๐บ๐ธ
TPI-Abuse
2026-09-15 18:32:38
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 47.128.33.178 (ec2-47-128-33-178.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.33.178 (ec2-47-128-33-178.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:32:33.652282 2026] [security2:error] [pid 2089:tid 2089] [client 47.128.33.178:59882] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pages4you.com|F|2"] [data ".old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pages4you.com"] [uri "/default.old"] [unique_id "aqmPQQDHxAYFIEyCGHydsQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-07-28 10:17:18
(1 month ago)
Plesk Fail2Ban jail: plesk-apache-badbot. Evidence: 47.128.33.178 - - [28/Jul/2026:13:17:18 +0300] " ...
show more
Plesk Fail2Ban jail: plesk-apache-badbot. Evidence: 47.128.33.178 - - [28/Jul/2026:13:17:18 +0300] "GET /robots.txt HTTP/1.1" 200 179 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] )"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 22:02:26
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.33.178 (ec2-47-128-33-178.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.33.178 (ec2-47-128-33-178.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 18:02:21.818688 2026] [security2:error] [pid 4744:tid 4744] [client 47.128.33.178:52988] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pages4you.com|F|2"] [data ".old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pages4you.com"] [uri "/default.old"] [unique_id "akgxbUBHFARVwz18ZuBJswAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-30 17:50:22
(3 months ago)
Ports: 80,443; Direction: 1; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-05-30 07:44:20
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.33.178 (ec2-47-128-33-178.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.33.178 (ec2-47-128-33-178.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 03:44:17.370707 2026] [security2:error] [pid 1416:tid 1416] [client 47.128.33.178:48532] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lertap5.com|F|2"] [data ".sas.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lertap5.com"] [uri "/HTMLHelp/HTML/www.sas.com"] [unique_id "ahqVUezCiW7tcyTOt-rjrAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 08:10:29
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.33.178 (ec2-47-128-33-178.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.33.178 (ec2-47-128-33-178.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 04:10:25.641093 2026] [security2:error] [pid 16998:tid 16998] [client 47.128.33.178:37336] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pages4you.com|F|2"] [data ".old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pages4you.com"] [uri "/default.old"] [unique_id "ahVVcSgJHOGrtEGVwcBK0AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-02 11:14:03
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.33.178 (ec2-47-128-33-178.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.33.178 (ec2-47-128-33-178.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 02 07:13:57.889608 2026] [security2:error] [pid 23168:tid 23168] [client 47.128.33.178:51618] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.greenroomonline.org|F|2"] [data ".wagonwheeltheatre.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.greenroomonline.org"] [uri "/theaters/www.wagonwheeltheatre.com"] [unique_id "afXcdRdbQXYzkIMX6-rlJAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-04-19 07:56:14
(4 months ago)
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:user-agent. (1100000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-13 21:32:57
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.33.178 (ec2-47-128-33-178.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.33.178 (ec2-47-128-33-178.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 13 17:32:53.134507 2026] [security2:error] [pid 1640594:tid 1640594] [client 47.128.33.178:43546] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lertap5.com|F|2"] [data ".sas.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lertap5.com"] [uri "/HTMLHelp/Lrtp59HTML/www.sas.com"] [unique_id "ad1hBReGwMSxdqb_qmERcgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-04-11 19:54:01
(5 months ago)
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:user-agent. (1100000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-27 12:11:03
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.33.178 (ec2-47-128-33-178.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.33.178 (ec2-47-128-33-178.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 08:10:57.529663 2026] [security2:error] [pid 30288:tid 30288] [client 47.128.33.178:59892] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pages4you.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pages4you.com"] [uri "/photos/Thumbs.db"] [unique_id "acZz0WmuDBNQWlCor8u1LQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 04:06:37
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.33.178 (ec2-47-128-33-178.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.33.178 (ec2-47-128-33-178.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 00:06:29.787685 2026] [security2:error] [pid 3985:tid 3985] [client 47.128.33.178:58440] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||greenroomonline.org|F|2"] [data ".wagonwheeltheatre.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "greenroomonline.org"] [uri "/theaters/www.wagonwheeltheatre.com"] [unique_id "acSwxSksDo37JDuhpvhT1wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
filstal.org
2026-03-11 04:59:49
(6 months ago)
Aggressive Web Bot/Crawler detected by Fail2ban.
Bad Web Bot
๐จ๐ญ
backslash
2026-02-26 08:42:01
(6 months ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
๐ช๐ธ
librebit
2026-02-26 03:13:53
(6 months ago)
Brute force
Brute-Force