🇺🇸
TPI-Abuse
2026-09-10 21:02:00
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 17:01:52.386799 2026] [security2:error] [pid 7316:tid 7316] [client 47.79.201.67:42518] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||carpascarpe.com|F|2"] [data ".weebly.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "carpascarpe.com"] [uri "/www.weebly.com"] [unique_id "aqMawP31bizOCvtDoL1HMwAAAA4"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-10 00:08:53
(1 day ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-10 00:08 UTC
show less
Bad Web Bot
🇩🇪
Vegascosmetics
2026-09-08 15:02:19
(2 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 65>=65, Abuse 60, NonEU, first-seen)
show less
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 13:07:21
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 09:07:13.613824 2026] [security2:error] [pid 29198:tid 29198] [client 47.79.201.67:6000] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.clayrivers.com|F|2"] [data ".clayrivers.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.clayrivers.com"] [uri "/www.clayrivers.com"] [unique_id "aqAIgShiCjmmvoyPKEzFYgAAAAA"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Selckie
2026-09-07 08:03:11
(4 days ago)
fail2ban: NGINX unusual impact
Web App Attack
🇩🇪
jbcrn
2026-09-06 14:04:35
(4 days ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /deflagration.Momordica-odontohyperesthesia. User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36
show less
Bad Web Bot
Web App Attack
🇩🇪
jbcrn
2026-09-03 10:10:56
(1 week ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /nonpause-ancestrian. User-Agent: Mozilla/5.0 (Linux; Android 12; Infinix X6817) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Mobile Safari/537.36
show less
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-02 11:29:13
(1 week ago)
Detected 31 connections from 47.79.201.67 last 60 minutes.; 47.79.201.67 is part of network 47.0.0.0 ...
show more
Detected 31 connections from 47.79.201.67 last 60 minutes.; 47.79.201.67 is part of network 47.0.0.0 with 207158 total distributed connections; Logs: 47.79.201.67 - - [02/Sep/2026:00:01:35 +0200] "GET /watch?listen=false&v=403PtyUB0FE HTTP/1.1" 499 0 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 47.79.201.67 - - [02/Sep/2026:00:01:46 +0200] "GET /watch?v=UJT3TIccnuA HTTP/1.1" 499 0 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.201.67 - - [02/Sep/2026:00:01:48 +0200] "GET /watch?nojs=1&v=ui6mAhGZ_vs HTTP/1.1" 499 0 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 47.79.201.67 - - [02/Sep/2026:00:02:13 +0200] "GET /watch?listen=1&v=78HAn6_W578 HTTP/1.1" 500 1568 "https://www.google.com/" "Mozilla/5.0 (Macinto
show less
DDoS Attack
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-02 11:13:45
(1 week ago)
Detected 33 connections from 47.79.201.67 last 60 minutes.; 47.79.201.67 is part of network 47.0.0.0 ...
show more
Detected 33 connections from 47.79.201.67 last 60 minutes.; 47.79.201.67 is part of network 47.0.0.0 with 200581 total distributed connections; Logs: 47.79.201.67 - - [02/Sep/2026:00:01:35 +0200] "GET /watch?listen=false&v=403PtyUB0FE HTTP/1.1" 499 0 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 47.79.201.67 - - [02/Sep/2026:00:01:46 +0200] "GET /watch?v=UJT3TIccnuA HTTP/1.1" 499 0 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.201.67 - - [02/Sep/2026:00:01:48 +0200] "GET /watch?nojs=1&v=ui6mAhGZ_vs HTTP/1.1" 499 0 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 47.79.201.67 - - [02/Sep/2026:00:02:13 +0200] "GET /watch?listen=1&v=78HAn6_W578 HTTP/1.1" 500 1568 "https://www.google.com/" "Mozilla/5.0 (Macinto
show less
DDoS Attack
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-02 10:58:32
(1 week ago)
Detected 37 connections from 47.79.201.67 last 60 minutes.; 47.79.201.67 is part of network 47.0.0.0 ...
show more
Detected 37 connections from 47.79.201.67 last 60 minutes.; 47.79.201.67 is part of network 47.0.0.0 with 192283 total distributed connections; Logs: 47.79.201.67 - - [02/Sep/2026:00:01:35 +0200] "GET /watch?listen=false&v=403PtyUB0FE HTTP/1.1" 499 0 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 47.79.201.67 - - [02/Sep/2026:00:01:46 +0200] "GET /watch?v=UJT3TIccnuA HTTP/1.1" 499 0 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.201.67 - - [02/Sep/2026:00:01:48 +0200] "GET /watch?nojs=1&v=ui6mAhGZ_vs HTTP/1.1" 499 0 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 47.79.201.67 - - [02/Sep/2026:00:02:13 +0200] "GET /watch?listen=1&v=78HAn6_W578 HTTP/1.1" 500 1568 "https://www.google.com/" "Mozilla/5.0 (Macinto
show less
DDoS Attack
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-02 10:28:55
(1 week ago)
Detected 41 connections from 47.79.201.67 last 60 minutes.; 47.79.201.67 is part of network 47.0.0.0 ...
show more
Detected 41 connections from 47.79.201.67 last 60 minutes.; 47.79.201.67 is part of network 47.0.0.0 with 192276 total distributed connections; Logs: 47.79.201.67 - - [02/Sep/2026:00:01:35 +0200] "GET /watch?listen=false&v=403PtyUB0FE HTTP/1.1" 499 0 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 47.79.201.67 - - [02/Sep/2026:00:01:46 +0200] "GET /watch?v=UJT3TIccnuA HTTP/1.1" 499 0 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.201.67 - - [02/Sep/2026:00:01:48 +0200] "GET /watch?nojs=1&v=ui6mAhGZ_vs HTTP/1.1" 499 0 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 47.79.201.67 - - [02/Sep/2026:00:02:13 +0200] "GET /watch?listen=1&v=78HAn6_W578 HTTP/1.1" 500 1568 "https://www.google.com/" "Mozilla/5.0 (Macinto
show less
DDoS Attack
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-01 22:02:47
(1 week ago)
Detected 49 connections from 47.79.201.67 last 60 minutes.; 47.79.201.67 is part of network 47.79.0. ...
show more
Detected 49 connections from 47.79.201.67 last 60 minutes.; 47.79.201.67 is part of network 47.79.0.0 with 29245 distributed connections; Logs: 47.79.201.67 - - [02/Sep/2026:00:01:35 +0200] "GET /watch?listen=false&v=403PtyUB0FE HTTP/1.1" 499 0 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 47.79.201.67 - - [02/Sep/2026:00:01:46 +0200] "GET /watch?v=UJT3TIccnuA HTTP/1.1" 499 0 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.201.67 - - [02/Sep/2026:00:01:48 +0200] "GET /watch?nojs=1&v=ui6mAhGZ_vs HTTP/1.1" 499 0 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 47.79.201.67 - - [02/Sep/2026:00:02:13 +0200] "GET /watch?listen=1&v=78HAn6_W578 HTTP/1.1" 500 1568 "https://www.google.com/" "Mozilla/5.0 (Macintosh; In
show less
DDoS Attack
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-01 21:52:59
(1 week ago)
Detected 49 connections from 47.79.201.67 last 60 minutes.; 47.79.201.67 is part of network 47.79.0. ...
show more
Detected 49 connections from 47.79.201.67 last 60 minutes.; 47.79.201.67 is part of network 47.79.0.0 with 29238 distributed connections; Logs: 47.79.201.67 - - [01/Sep/2026:18:01:33 +0200] "GET /hashtag/yogisarkar HTTP/1.1" 500 2419 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 47.79.201.67 - - [01/Sep/2026:18:04:43 +0200] "GET /watch?listen=false&v=q5G0VQ9_S_Y HTTP/1.1" 500 1573 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.201.67 - - [01/Sep/2026:18:05:22 +0200] "GET /hashtag/malavallimahadevaswamy HTTP/1.1" 200 6355 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36" 47.79.201.67 - - [01/Sep/2026:18:10:15 +0200] "GET /preferences?referer=/watch?listen=1&v=LFqfj5e9kMg HTTP/1.1" 200 6377 "https://www.google.co
show less
DDoS Attack
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-01 21:32:38
(1 week ago)
Detected 50 connections from 47.79.201.67 last 60 minutes.; 47.79.201.67 is part of network 47.79.0. ...
show more
Detected 50 connections from 47.79.201.67 last 60 minutes.; 47.79.201.67 is part of network 47.79.0.0 with 29234 distributed connections; Logs: 47.79.201.67 - - [01/Sep/2026:18:01:33 +0200] "GET /hashtag/yogisarkar HTTP/1.1" 500 2419 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 47.79.201.67 - - [01/Sep/2026:18:04:43 +0200] "GET /watch?listen=false&v=q5G0VQ9_S_Y HTTP/1.1" 500 1573 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.201.67 - - [01/Sep/2026:18:05:22 +0200] "GET /hashtag/malavallimahadevaswamy HTTP/1.1" 200 6355 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36" 47.79.201.67 - - [01/Sep/2026:18:10:15 +0200] "GET /preferences?referer=/watch?listen=1&v=LFqfj5e9kMg HTTP/1.1" 200 6377 "https://www.google.co
show less
DDoS Attack
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-01 21:12:15
(1 week ago)
Detected 34 connections from 47.79.201.67 last 60 minutes.; 47.79.201.67 is part of network 47.79.0. ...
show more
Detected 34 connections from 47.79.201.67 last 60 minutes.; 47.79.201.67 is part of network 47.79.0.0 with 30197 distributed connections; Logs: 47.79.201.67 - - [01/Sep/2026:18:01:33 +0200] "GET /hashtag/yogisarkar HTTP/1.1" 500 2419 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 47.79.201.67 - - [01/Sep/2026:18:04:43 +0200] "GET /watch?listen=false&v=q5G0VQ9_S_Y HTTP/1.1" 500 1573 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.201.67 - - [01/Sep/2026:18:05:22 +0200] "GET /hashtag/malavallimahadevaswamy HTTP/1.1" 200 6355 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36" 47.79.201.67 - - [01/Sep/2026:18:10:15 +0200] "GET /preferences?referer=/watch?listen=1&v=LFqfj5e9kMg HTTP/1.1" 200 6377 "https://www.google.co
show less
DDoS Attack
Bad Web Bot
Web App Attack