🇩🇪
Vegascosmetics
2026-09-11 18:03:21
(5 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after high AbuseIPDB reputation + local blo ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after high AbuseIPDB reputation + local block policy. Evidence: High Abuse + Suspicion (64, Abuse: 59)
show less
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 15:11:24
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 47.79.207.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.207.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 11:11:20.694104 2026] [security2:error] [pid 28534:tid 28534] [client 47.79.207.214:19458] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.americanureport.com|F|2"] [data ".americanureport.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.americanureport.com"] [uri "/tag/alumni/www.americanureport.com"] [unique_id "aqLImPI0AfJd1XXaQMFQEgAAABE"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 04:08:15
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 47.79.207.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.207.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 00:08:08.272058 2026] [security2:error] [pid 31431:tid 31465] [client 47.79.207.214:31178] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||whatismetamodern.com|F|2"] [data ".instagram.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "whatismetamodern.com"] [uri "/film/lars-and-the-real-girl-metamodernism/www.instagram.com"] [unique_id "aqItKHNkqeK6GZcKL0gJCwAAAQU"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 01:09:54
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 47.79.207.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.207.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 21:09:47.440840 2026] [security2:error] [pid 9787:tid 9787] [client 47.79.207.214:30966] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||leolion.net|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "leolion.net"] [uri "/cynosurephotography.com"] [unique_id "aqIDW9E8d-V0-iQEOH0JHQAAAAU"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 23:02:38
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.207.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.207.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 19:02:34.616684 2026] [security2:error] [pid 10861:tid 10861] [client 47.79.207.214:8772] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||home.agingworkforcenews.com|F|2"] [data ".thenation.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "home.agingworkforcenews.com"] [uri "/2005/http.thenation.com"] [unique_id "aqHlim4JpOdJ-TE3keyjYgAAAAI"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 06:04:51
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.207.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.207.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 02:04:45.625854 2026] [security2:error] [pid 19615:tid 19615] [client 47.79.207.214:39678] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||englishmagic.us|F|2"] [data ".coffeecup.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "englishmagic.us"] [uri "/www.coffeecup.com"] [unique_id "aqD2_QcTWLB4ZeDUvKgBegAAACE"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 21:00:47
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.207.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.207.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 17:00:39.469722 2026] [security2:error] [pid 17942:tid 17969] [client 47.79.207.214:37222] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aafm.us|F|2"] [data ".aafmafrica.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aafm.us"] [uri "/www.AAFMAfrica.com"] [unique_id "aqB3dzdrzj1cf2vCNqyamAAAAVc"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
london2038.com
2026-09-07 02:00:19
(4 days ago)
Malformed or malicious web request
47.79.207.214 - - [07/Sep/2026:04:00:14 +0200] "GET /%20London203 ...
show more
Malformed or malicious web request
47.79.207.214 - - [07/Sep/2026:04:00:14 +0200] "GET /%20London2038%5D. HTTP/1.1" 301 0 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 12; Infinix X6817) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Mobile Safari/537.36"
show less
Hacking
Web App Attack
🇩🇪
jbcrn
2026-09-06 14:01:47
(5 days ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /deflagration.describable-plankage. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 11:03:18
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.207.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.207.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 07:03:10.143048 2026] [security2:error] [pid 657:tid 657] [client 47.79.207.214:30954] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.thebeeplace.com|F|2"] [data ".scientificbeekeeping.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.thebeeplace.com"] [uri "/learning-center/additional-resources/www.ScientificBeekeeping.com"] [unique_id "ap1Ibtjwr-RCU19Twgb74AAAABQ"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
jbcrn
2026-09-03 11:10:48
(1 week ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /turmoil-meganucleus. User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36
show less
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-02 12:16:00
(1 week ago)
Detected 33 connections from 47.79.207.214 last 60 minutes.; 47.79.207.214 is part of network 47.0.0 ...
show more
Detected 33 connections from 47.79.207.214 last 60 minutes.; 47.79.207.214 is part of network 47.0.0.0 with 207166 total distributed connections; Logs: 47.79.207.214 - - [02/Sep/2026:00:00:09 +0200] "GET /watch?v=0K--JtXxM9U HTTP/1.1" 200 7207 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36" 47.79.207.214 - - [02/Sep/2026:00:01:38 +0200] "GET /watch?listen=false&v=TnWbFesV2h0 HTTP/1.1" 500 1570 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36" 47.79.207.214 - - [02/Sep/2026:00:01:39 +0200] "GET /embed/jr2EgkwUQ0I HTTP/1.1" 200 1639 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36 Edg/132.0.0.0" 47.79.207.214 - - [02/Sep/2026:00:03:02 +0200] "GET /toggle_theme?referer=/watch?listen=1&v=HdvZLbkkL08 HTTP/1.1" 302 0 "https://w
show less
DDoS Attack
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-02 11:48:30
(1 week ago)
Detected 42 connections from 47.79.207.214 last 60 minutes.; 47.79.207.214 is part of network 47.0.0 ...
show more
Detected 42 connections from 47.79.207.214 last 60 minutes.; 47.79.207.214 is part of network 47.0.0.0 with 207166 total distributed connections; Logs: 47.79.207.214 - - [02/Sep/2026:00:00:09 +0200] "GET /watch?v=0K--JtXxM9U HTTP/1.1" 200 7207 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36" 47.79.207.214 - - [02/Sep/2026:00:01:38 +0200] "GET /watch?listen=false&v=TnWbFesV2h0 HTTP/1.1" 500 1570 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36" 47.79.207.214 - - [02/Sep/2026:00:01:39 +0200] "GET /embed/jr2EgkwUQ0I HTTP/1.1" 200 1639 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36 Edg/132.0.0.0" 47.79.207.214 - - [02/Sep/2026:00:03:02 +0200] "GET /toggle_theme?referer=/watch?listen=1&v=HdvZLbkkL08 HTTP/1.1" 302 0 "https://w
show less
DDoS Attack
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-02 11:33:04
(1 week ago)
Detected 45 connections from 47.79.207.214 last 60 minutes.; 47.79.207.214 is part of network 47.0.0 ...
show more
Detected 45 connections from 47.79.207.214 last 60 minutes.; 47.79.207.214 is part of network 47.0.0.0 with 207158 total distributed connections; Logs: 47.79.207.214 - - [02/Sep/2026:00:00:09 +0200] "GET /watch?v=0K--JtXxM9U HTTP/1.1" 200 7207 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36" 47.79.207.214 - - [02/Sep/2026:00:01:38 +0200] "GET /watch?listen=false&v=TnWbFesV2h0 HTTP/1.1" 500 1570 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36" 47.79.207.214 - - [02/Sep/2026:00:01:39 +0200] "GET /embed/jr2EgkwUQ0I HTTP/1.1" 200 1639 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36 Edg/132.0.0.0" 47.79.207.214 - - [02/Sep/2026:00:03:02 +0200] "GET /toggle_theme?referer=/watch?listen=1&v=HdvZLbkkL08 HTTP/1.1" 302 0 "https://w
show less
DDoS Attack
Bad Web Bot
Web App Attack
🇳🇴
tmiland
2026-09-02 11:17:40
(1 week ago)
Detected 48 connections from 47.79.207.214 last 60 minutes.; 47.79.207.214 is part of network 47.0.0 ...
show more
Detected 48 connections from 47.79.207.214 last 60 minutes.; 47.79.207.214 is part of network 47.0.0.0 with 202559 total distributed connections; Logs: 47.79.207.214 - - [02/Sep/2026:00:00:09 +0200] "GET /watch?v=0K--JtXxM9U HTTP/1.1" 200 7207 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36" 47.79.207.214 - - [02/Sep/2026:00:01:38 +0200] "GET /watch?listen=false&v=TnWbFesV2h0 HTTP/1.1" 500 1570 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36" 47.79.207.214 - - [02/Sep/2026:00:01:39 +0200] "GET /embed/jr2EgkwUQ0I HTTP/1.1" 200 1639 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36 Edg/132.0.0.0" 47.79.207.214 - - [02/Sep/2026:00:03:02 +0200] "GET /toggle_theme?referer=/watch?listen=1&v=HdvZLbkkL08 HTTP/1.1" 302 0 "https://w
show less
DDoS Attack
Bad Web Bot
Web App Attack