119] [client 47.128.26.40:28526] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||med-engineering.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "med-engineering.com"] [uri "/diflucan.com"] [unique_id "aphbZA8FNaPA8IrMrejIRQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
masterguru
2026-05-10 07:37:48
(3 months ago)
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:user-agent. (1100000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:user-agent. (1100000-123)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-04-22 16:56:18
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.26.40 (ec2-47-128-26-40.ap-southeast-1.c ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.26.40 (ec2-47-128-26-40.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 12:56:13.891068 2026] [security2:error] [pid 29143:tid 29143] [client 47.128.26.40:24942] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.med-engineering.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.med-engineering.com"] [uri "/era.com"] [unique_id "aej9rUGveGvZIRoQA2oZTQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-12 19:01:18
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.26.40 (ec2-47-128-26-40.ap-southeast-1.c ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.26.40 (ec2-47-128-26-40.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 12 15:01:12.537949 2026] [security2:error] [pid 3474615:tid 3474619] [client 47.128.26.40:40014] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.munatseng.org|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.munatseng.org"] [uri "/stories/tsengkwongchi.com"] [unique_id "advr-DGbu5UMYwkyPthNyAAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
bigorre.org
2026-03-05 10:13:06
(6 months ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
🇨🇭
backslash
2026-03-03 10:12:09
(6 months ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
🇫🇷
bigorre.org
2026-02-20 15:52:02
(6 months ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
🇫🇷
bigorre.org
2026-02-13 13:22:47
(6 months ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
🇺🇸
TPI-Abuse
2026-01-29 19:21:01
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.26.40 (ec2-47-128-26-40.ap-southeast-1.c ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.26.40 (ec2-47-128-26-40.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 29 14:20:53.418182 2026] [security2:error] [pid 13587:tid 13587] [client 47.128.26.40:53528] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||phantomquailkennel.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "phantomquailkennel.com"] [uri "/paypal.com"] [unique_id "aXuzFRDa3Ru0tUR0sE7s2wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-23 19:23:38
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.26.40 (ec2-47-128-26-40.ap-southeast-1.c ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.26.40 (ec2-47-128-26-40.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 23 14:23:31.933884 2026] [security2:error] [pid 14024:tid 14024] [client 47.128.26.40:29208] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gilesvolvocarselpaso.com.acadianahero.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gilesvolvocarselpaso.com.acadianahero.com"] [uri "/linkedin.com"] [unique_id "aXPKs_M9LhtmZhwPB2q1SQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-01-17 13:17:00
(7 months ago)
WP Probing and/or Hacking
Port Scan
Web App Attack
🇩🇪
Didier Lagaert
2026-01-10 01:46:34
(7 months ago)
lie-88 : Bloc AI bots=>/robots.txt(Bytespider)
Hacking
🇫🇷
bigorre.org
2026-01-04 09:56:48
(8 months ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
🇮🇪
Jim Keir
2026-01-03 18:29:49
(8 months ago)
2026-01-03 18:29:48 47.128.26.40 Bad bot, blocking Mozilla/5.0
Bad Web Bot