🇺🇸
TPI-Abuse
2026-09-11 22:15:30
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.193 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 18:15:24.469617 2026] [security2:error] [pid 17584:tid 17584] [client 47.79.206.193:61646] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bidsonlineauctions.com|F|2"] [data ".hibid.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bidsonlineauctions.com"] [uri "/www.hibid.com"] [unique_id "aqR9fJN-LqktU3uEOJjtzAAAAAA"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Vegascosmetics
2026-09-11 18:19:22
(9 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 67>=65, Abuse 64, NonEU, first-seen, Change* path)
show less
Hacking
Exploited Host
Web App Attack
🇩🇪
LRob
2026-09-11 17:11:13
(10 hours ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: /dossier/licence/feed | 2026-09-11 17:11 UTC
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 17:03:28
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.193 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:03:21.971756 2026] [security2:error] [pid 14195:tid 14195] [client 47.79.206.193:41982] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.smogsandiego.com|F|2"] [data ".asapstarsmog.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.smogsandiego.com"] [uri "/www.asapstarsmog.com"] [unique_id "aqQ0WS8IWkFFLlfRrxbx3AAAAAU"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-10 07:04:53
(1 day ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: /categorie/affichage-numerique | 2026-09-10 07:04 UTC
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-09 03:06:47
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 47.79.206.193 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 47.79.206.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 23:06:43.112617 2026] [security2:error] [pid 4486:tid 4486] [client 47.79.206.193:55706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nextngnr.com"] [uri "/f7ebIo.htaccess"] [unique_id "aqDNQz_h9t7rw2DBttaUfAAAAAM"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Charlesiv
2026-09-08 18:01:28
(3 days ago)
Triggered Cloudflare WAF (botFight) from SG.
Action taken: MANAGED_CHALLENGE
ASN: 45102 (Alibaba (US ...
show more
Triggered Cloudflare WAF (botFight) from SG.
Action taken: MANAGED_CHALLENGE
ASN: 45102 (Alibaba (US) Technology Co., Ltd.)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-09-08T17:00:06Z
Ray ID: a37f81eb0c2a9c71
UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 02:11:56
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.193 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:11:49.096326 2026] [security2:error] [pid 8533:tid 8556] [client 47.79.206.193:12354] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.newtrendmag.org|F|2"] [data ".oicsummit2003.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.newtrendmag.org"] [uri "/www.oicsummit2003.com"] [unique_id "ap9u5WAiVFrFp2-v2YicfwAAARU"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
jbcrn
2026-09-06 14:01:05
(5 days ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /deflagration.lomatine. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
🇩🇪
jbcrn
2026-09-03 10:11:09
(1 week ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /subaffluent-snoring. User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36
show less
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-02 11:46:32
(1 week ago)
Detected 45 connections from 47.79.206.193 last 60 minutes.; 47.79.206.193 is part of network 47.0.0 ...
show more
Detected 45 connections from 47.79.206.193 last 60 minutes.; 47.79.206.193 is part of network 47.0.0.0 with 207166 total distributed connections; Logs: 47.79.206.193 - - [02/Sep/2026:00:01:37 +0200] "GET /watch?v=FV9t_QsH_QA HTTP/1.1" 200 8354 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.206.193 - - [02/Sep/2026:00:01:57 +0200] "GET /hashtag/amitshahthuglife HTTP/1.1" 200 4854 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36" 47.79.206.193 - - [02/Sep/2026:00:03:01 +0200] "GET /watch?listen=false&v=5NEfkTLS5sw HTTP/1.1" 500 1571 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.206.193 - - [02/Sep/2026:00:03:21 +0200] "GET /watch?listen=false&v=T4LOnI2ee2w HTTP/1.1" 200 8820 "https://www.google.com/" "Moz
show less
DDoS Attack
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-02 11:31:05
(1 week ago)
Detected 44 connections from 47.79.206.193 last 60 minutes.; 47.79.206.193 is part of network 47.0.0 ...
show more
Detected 44 connections from 47.79.206.193 last 60 minutes.; 47.79.206.193 is part of network 47.0.0.0 with 207158 total distributed connections; Logs: 47.79.206.193 - - [02/Sep/2026:00:01:37 +0200] "GET /watch?v=FV9t_QsH_QA HTTP/1.1" 200 8354 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.206.193 - - [02/Sep/2026:00:01:57 +0200] "GET /hashtag/amitshahthuglife HTTP/1.1" 200 4854 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36" 47.79.206.193 - - [02/Sep/2026:00:03:01 +0200] "GET /watch?listen=false&v=5NEfkTLS5sw HTTP/1.1" 500 1571 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.206.193 - - [02/Sep/2026:00:03:21 +0200] "GET /watch?listen=false&v=T4LOnI2ee2w HTTP/1.1" 200 8820 "https://www.google.com/" "Moz
show less
DDoS Attack
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-02 11:15:40
(1 week ago)
Detected 41 connections from 47.79.206.193 last 60 minutes.; 47.79.206.193 is part of network 47.0.0 ...
show more
Detected 41 connections from 47.79.206.193 last 60 minutes.; 47.79.206.193 is part of network 47.0.0.0 with 201582 total distributed connections; Logs: 47.79.206.193 - - [02/Sep/2026:00:01:37 +0200] "GET /watch?v=FV9t_QsH_QA HTTP/1.1" 200 8354 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.206.193 - - [02/Sep/2026:00:01:57 +0200] "GET /hashtag/amitshahthuglife HTTP/1.1" 200 4854 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36" 47.79.206.193 - - [02/Sep/2026:00:03:01 +0200] "GET /watch?listen=false&v=5NEfkTLS5sw HTTP/1.1" 500 1571 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.206.193 - - [02/Sep/2026:00:03:21 +0200] "GET /watch?listen=false&v=T4LOnI2ee2w HTTP/1.1" 200 8820 "https://www.google.com/" "Moz
show less
DDoS Attack
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-02 11:00:23
(1 week ago)
Detected 44 connections from 47.79.206.193 last 60 minutes.; 47.79.206.193 is part of network 47.0.0 ...
show more
Detected 44 connections from 47.79.206.193 last 60 minutes.; 47.79.206.193 is part of network 47.0.0.0 with 192397 total distributed connections; Logs: 47.79.206.193 - - [02/Sep/2026:00:01:37 +0200] "GET /watch?v=FV9t_QsH_QA HTTP/1.1" 200 8354 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.206.193 - - [02/Sep/2026:00:01:57 +0200] "GET /hashtag/amitshahthuglife HTTP/1.1" 200 4854 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36" 47.79.206.193 - - [02/Sep/2026:00:03:01 +0200] "GET /watch?listen=false&v=5NEfkTLS5sw HTTP/1.1" 500 1571 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.206.193 - - [02/Sep/2026:00:03:21 +0200] "GET /watch?listen=false&v=T4LOnI2ee2w HTTP/1.1" 200 8820 "https://www.google.com/" "Moz
show less
DDoS Attack
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-02 10:30:44
(1 week ago)
Detected 44 connections from 47.79.206.193 last 60 minutes.; 47.79.206.193 is part of network 47.0.0 ...
show more
Detected 44 connections from 47.79.206.193 last 60 minutes.; 47.79.206.193 is part of network 47.0.0.0 with 192276 total distributed connections; Logs: 47.79.206.193 - - [02/Sep/2026:00:01:37 +0200] "GET /watch?v=FV9t_QsH_QA HTTP/1.1" 200 8354 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.206.193 - - [02/Sep/2026:00:01:57 +0200] "GET /hashtag/amitshahthuglife HTTP/1.1" 200 4854 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36" 47.79.206.193 - - [02/Sep/2026:00:03:01 +0200] "GET /watch?listen=false&v=5NEfkTLS5sw HTTP/1.1" 500 1571 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 47.79.206.193 - - [02/Sep/2026:00:03:21 +0200] "GET /watch?listen=false&v=T4LOnI2ee2w HTTP/1.1" 200 8820 "https://www.google.com/" "Moz
show less
DDoS Attack
Bad Web Bot
Web App Attack