π΅πΉ
Information Security
2026-08-22 16:00:25
(17 hours ago)
Web App Attack
Web App Attack
π©πͺ
AetherFox
2026-08-22 05:07:05
(1 day ago)
AetherFox VoidGuard detected: [Sat Aug 22 07:06:29.070280 2026] [authz_core:error] [pid 161956:tid 1 ...
show more
AetherFox VoidGuard detected: [Sat Aug 22 07:06:29.070280 2026] [authz_core:error] [pid 161956:tid 161986] [client 47.79.201.24:39628] AH01630: client denied by server configuration: proxy:https://[MASKED]/view_all_set.php, referer: https://www.google.com/
[Sat Aug 22 07:06:29.070504 2026] [authz_core:error] [pid 161956:tid 161986] [client 47.79.201.24:39628] AH01630: client denied by server configuration: /var/www/ERRORpages/403.html, referer: https://www.google.com/
[Sat Aug 22 07:07:02.112546 2026] [authz_core:error] [pid 161956:tid 162004] [client 47.79.201.24:58702] AH01630: client denied by server configuration: proxy:https://[MASKED]/view_all_bug_page.php, referer: https://www.google.com/
[Sat Aug 22 07:07:02.116573 2026] [authz_core:error] [pid 161956:tid 162004] [client 47.79.201.24:58702] AH01630: client denied by server configuration: /var/www/ERRORpages/403.html, referer: https://www.google.com/
[Sat Aug 22 07:07:05.696477 2026] [authz_core:err
...
show less
Bad Web Bot
Web App Attack
π©πͺ
AetherFox
2026-08-21 11:10:28
(1 day ago)
AetherFox VoidGuard detected: [Fri Aug 21 13:09:02.695952 2026] [authz_core:error] [pid 147571:tid 1 ...
show more
AetherFox VoidGuard detected: [Fri Aug 21 13:09:02.695952 2026] [authz_core:error] [pid 147571:tid 147621] [client 47.79.201.24:12434] AH01630: client denied by server configuration: /var/www/ERRORpages/403.html, referer: https://www.google.com/
[Fri Aug 21 13:09:06.336411 2026] [authz_core:error] [pid 147572:tid 147580] [client 47.79.201.24:12446] AH01630: client denied by server configuration: proxy:https://[MASKED]/excel_xml_export.php, referer: https://www.google.com/
[Fri Aug 21 13:09:06.336676 2026] [authz_core:error] [pid 147572:tid 147580] [client 47.79.201.24:12446] AH01630: client denied by server configuration: /var/www/ERRORpages/403.html, referer: https://www.google.com/
[Fri Aug 21 13:10:28.646513 2026] [authz_core:error] [pid 147571:tid 147615] [client 47.79.201.24:38132] AH01630: client denied by server configuration: proxy:https://[MASKED]/view_all_set.php, referer: https://www.google.com/
[Fri Aug 21 13:10:28.647758 2026] [authz_core:erro
...
show less
Bad Web Bot
Web App Attack
π΅πΉ
Information Security
2026-08-21 06:08:55
(2 days ago)
Web App Attack
Web App Attack
π©πͺ
AetherFox
2026-08-20 21:08:48
(2 days ago)
AetherFox VoidGuard detected: [Thu Aug 20 23:07:55.383184 2026] [authz_core:error] [pid 142528:tid 1 ...
show more
AetherFox VoidGuard detected: [Thu Aug 20 23:07:55.383184 2026] [authz_core:error] [pid 142528:tid 142578] [client 47.79.201.24:55834] AH01630: client denied by server configuration: proxy:https://[MASKED]/view_all_set.php, referer: https://www.google.com/
[Thu Aug 20 23:07:55.387272 2026] [authz_core:error] [pid 142528:tid 142578] [client 47.79.201.24:55834] AH01630: client denied by server configuration: /var/www/ERRORpages/403.html, referer: https://www.google.com/
[Thu Aug 20 23:08:33.946364 2026] [authz_core:error] [pid 142528:tid 142565] [client 47.79.201.24:24242] AH01630: client denied by server configuration: proxy:https://[MASKED]/csv_export.php, referer: https://www.google.com/
[Thu Aug 20 23:08:33.947469 2026] [authz_core:error] [pid 142528:tid 142565] [client 47.79.201.24:24242] AH01630: client denied by server configuration: /var/www/ERRORpages/403.html, referer: https://www.google.com/
[Thu Aug 20 23:08:48.282853 2026] [authz_core:error] [pi
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 23:26:34
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.24 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 19:26:29.799248 2026] [security2:error] [pid 29809:tid 29809] [client 47.79.201.24:21078] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jerusalem-korczak-home.com|F|2"] [data ".evrey.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jerusalem-korczak-home.com"] [uri "/np/Isr/www.evrey.com"] [unique_id "aoOYpR6A77QzNdWXxyfMJQAAACU"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
filstal.org
2026-08-16 19:15:18
(6 days ago)
Automated bot: spoofed/impossible user-agent, web scraping or automated request patterns detected. U ...
show more
Automated bot: spoofed/impossible user-agent, web scraping or automated request patterns detected. UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
πΊπΈ
1gz
2026-08-16 03:54:14
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /lajme/rezvani
UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
1gz
2026-08-15 17:25:03
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /lajme/hristijan
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
1gz
2026-08-15 00:54:53
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /english/government
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-08-12 15:11:16
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.24 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 11:11:08.921051 2026] [security2:error] [pid 3977307:tid 3977307] [client 47.79.201.24:63190] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.spacebooger.com|F|2"] [data ".spacebooger.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.spacebooger.com"] [uri "/tag/spiderman/www.spacebooger.com"] [unique_id "anyNDNZ0A_UUrpDIcwtEiQAAAAI"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
tecnicorioja
2026-08-08 22:01:19
(2 weeks ago)
(Mod_security)
Web App Attack
Brute-Force
Bad Web Bot
π©πͺ
big-cloud.nl
2026-08-07 19:07:05
(2 weeks ago)
Try to access /xmlrpc.php
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-06 19:19:17
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.24 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 15:19:11.148531 2026] [security2:error] [pid 1548121:tid 1548128] [client 47.79.201.24:65120] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.baronannaly.com|F|2"] [data ".stoborough.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.baronannaly.com"] [uri "/www.stoborough.com"] [unique_id "anTeLz4WotDhxvC3AAAlVwAAAMM"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
1gz
2026-07-31 08:17:54
(3 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /lajme/deepseek
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot