Anonymous
2026-09-13 16:19:15
(11 hours ago)
IP matched detection query 50 and more bad rqs apache.
Hacking
Bad Web Bot
Brute-Force
Web App Attack
🇫🇷
COMAITE
2026-07-03 16:32:04
(2 months ago)
SQL injection attempt from 47.128.99.165.
Web App Attack
🇫🇷
COMAITE
2026-06-29 10:06:25
(2 months ago)
SQL injection attempt from 47.128.99.165.
Web App Attack
🇦🇺
MAGIC
2026-04-02 00:35:13
(5 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
🇫🇷
bigorre.org
2026-03-08 13:58:12
(6 months ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
🇫🇷
bigorre.org
2026-03-07 09:56:29
(6 months ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
🇨🇭
backslash
2026-02-27 05:42:07
(6 months ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
🇺🇸
TPI-Abuse
2026-02-20 19:21:46
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.99.165 (ec2-47-128-99-165.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.99.165 (ec2-47-128-99-165.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 14:21:39.305164 2026] [security2:error] [pid 8420:tid 8420] [client 47.128.99.165:48088] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.turtlehill.org|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.turtlehill.org"] [uri "/cleanup/hill/images/Thumbs.db"] [unique_id "aZi0Q65cBzC74Udtgx9mZwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
bigorre.org
2026-02-13 14:31:02
(7 months ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
🇩🇪
Reinhard
2026-01-16 05:43:38
(7 months ago)
Unknown activity, but too many attacks with too many users.
Hacking
🇪🇸
librebit
2025-12-31 13:08:09
(8 months ago)
Brute force
Brute-Force
🇺🇸
TPI-Abuse
2025-12-28 21:12:34
(8 months ago)
(mod_security) mod_security (id:211190) triggered by 47.128.99.165 (ec2-47-128-99-165.ap-southeast-1 ...
show more
(mod_security) mod_security (id:211190) triggered by 47.128.99.165 (ec2-47-128-99-165.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 16:12:29.948425 2025] [security2:error] [pid 22691:tid 22691] [client 47.128.99.165:45332] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||heuristicbooks.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /Heuristic Books -- Algorithms for Better Living_files/ccx/?dir=%2Fhome%2Frbanis%2Fetc%2Ffgtr.banis-associates.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "heuristicbooks.com"] [uri "/Heuristic Books -- Algorithms for Better Living_files/ccx/"] [unique_id "aVGdPcl-_dW4mK0iX2bJRQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
xmission.com
2025-12-23 18:49:43
(8 months ago)
47.128.99.165 - - [23/Dec/2025:11:49:42 -0700] "GET /category/photos/daily-photo/page/1943/?page=178 ...
show more
47.128.99.165 - - [23/Dec/2025:11:49:42 -0700] "GET /category/photos/daily-photo/page/1943/?page=178 HTTP/2.0" 200 9375 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.0.0 Safari/537.36"
47.128.99.165 - - [23/Dec/2025:11:49:43 -0700] "GET /wp-content/uploads/2012/07/12_09_2005.jpg HTTP/2.0" 206 500 "https://dooce.com/category/photos/daily-photo/page/1943/?page=178" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.0.0 Safari/537.36"
47.128.99.165 - - [23/Dec/2025:11:49:43 -0700] "GET /photos/dailyphoto/12_09_2005.jpg HTTP/2.0" 206 500 "https://dooce.com/category/photos/daily-photo/page/1943/?page=178" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.0.0 Safari/537.36"
47.128.99.165 - - [23/Dec/2025:11:49:43 -0700] "GET /photos/dailyphoto/12_09_2005_02.jpg HTTP/2.0" 404 548
...
show less
Bad Web Bot
🇨🇦
1gz
2025-12-20 21:55:19
(8 months ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] )
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2025-12-19 05:18:19
(8 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack