๐ฆ๐บ
Anytech
2026-07-07 19:56:53
(2 months ago)
Blocked bot: Bytespider
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 19:38:15
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.59.175 (ec2-47-128-59-175.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.59.175 (ec2-47-128-59-175.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 15:38:09.198573 2026] [security2:error] [pid 363:tid 363] [client 47.128.59.175:24752] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||noviasaltovacio.com.mx|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "noviasaltovacio.com.mx"] [uri "/contactanos/[email protected] "] [unique_id "agDeob8DFT6FXU2375zuhwAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
Anytech
2026-03-27 00:41:07
(6 months ago)
Blocked by conn-monitor: Rule http-old-chrome: Chrome version below 100 -- no legitimate user runs t ...
show more
Blocked by conn-monitor: Rule http-old-chrome: Chrome version below 100 -- no legitimate user runs this, always a bot (app: broncos1, 1 hits)
show less
Web App Attack
๐จ๐ฆ
1gz
2026-03-11 10:50:25
(6 months ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /showbiz/incident-ne-xhirimet-e-fast-furious-dublanti-i-vin-diesel-ne-koma/473331/
UA: Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] )
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
Didier Lagaert
2026-02-22 12:23:09
(7 months ago)
lie-88 : Bloc AI bots=>/component/jevents/evenementsparjour/2029/9/7/-?Itemid=950(Bytespider)
Hacking
๐ช๐ธ
masterguru
2026-02-06 08:56:06
(7 months ago)
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:user-agent. (1100000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
Bad Web Bot
๐ช๐ธ
librebit
2026-02-05 08:01:19
(7 months ago)
Brute force
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-12-18 07:23:22
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.59.175 (ec2-47-128-59-175.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.59.175 (ec2-47-128-59-175.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 18 02:23:15.463598 2025] [security2:error] [pid 1346:tid 1346] [client 47.128.59.175:32456] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.med-engineering.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.med-engineering.com"] [uri "/elaanmarketing.com"] [unique_id "aUOr488npkU9iaR-nIjKYAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2025-12-17 19:16:53
(9 months ago)
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:user-agent. (1100000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
Bad Web Bot
๐ฎ๐ฉ
hermawan
2025-12-10 01:07:52
(9 months ago)
[Wed Dec 10 07:55:11.698153 2025] [security2:error] [pid 277875:tid 140673519969984] [client 47.128. ...
show more
[Wed Dec 10 07:55:11.698153 2025] [security2:error] [pid 277875:tid 140673519969984] [client 47.128.59.175:46846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Feed" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "252"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Feed found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] ) request_line = GET /index.php/informasi-iklim/buletin-1/buletin-informasi-iklim-dan-lingkungan HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/informasi-iklim/buletin-1/buletin-informasi-iklim-dan-lingkungan"] [unique_id "aTjE713TeaP2NSm8m0nGggAARwE"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[277877] [cCj/eo7lbiw] [aTjE713TeaP2NSm8m0nGggAARwE] keep_aliv
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-18 18:09:10
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.59.175 (ec2-47-128-59-175.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.59.175 (ec2-47-128-59-175.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 18 13:09:02.711692 2025] [security2:error] [pid 9371:tid 9371] [client 47.128.59.175:53544] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.et.lobibilisim.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.et.lobibilisim.com"] [uri "/storage/oauth-private.key"] [unique_id "aRy2PnkJK98Gliq-FeTG4wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-14 09:55:54
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.59.175 (ec2-47-128-59-175.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.59.175 (ec2-47-128-59-175.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 14 04:55:49.477890 2025] [security2:error] [pid 1653051:tid 1653051] [client 47.128.59.175:54900] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.coolwebsites.org|F|2"] [data ".djstore.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.coolwebsites.org"] [uri "/www.djstore.com"] [unique_id "aRb8pT7u0fDsR9Beoti3yQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Globe2
2025-10-04 03:15:02
(1 year ago)
[04/Oct/2025:04:15:00 +0100] -PQBCCAhBi3xtktAEuu4cZXN 47.128.59.175 28926 91.212.212.13 443
[04/Oct/ ...
show more
[04/Oct/2025:04:15:00 +0100] -PQBCCAhBi3xtktAEuu4cZXN 47.128.59.175 28926 91.212.212.13 443
[04/Oct/2025:04:15:00 +0100] bMBlGeMHpU5vJMsTTImsbpjq 47.128.59.175 28926 91.212.212.13 443
[04/Oct/2025:04:15:01 +0100] mkxQam7r9wLpvQ5YvqYP3PPd 47.128.59.175 28926 91.212.212.13 443
...
show less
Web App Attack
๐ฌ๐ง
NotCool
2025-09-27 01:51:10
(1 year ago)
(CRAWLDELAY) Generic Bot Crawl-delay Violation 47.128.59.175 (SG/Singapore/ec2-47-128-59-175.ap-sout ...
show more
(CRAWLDELAY) Generic Bot Crawl-delay Violation 47.128.59.175 (SG/Singapore/ec2-47-128-59-175.ap-southeast-1.compute.amazonaws.com): 10 in the last 3600 secs
show less
Bad Web Bot
๐ซ๐ท
bigorre.org
2025-09-23 22:06:54
(1 year ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot