๐ฉ๐ช
AetherFox
2026-08-21 15:09:33
(3 hours ago)
AetherFox VoidGuard detected: [Fri Aug 21 17:08:22.333626 2026] [authz_core:error] [pid 147571:tid 1 ...
show more
AetherFox VoidGuard detected: [Fri Aug 21 17:08:22.333626 2026] [authz_core:error] [pid 147571:tid 147614] [client 47.79.201.60:2902] AH01630: client denied by server configuration: /var/www/ERRORpages/403.html, referer: https://www.google.com/
[Fri Aug 21 17:09:06.084419 2026] [authz_core:error] [pid 147571:tid 147611] [client 47.79.201.60:61852] AH01630: client denied by server configuration: proxy:https://[MASKED]/view_all_set.php, referer: https://www.google.com/
[Fri Aug 21 17:09:06.085872 2026] [authz_core:error] [pid 147571:tid 147611] [client 47.79.201.60:61852] AH01630: client denied by server configuration: /var/www/ERRORpages/403.html, referer: https://www.google.com/
[Fri Aug 21 17:09:33.308301 2026] [authz_core:error] [pid 147571:tid 147611] [client 47.79.201.60:55224] AH01630: client denied by server configuration: proxy:https://[MASKED]/view_filters_page.php, referer: https://www.google.com/
[Fri Aug 21 17:09:33.308512 2026] [authz_core:erro
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
AetherFox
2026-08-20 17:10:06
(1 day ago)
AetherFox VoidGuard detected: [Thu Aug 20 19:09:14.411669 2026] [authz_core:error] [pid 142528:tid 1 ...
show more
AetherFox VoidGuard detected: [Thu Aug 20 19:09:14.411669 2026] [authz_core:error] [pid 142528:tid 142563] [client 47.79.201.60:9568] AH01630: client denied by server configuration: proxy:https://[MASKED]/view_all_set.php, referer: https://www.google.com/
[Thu Aug 20 19:09:14.413424 2026] [authz_core:error] [pid 142528:tid 142563] [client 47.79.201.60:9568] AH01630: client denied by server configuration: /var/www/ERRORpages/403.html, referer: https://www.google.com/
[Thu Aug 20 19:09:49.022926 2026] [authz_core:error] [pid 142527:tid 142549] [client 47.79.201.60:11138] AH01630: client denied by server configuration: proxy:https://[MASKED]/excel_xml_export.php, referer: https://www.google.com/
[Thu Aug 20 19:09:49.024901 2026] [authz_core:error] [pid 142527:tid 142549] [client 47.79.201.60:11138] AH01630: client denied by server configuration: /var/www/ERRORpages/403.html, referer: https://www.google.com/
[Thu Aug 20 19:10:06.455743 2026] [authz_core:error]
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
1gz
2026-08-17 13:44:51
(4 days ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /lajme/bursaspor
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
1gz
2026-08-17 09:25:25
(4 days ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /showbiz/emily
UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
1gz
2026-08-16 04:46:21
(5 days ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /lajme/ruben
UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
1gz
2026-08-15 16:23:25
(6 days ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /lajme/statistikat
UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-15 07:29:57
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.60 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 03:29:51.841920 2026] [security2:error] [pid 11067:tid 11067] [client 47.79.201.60:17508] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.spacebooger.com|F|2"] [data ".spacebooger.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.spacebooger.com"] [uri "/tag/meme/www.spacebooger.com"] [unique_id "aoAVb3Q-uMsL3s8Xw4jSDQAAAAM"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-12 19:33:04
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.60 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 15:32:54.932808 2026] [security2:error] [pid 3812345:tid 3812345] [client 47.79.201.60:38670] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.register-yacht-gibraltar.com|F|2"] [data ".register-yacht-gibraltar.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.register-yacht-gibraltar.com"] [uri "/tr/www.register-yacht-gibraltar.com"] [unique_id "anzKZgpNNMz5LC-o3GAMZQAAAAM"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 13:51:03
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.60 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 09:50:57.991891 2026] [security2:error] [pid 12920:tid 12920] [client 47.79.201.60:57626] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.fundingworkingcapital.com|F|2"] [data ".fundingworkingcapital.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.fundingworkingcapital.com"] [uri "/tag/angel-investors-website/www.fundingworkingcapital.com"] [unique_id "ansowTtWn6FL7vwTNWcc-wAAAA0"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-09 23:05:08
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.60 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 09 19:05:02.983643 2026] [security2:error] [pid 3119885:tid 3119885] [client 47.79.201.60:39246] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.clayrivers.com|F|2"] [data ".clayrivers.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.clayrivers.com"] [uri "/10-things/look-up-in-the-sky-jpg/www.clayrivers.com"] [unique_id "ankHnjKs7_pJ0XNwu7SGtgAAAAE"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-08 03:38:19
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.60 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 23:38:14.221060 2026] [security2:error] [pid 92938:tid 92946] [client 47.79.201.60:38094] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.iheb.org|F|2"] [data ".iacsb.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.iheb.org"] [uri "/www.IACSB.com"] [unique_id "anakph1rDgfD8h6rUkmg-AAAAQY"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 13:11:34
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.60 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 09:11:30.504559 2026] [security2:error] [pid 414062:tid 414062] [client 47.79.201.60:45232] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pamolson.org|F|2"] [data ".michaelmoore.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pamolson.org"] [uri "/www.michaelmoore.com"] [unique_id "anXZgpBOpkM7araPgOAtogAAAAw"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Sklurk
2026-08-07 03:08:32
(2 weeks ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-06 18:22:32
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.60 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 14:22:24.433975 2026] [security2:error] [pid 2693537:tid 2693537] [client 47.79.201.60:21106] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lertap5.com|F|2"] [data ".winzip.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lertap5.com"] [uri "/Documentation/www.winzip.com"] [unique_id "anTQ4D-7DknfnzXun_MvnAAAAAA"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-02 02:35:12
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.60 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 22:35:07.765211 2026] [security2:error] [pid 1627199:tid 1627199] [client 47.79.201.60:18434] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sangalgano.montepulciano.org|F|2"] [data ".themoneytizer.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sangalgano.montepulciano.org"] [uri "/www.themoneytizer.com"] [unique_id "am6s2wtyGs0YMqdzwVXrfgAAABo"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack