🇺🇸
TPI-Abuse
2026-09-10 05:11:23
(17 minutes ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.63 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 01:11:17.528225 2026] [security2:error] [pid 31588:tid 31588] [client 47.79.201.63:20412] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||cedricwillems.com|F|2"] [data ".cedricwillems.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cedricwillems.com"] [uri "/www.cedricwillems.com"] [unique_id "aqI79Z3c4VZlVI6pthVzyQAAABE"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-10 03:04:06
(2 hours ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-10 03:04 UTC
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-10 02:11:54
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.63 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 22:11:49.595703 2026] [security2:error] [pid 8988:tid 8988] [client 47.79.201.63:59146] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.americanureport.com|F|2"] [data ".americanureport.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.americanureport.com"] [uri "/tag/tuition/www.americanureport.com"] [unique_id "aqIR5edJqyZrkyaXksia8AAAAAw"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 21:09:49
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.63 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 17:09:42.334678 2026] [security2:error] [pid 15599:tid 15599] [client 47.79.201.63:14572] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rail-town.com|F|2"] [data ".cosmi.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rail-town.com"] [uri "/www.cosmi.com"] [unique_id "aqHLFoXMG9VD64mMg1-gCQAAAAw"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 18:03:31
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.63 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 14:03:26.752462 2026] [security2:error] [pid 25326:tid 25383] [client 47.79.201.63:44454] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||newtrendmag.org|F|2"] [data ".talibancountry.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "newtrendmag.org"] [uri "/www.TalibanCountry.com"] [unique_id "aqGfbkvivgOWLqKMQhrD1AAAAI4"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 16:08:00
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.63 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 12:07:53.330054 2026] [security2:error] [pid 1674267:tid 1674267] [client 47.79.201.63:7046] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.artocratic.com|F|2"] [data ".orchidtierney.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.artocratic.com"] [uri "/home/www.orchidtierney.com"] [unique_id "aqGEWVDx8tH7aAqMBClfzQAAABI"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 03:09:55
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.63 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 23:09:48.345139 2026] [security2:error] [pid 11084:tid 11084] [client 47.79.201.63:21350] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.northfortworthalliance.com|F|2"] [data ".facebook.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.northfortworthalliance.com"] [uri "/www.facebook.com"] [unique_id "aqDN_JGw4ockoNgWM6LQ5wAAAAM"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-09 03:09:07
(1 day ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: /pylog/index.html | 2026-09-09 03:09 UTC
show less
Bad Web Bot
🇩🇪
jbcrn
2026-09-06 14:00:42
(3 days ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /deflagration.superably. User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Mobile Safari/537.36
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 09:02:49
(3 days ago)
Web application attack detected.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:04:14
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.63 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:04:09.458826 2026] [security2:error] [pid 15365:tid 15365] [client 47.79.201.63:56438] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nunsunveiled.com|F|2"] [data ".cherylreed.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nunsunveiled.com"] [uri "/www.cherylreed.com"] [unique_id "apyDyaoAAKtR1FuzHRvO6QAAAGo"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
flaus
2026-09-04 02:16:32
(6 days ago)
$f2bV_matches
Hacking
Bad Web Bot
Web App Attack
🇩🇪
jbcrn
2026-09-03 13:08:44
(6 days ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /unimputed-hereunder. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
🇵🇹
Information Security
2026-09-02 15:20:33
(1 week ago)
Web App Attack
Web App Attack
🇳🇴
tmiland
2026-09-02 11:44:38
(1 week ago)
Detected 33 connections from 47.79.201.63 last 60 minutes.; 47.79.201.63 is part of network 47.0.0.0 ...
show more
Detected 33 connections from 47.79.201.63 last 60 minutes.; 47.79.201.63 is part of network 47.0.0.0 with 207166 total distributed connections; Logs: 47.79.201.63 - - [02/Sep/2026:00:00:53 +0200] "GET /watch?index=7&list=PLvaFvXiKiETQBy5bCUr2k33NJgnhDWh81&v=fWtxM1bPSfg HTTP/1.1" 200 6957 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36" 47.79.201.63 - - [02/Sep/2026:00:01:35 +0200] "GET /watch?iv_load_policy=1&list=PLgoGNHv8BlgEDTLuJbjDk10sFwoJ-cBIi&v=EIICLkjz4OI HTTP/1.1" 499 0 "https://www.google.com/" "Mozilla/5.0 (Linux; arm_64; Android 14; SM-A346E) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6723.1012 YaSearchBrowser/24.125.1 BroPP/1.0 YaSearchApp/24.125.1 webOmni SA/3 Mobile Safari/537.36" 47.79.201.63 - - [02/Sep/2026:00:01:39 +0200] "GET /hashtag/bigtvlive HTTP/1.1" 200 6716 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.
show less
DDoS Attack
Bad Web Bot
Web App Attack