๐ฉ๐ช
filstal.org
2026-03-20 12:54:46
(5 months ago)
Aggressive Web Bot/Crawler - Multiple UA-switching detected.
Bad Web Bot
๐ซ๐ท
bigorre.org
2026-02-23 13:16:20
(6 months ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
๐ฎ๐ณ
dineshskt4all
2026-01-20 09:24:02
(7 months ago)
47.128.99.39 - - [20/Jan/2026:09:23:58 +0000] "GET /index.php?limit=75&order=ASC&path=80_84&product_ ...
show more
47.128.99.39 - - [20/Jan/2026:09:23:58 +0000] "GET /index.php?limit=75&order=ASC&path=80_84&product_id=102&route=product%2Fproduct&sort=pd.name HTTP/1.0" 403 3258 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.0.0 Safari/537.36"
...
show less
IoT Targeted
๐จ๐ฆ
1gz
2026-01-18 01:50:00
(8 months ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /showbiz/braktisen-top-channel-per-klanin-zbulohet-surpriza-e-erionit-dhe-besit-ne-kengen-magjike/350875/
UA: Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] )
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-01-09 05:56:03
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 47.128.99.39 (ec2-47-128-99-39.ap-southeast-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 47.128.99.39 (ec2-47-128-99-39.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 09 00:56:00.250603 2026] [security2:error] [pid 20484:tid 20484] [client 47.128.99.39:50980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "robertbanis.com"] [uri "/ccx/"] [unique_id "aWCYcPh5qs-iAhVeWUe5xwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-19 16:30:26
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.99.39 (ec2-47-128-99-39.ap-southeast-1.c ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.99.39 (ec2-47-128-99-39.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 19 11:30:20.804431 2025] [security2:error] [pid 26119:tid 26119] [client 47.128.99.39:26026] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||scoutinsignia.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "scoutinsignia.com"] [uri "/ranks/WS_FTP.LOG"] [unique_id "aUV9nCJuE3eOieQ-kU3_7gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
NotCool
2025-12-18 09:27:19
(9 months ago)
(CRAWLDELAY) Generic Bot Crawl-delay Violation 47.128.99.39 (ec2-47-128-99-39.ap-southeast-1.compute ...
show more
(CRAWLDELAY) Generic Bot Crawl-delay Violation 47.128.99.39 (ec2-47-128-99-39.ap-southeast-1.compute.amazonaws.com): 10 in the last 3600 secs
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-12-04 19:18:17
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.99.39 (ec2-47-128-99-39.ap-southeast-1.c ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.99.39 (ec2-47-128-99-39.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 04 14:18:12.789387 2025] [security2:error] [pid 13948:tid 13948] [client 47.128.99.39:23518] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||melsjukeboxes.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "melsjukeboxes.com"] [uri "/[email protected] "] [unique_id "aTHedNCpr0V36grxsqDCVQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2025-11-23 01:24:09
(9 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2025-10-30 11:47:13
(10 months ago)
47.128.99.39 - - [30/Oct/2025:12:47:11 +0100] "GET /robots.txt HTTP/1.1" 403 4829 "-" "Mozilla/5.0 ( ...
show more
47.128.99.39 - - [30/Oct/2025:12:47:11 +0100] "GET /robots.txt HTTP/1.1" 403 4829 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] )"
...
show less
Web App Attack
๐ฉ๐ช
conseilgouz
2025-10-28 09:16:16
(10 months ago)
ave-88 : Bloc AI bots=>/component/weblinks/weblink/6-droit-de-l-union-europeenne?Itemid=101&cati ...
show more
ave-88 : Bloc AI bots=>/component/weblinks/weblink/6-droit-de-l-union-europeenne?Itemid=101&catid=16&task=weblink.g...(Bytespider)
show less
Hacking
Anonymous
2025-10-19 15:16:48
(10 months ago)
Ports: 80,443; Direction: 1; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-09-24 08:30:32
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.99.39 (ec2-47-128-99-39.ap-southeast-1.c ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.99.39 (ec2-47-128-99-39.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 24 04:30:25.444474 2025] [security2:error] [pid 3055838:tid 3055838] [client 47.128.99.39:42544] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||elcalamo.com|F|2"] [data ".pdb"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "elcalamo.com"] [uri "/pda/sandomingo-salome.PDB"] [unique_id "aNOsIc1lrZmRKWgSVNcIRwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-09-19 07:56:31
(11 months ago)
Ports: 80,443; Direction: 1; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ซ๐ท
bigorre.org
2025-09-05 09:50:39
(1 year ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot