๐ฉ๐ช
HERA - Operations
2026-09-02 04:02:15
(1 day ago)
sensobox - searching for vulnerable scripts: security.txt 2026/09/02 06:02:15
Web App Attack
๐ช๐ธ
librebit
2026-08-28 10:22:33
(5 days ago)
Brute force
Brute-Force
๐น๐ท
neron
2026-08-15 23:06:48
(2 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-08-10 00:29:22
(3 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐บ๐ธ
Lezetho
2026-08-04 06:00:12
(4 weeks ago)
DDoS, WebSpam, Web Attack, and Brute-force blocked by Cloudflare
DDoS Attack
Email Spam
Hacking
Brute-Force
๐น๐ท
neron
2026-07-28 10:19:38
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-14 06:30:53
(1 month ago)
(mod_security) mod_security (id:243420) triggered by 149.56.150.11 (crawl-149-56-150-11.dataprovider ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.150.11 (crawl-149-56-150-11.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 14 02:30:49.691070 2026] [security2:error] [pid 23696:tid 23696] [client 149.56.150.11:37343] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.ospreylake.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.ospreylake.org"] [uri "/AppData/Local/Temp/osprey_milfoil.htm"] [unique_id "alXXmetjS6IKEFxFC4rVlgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-12 05:10:00
(1 month ago)
(mod_security) mod_security (id:243420) triggered by 149.56.150.11 (crawl-149-56-150-11.dataprovider ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.150.11 (crawl-149-56-150-11.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 01:09:55.287762 2026] [security2:error] [pid 18373:tid 18373] [client 149.56.150.11:37783] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.stewhist.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.stewhist.org"] [uri "/index.html"] [unique_id "alMho4l9agFm4KEyFFnoxgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
SkyDancer
2026-07-08 01:13:39
(1 month ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
Anonymous
2026-07-06 11:59:49
(1 month ago)
149.56.150.11 - - [06/Jul/2026:11:59:49 +0000] "GET /robots.txt HTTP/1.1" 404 162 "-" "Mozilla/5.0 ( ...
show more
149.56.150.11 - - [06/Jul/2026:11:59:49 +0000] "GET /robots.txt HTTP/1.1" 404 162 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.11 - - [06/Jul/2026:11:59:49 +0000] "GET /sitemap.xml HTTP/1.1" 404 162 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 21:23:54
(2 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.150.11 (crawl-149-56-150-11.dataprovider ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.150.11 (crawl-149-56-150-11.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 17:23:51.046898 2026] [security2:error] [pid 28766:tid 28766] [client 149.56.150.11:52563] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||musicshowcase.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "musicshowcase.us"] [uri "/bandolero.htm"] [unique_id "ajMQZxEbKdsP_3n3ayvMbQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
psauxit
2026-05-27 00:16:57
(3 months ago)
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrp ...
show more
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrpc_attack, wp-login brute force, excessive crawling/scraping
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-30 08:32:59
(4 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.150.11 (crawl-149-56-150-11.dataprovider ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.150.11 (crawl-149-56-150-11.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 04:32:55.375206 2026] [security2:error] [pid 5072:tid 5072] [client 149.56.150.11:53009] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.homecheckinmaine.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.homecheckinmaine.com"] [uri "/contact.php"] [unique_id "afMTtyWnjWMaV_l-xQBLqAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2026-04-04 18:13:08
(4 months ago)
2026-04-04 20:13:08 (CET) ~ Blocked by abusescan risk assessment
Web App Attack
๐บ๐ธ
lavnet.net
2026-03-29 18:05:03
(5 months ago)
149.56.150.11 - - [29/Mar/2026:18:05:02 +0000] "GET /sitemap.xml HTTP/1.1" 404 2110 "-" "Mozilla/5.0 ...
show more
149.56.150.11 - - [29/Mar/2026:18:05:02 +0000] "GET /sitemap.xml HTTP/1.1" 404 2110 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.11 - - [29/Mar/2026:18:05:02 +0000] "GET /ads.txt HTTP/1.1" 404 2083 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.11 - - [29/Mar/2026:18:05:03 +0000] "GET /security.txt HTTP/1.1" 404 2083 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.11 - - [29/Mar/2026:18:05:03 +0000] "GET /.well-known/security.txt HTTP/1.1" 404 2083 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.11 - - [29/Mar/2026:18:05:03 +0000] "GET /llms.txt HTTP/1.1" 404 2083 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.11 - - [29/Mar/2026:18:05:03 +0000] "GET /humans.txt HTTP/1.1" 404 2083 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
...
show less
Brute-Force