🇩🇪
palzer.IT
2026-09-06 09:27:08
(12 hours ago)
Fail2ban automatic report for plesk-apache-badbot: 47.128.26.69 - - [06/Sep/2026:11:26:53 +0200] GET ...
show more
Fail2ban automatic report for plesk-apache-badbot: 47.128.26.69 - - [06/Sep/2026:11:26:53 +0200] GET /service/termine/eventsnachtag/2026/11/21/29 [DOMAIN_REMOVED] 200 17137 - Mozilla/5.0 (compatible; Bytespider; spider-feedback@[DOMAIN_REMOVED]) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.0.0 Safari/537.36
show less
Bad Web Bot
🇩🇪
palzer.IT
2026-09-03 15:39:26
(3 days ago)
Fail2ban automatic report for plesk-apache-badbot: 47.128.26.69 - - [03/Sep/2026:17:39:13 +0200] GET ...
show more
Fail2ban automatic report for plesk-apache-badbot: 47.128.26.69 - - [03/Sep/2026:17:39:13 +0200] GET /service/termine/eventsnachtag/2023/12/4/30 [DOMAIN_REMOVED] 200 17085 - Mozilla/5.0 (compatible; Bytespider; spider-feedback@[DOMAIN_REMOVED]) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.0.0 Safari/537.36
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-24 10:33:43
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 47.128.26.69 (ec2-47-128-26-69.ap-southeast-1.c ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.26.69 (ec2-47-128-26-69.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 06:33:40.177992 2026] [security2:error] [pid 13176:tid 13176] [client 47.128.26.69:42318] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.med-engineering.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.med-engineering.com"] [uri "/2captcha.com"] [unique_id "aoweBONNLpuQx5tYgYP6EQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-21 15:52:30
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.26.69 (ec2-47-128-26-69.ap-southeast-1.c ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.26.69 (ec2-47-128-26-69.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 11:52:24.268840 2026] [security2:error] [pid 10023:tid 10023] [client 47.128.26.69:13956] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.med-engineering.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.med-engineering.com"] [uri "/forbesnewstoday.com"] [unique_id "ajgIuNxLqLJhMXLGMiJawgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-15 13:12:38
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.26.69 (ec2-47-128-26-69.ap-southeast-1.c ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.26.69 (ec2-47-128-26-69.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 09:12:32.859664 2026] [security2:error] [pid 4322:tid 4322] [client 47.128.26.69:47152] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.med-engineering.com|F|2"] [data ".agdj.med-engineering.com.avl.db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.med-engineering.com"] [uri "/biu.agdj.med-engineering.com.avl.db"] [unique_id "agcbwJgp_c5XYlmJR89QXgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
masterguru
2026-04-11 19:23:33
(4 months ago)
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:user-agent. (1100000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:user-agent. (1100000-123)
show less
Bad Web Bot
🇫🇷
bigorre.org
2026-03-08 09:57:02
(5 months ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
🇩🇪
BlueWire Hosting
2026-01-13 02:40:18
(7 months ago)
Bad bot ignoring robot.txt
Bad Web Bot
🇪🇸
librebit
2026-01-12 02:41:29
(7 months ago)
Brute force
Brute-Force
🇩🇪
conseilgouz
2026-01-07 13:02:04
(7 months ago)
gie-88 : Bloc AI bots=>/robots.txt(Bytespider)
Hacking
🇦🇺
MAGIC
2026-01-07 02:06:14
(7 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
🇫🇷
bigorre.org
2025-12-31 14:04:25
(8 months ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
🇺🇸
fortypoundhead
2025-12-16 10:50:56
(8 months ago)
Banned IP Address
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2025-12-12 12:40:48
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.26.69 (ec2-47-128-26-69.ap-southeast-1.c ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.26.69 (ec2-47-128-26-69.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 12 07:40:41.562440 2025] [security2:error] [pid 4745:tid 4745] [client 47.128.26.69:48464] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.informativearticles.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.informativearticles.com"] [uri "/web-design/[email protected] "] [unique_id "aTwNSfH2CNGZNLsHh38AMgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
hermawan
2025-12-12 02:26:54
(8 months ago)
[Fri Dec 12 09:26:24.396197 2025] [security2:error] [pid 166108:tid 139917916022464] [client 47.128. ...
show more
[Fri Dec 12 09:26:24.396197 2025] [security2:error] [pid 166108:tid 139917916022464] [client 47.128.26.69:42024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Feed" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "253"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Feed found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] ) request_line = GET / HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/"] [unique_id "aTt9ULp1rrkvSSi2g3MyIQAAwRg"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[166133] [6z7d/HdIBFI] [aTt9ULp1rrkvSSi2g3MyIQAAwRg] keep_alive=[1] [2025-12-12 09:26:24.396214] [R:aTt9ULp1rrkvSSi2g3MyIQAAwRg] UA:'Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile
...
show less
Hacking
Web App Attack