๐ซ๐ท
mail.avx.gr
2026-07-21 02:29:15
(3 days ago)
Plesk Fail2Ban jail: plesk-apache-badbot. Evidence: 47.128.33.133 - - [21/Jul/2026:05:29:14 +0300] " ...
show more
Plesk Fail2Ban jail: plesk-apache-badbot. Evidence: 47.128.33.133 - - [21/Jul/2026:05:29:14 +0300] "GET /robots.txt HTTP/1.1" 200 179 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] )"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 13:07:35
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 47.128.33.133 (ec2-47-128-33-133.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.33.133 (ec2-47-128-33-133.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 09:07:29.956077 2026] [security2:error] [pid 16191:tid 16191] [client 47.128.33.133:48528] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pages4you.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pages4you.com"] [uri "/photos/Thumbs.db"] [unique_id "ajFKkRMQ8w7b36aVdcLSjwAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 04:19:37
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 47.128.33.133 (ec2-47-128-33-133.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.33.133 (ec2-47-128-33-133.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 00:19:29.898862 2026] [security2:error] [pid 16339:tid 16339] [client 47.128.33.133:57376] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pages4you.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pages4you.com"] [uri "/photos/Thumbs.db"] [unique_id "ahZw0Z0mrtpsAkH6zrA2LAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 19:51:35
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.33.133 (ec2-47-128-33-133.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.33.133 (ec2-47-128-33-133.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 15:51:28.815535 2026] [security2:error] [pid 14336:tid 14336] [client 47.128.33.133:29234] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bahamascruisersguide.com|F|2"] [data ".blogspot.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bahamascruisersguide.com"] [uri "/Blogs-Websites/snowbirdscompassrose.blogspot.com"] [unique_id "agjKwKAnfOfx1j-t9FlgngAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-03-23 18:06:59
(4 months ago)
Ports: 80,443; Direction: 1; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-03-21 20:35:06
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.33.133 (ec2-47-128-33-133.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.33.133 (ec2-47-128-33-133.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 16:34:58.464253 2026] [security2:error] [pid 7792:tid 7792] [client 47.128.33.133:12602] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pages4you.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pages4you.com"] [uri "/Graphics2/Thumbs.db"] [unique_id "ab8A8izkchgmE4-EHzDjLAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-13 19:09:55
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.33.133 (ec2-47-128-33-133.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.33.133 (ec2-47-128-33-133.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 15:09:49.524741 2026] [security2:error] [pid 20187:tid 20187] [client 47.128.33.133:61878] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lertap5.com|F|2"] [data ".sas.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lertap5.com"] [uri "/HTMLHelp/HTML/www.sas.com"] [unique_id "abRg_afQDBH-FmLrSXEbxQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
bigorre.org
2026-03-06 09:52:22
(4 months ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
๐ฉ๐ช
dbmwebdesign
2026-03-01 17:37:15
(4 months ago)
Bot detected and blocked by Fail2Ban in bytespider jail
Bad Web Bot
๐ฉ๐ช
dbmwebdesign
2026-02-20 00:01:12
(5 months ago)
Bot detected and blocked by Fail2Ban in bytespider jail
Bad Web Bot
๐ฉ๐ช
Didier Lagaert
2026-02-18 19:36:24
(5 months ago)
lie-88 : Bloc AI bots=>/components/com_jevents/assets/css/jevcustom.css?v=3.6.47(Bytespider)
Hacking
๐ฉ๐ช
dbmwebdesign
2026-02-12 16:10:32
(5 months ago)
Bot detected and blocked by Fail2Ban in bytespider jail
Bad Web Bot
๐ฎ๐ณ
dineshskt4all
2026-01-23 19:32:32
(6 months ago)
47.128.33.133 - - [23/Jan/2026:19:32:28 +0000] "GET /trip/special-manali-honeymoon-package-by-volvo/ ...
show more
47.128.33.133 - - [23/Jan/2026:19:32:28 +0000] "GET /trip/special-manali-honeymoon-package-by-volvo/ HTTP/1.0" 200 43338 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] )"
...
show less
IoT Targeted
๐ช๐ธ
librebit
2026-01-10 09:37:40
(6 months ago)
Brute force
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-12-28 21:17:07
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 47.128.33.133 (ec2-47-128-33-133.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 47.128.33.133 (ec2-47-128-33-133.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 16:17:03.168049 2025] [security2:error] [pid 14935:tid 14935] [client 47.128.33.133:14938] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "robertbanis.com"] [uri "/ccx/"] [unique_id "aVGeTxThoaH2vkoUpvMk3AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack