🇺🇸
TPI-Abuse
2026-09-09 12:08:00
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:07:53.830299 2026] [security2:error] [pid 7010:tid 7020] [client 47.79.201.96:58318] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.sallykimmel.com|F|2"] [data ".sallykimmel.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.sallykimmel.com"] [uri "/www.sallykimmel.com"] [unique_id "aqFMGRvpa14_1M83y__mzQAAAIY"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 00:09:25
(1 day ago)
apache vulnerability scan
Web App Attack
🇩🇪
Vegascosmetics
2026-09-07 23:06:36
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after high AbuseIPDB reputation + local blo ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after high AbuseIPDB reputation + local block policy. Evidence: High Abuse + Suspicion (64, Abuse: 59)
show less
Hacking
Exploited Host
Web App Attack
🇩🇪
jbcrn
2026-09-06 14:00:18
(3 days ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /deflagration.enamourment. User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 06:03:17
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 02:03:11.475449 2026] [security2:error] [pid 2528:tid 2528] [client 47.79.201.96:52748] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jerusalem-korczak-home.com|F|2"] [data ".jerusalem-korczak-home.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jerusalem-korczak-home.com"] [uri "/td/www.jerusalem-korczak-home.com"] [unique_id "ap0CH6Gpo3nohz6Zwf2YvQAAAGc"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:03:36
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:03:30.295736 2026] [security2:error] [pid 19052:tid 19052] [client 47.79.201.96:34220] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tobyjohnson.com|F|2"] [data ".librarything.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tobyjohnson.com"] [uri "/www.librarything.com"] [unique_id "appfMhcEVi9zEnwUlloDkAAAABY"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
jbcrn
2026-09-03 12:07:32
(6 days ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /dairi-parepididymis. User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36
show less
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-02 11:45:01
(1 week ago)
Detected 37 connections from 47.79.201.96 last 60 minutes.; 47.79.201.96 is part of network 47.0.0.0 ...
show more
Detected 37 connections from 47.79.201.96 last 60 minutes.; 47.79.201.96 is part of network 47.0.0.0 with 207166 total distributed connections; Logs: 47.79.201.96 - - [02/Sep/2026:00:01:38 +0200] "GET /watch?listen=1&v=SGTdpa2z6Ig HTTP/1.1" 500 1567 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 47.79.201.96 - - [02/Sep/2026:00:01:38 +0200] "GET /watch?listen=false&v=eLSOeaYKQ6s HTTP/1.1" 500 1571 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36" 47.79.201.96 - - [02/Sep/2026:00:02:00 +0200] "GET /channel/UCpH-ILyduTkw2Va6Hc7tvAw HTTP/1.1" 200 13654 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.201.96 - - [02/Sep/2026:00:02:16 +0200] "GET /watch?nojs=1&v=bLD_jbIKnSA HTTP/1.1" 500 1566 "https://www.google.com/"
show less
DDoS Attack
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-02 11:14:08
(1 week ago)
Detected 31 connections from 47.79.201.96 last 60 minutes.; 47.79.201.96 is part of network 47.0.0.0 ...
show more
Detected 31 connections from 47.79.201.96 last 60 minutes.; 47.79.201.96 is part of network 47.0.0.0 with 200785 total distributed connections; Logs: 47.79.201.96 - - [02/Sep/2026:00:01:38 +0200] "GET /watch?listen=1&v=SGTdpa2z6Ig HTTP/1.1" 500 1567 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 47.79.201.96 - - [02/Sep/2026:00:01:38 +0200] "GET /watch?listen=false&v=eLSOeaYKQ6s HTTP/1.1" 500 1571 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36" 47.79.201.96 - - [02/Sep/2026:00:02:00 +0200] "GET /channel/UCpH-ILyduTkw2Va6Hc7tvAw HTTP/1.1" 200 13654 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.201.96 - - [02/Sep/2026:00:02:16 +0200] "GET /watch?nojs=1&v=bLD_jbIKnSA HTTP/1.1" 500 1566 "https://www.google.com/"
show less
DDoS Attack
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-02 10:58:54
(1 week ago)
Detected 33 connections from 47.79.201.96 last 60 minutes.; 47.79.201.96 is part of network 47.0.0.0 ...
show more
Detected 33 connections from 47.79.201.96 last 60 minutes.; 47.79.201.96 is part of network 47.0.0.0 with 192283 total distributed connections; Logs: 47.79.201.96 - - [02/Sep/2026:00:01:38 +0200] "GET /watch?listen=1&v=SGTdpa2z6Ig HTTP/1.1" 500 1567 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 47.79.201.96 - - [02/Sep/2026:00:01:38 +0200] "GET /watch?listen=false&v=eLSOeaYKQ6s HTTP/1.1" 500 1571 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36" 47.79.201.96 - - [02/Sep/2026:00:02:00 +0200] "GET /channel/UCpH-ILyduTkw2Va6Hc7tvAw HTTP/1.1" 200 13654 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.201.96 - - [02/Sep/2026:00:02:16 +0200] "GET /watch?nojs=1&v=bLD_jbIKnSA HTTP/1.1" 500 1566 "https://www.google.com/"
show less
DDoS Attack
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-02 10:29:18
(1 week ago)
Detected 38 connections from 47.79.201.96 last 60 minutes.; 47.79.201.96 is part of network 47.0.0.0 ...
show more
Detected 38 connections from 47.79.201.96 last 60 minutes.; 47.79.201.96 is part of network 47.0.0.0 with 192276 total distributed connections; Logs: 47.79.201.96 - - [02/Sep/2026:00:01:38 +0200] "GET /watch?listen=1&v=SGTdpa2z6Ig HTTP/1.1" 500 1567 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 47.79.201.96 - - [02/Sep/2026:00:01:38 +0200] "GET /watch?listen=false&v=eLSOeaYKQ6s HTTP/1.1" 500 1571 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36" 47.79.201.96 - - [02/Sep/2026:00:02:00 +0200] "GET /channel/UCpH-ILyduTkw2Va6Hc7tvAw HTTP/1.1" 200 13654 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.201.96 - - [02/Sep/2026:00:02:16 +0200] "GET /watch?nojs=1&v=bLD_jbIKnSA HTTP/1.1" 500 1566 "https://www.google.com/"
show less
DDoS Attack
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-01 22:03:02
(1 week ago)
Detected 38 connections from 47.79.201.96 last 60 minutes.; 47.79.201.96 is part of network 47.79.0. ...
show more
Detected 38 connections from 47.79.201.96 last 60 minutes.; 47.79.201.96 is part of network 47.79.0.0 with 29245 distributed connections; Logs: 47.79.201.96 - - [02/Sep/2026:00:01:38 +0200] "GET /watch?listen=1&v=SGTdpa2z6Ig HTTP/1.1" 500 1567 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 47.79.201.96 - - [02/Sep/2026:00:01:38 +0200] "GET /watch?listen=false&v=eLSOeaYKQ6s HTTP/1.1" 500 1571 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36" 47.79.201.96 - - [02/Sep/2026:00:02:00 +0200] "GET /channel/UCpH-ILyduTkw2Va6Hc7tvAw HTTP/1.1" 200 13654 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.201.96 - - [02/Sep/2026:00:02:16 +0200] "GET /watch?nojs=1&v=bLD_jbIKnSA HTTP/1.1" 500 1566 "https://www.google.com/" "Moz
show less
DDoS Attack
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-01 21:43:04
(1 week ago)
Detected 38 connections from 47.79.201.96 last 60 minutes.; 47.79.201.96 is part of network 47.79.0. ...
show more
Detected 38 connections from 47.79.201.96 last 60 minutes.; 47.79.201.96 is part of network 47.79.0.0 with 29246 distributed connections; Logs: 47.79.201.96 - - [01/Sep/2026:18:00:21 +0200] "GET /watch?listen=1&v=qp-ezuQg0VI HTTP/1.1" 200 7447 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36 Edg/132.0.0.0" 47.79.201.96 - - [01/Sep/2026:18:00:24 +0200] "GET /watch?v=gGU0ymVaSug HTTP/1.1" 200 8464 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36" 47.79.201.96 - - [01/Sep/2026:18:00:37 +0200] "GET /hashtag/vijayprasadreddydebate HTTP/1.1" 200 1528 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Mobile Safari/537.36" 47.79.201.96 - - [01/Sep/2026:18:01:43 +0200] "GET /watch?iv_load_policy=1&v=DMCYSqF5xTY HTTP/1.1" 499 0 "https://www.google.com/"
show less
DDoS Attack
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-01 21:22:43
(1 week ago)
Detected 34 connections from 47.79.201.96 last 60 minutes.; 47.79.201.96 is part of network 47.79.0. ...
show more
Detected 34 connections from 47.79.201.96 last 60 minutes.; 47.79.201.96 is part of network 47.79.0.0 with 30030 distributed connections; Logs: 47.79.201.96 - - [01/Sep/2026:18:00:21 +0200] "GET /watch?listen=1&v=qp-ezuQg0VI HTTP/1.1" 200 7447 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36 Edg/132.0.0.0" 47.79.201.96 - - [01/Sep/2026:18:00:24 +0200] "GET /watch?v=gGU0ymVaSug HTTP/1.1" 200 8464 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36" 47.79.201.96 - - [01/Sep/2026:18:00:37 +0200] "GET /hashtag/vijayprasadreddydebate HTTP/1.1" 200 1528 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Mobile Safari/537.36" 47.79.201.96 - - [01/Sep/2026:18:01:43 +0200] "GET /watch?iv_load_policy=1&v=DMCYSqF5xTY HTTP/1.1" 499 0 "https://www.google.com/"
show less
DDoS Attack
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-01 21:02:21
(1 week ago)
Detected 31 connections from 47.79.201.96 last 60 minutes.; 47.79.201.96 is part of network 47.79.0. ...
show more
Detected 31 connections from 47.79.201.96 last 60 minutes.; 47.79.201.96 is part of network 47.79.0.0 with 29606 distributed connections; Logs: 47.79.201.96 - - [01/Sep/2026:18:00:21 +0200] "GET /watch?listen=1&v=qp-ezuQg0VI HTTP/1.1" 200 7447 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36 Edg/132.0.0.0" 47.79.201.96 - - [01/Sep/2026:18:00:24 +0200] "GET /watch?v=gGU0ymVaSug HTTP/1.1" 200 8464 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36" 47.79.201.96 - - [01/Sep/2026:18:00:37 +0200] "GET /hashtag/vijayprasadreddydebate HTTP/1.1" 200 1528 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Mobile Safari/537.36" 47.79.201.96 - - [01/Sep/2026:18:01:43 +0200] "GET /watch?iv_load_policy=1&v=DMCYSqF5xTY HTTP/1.1" 499 0 "https://www.google.com/"
show less
DDoS Attack
Bad Web Bot
Web App Attack