๐น๐ท
neron
2026-08-15 23:06:48
(1 week ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-08-09 22:29:21
(2 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ฌ๐ง
candc
2026-07-08 07:02:47
(1 month ago)
Observed suspicious activity over last 24h.
Requests: 7; security events: 1.
Top path: / (4 hits).
Web App Attack
Brute-Force
๐บ๐ธ
VanKoh
2026-06-05 21:17:58
(2 months ago)
149.56.150.118 - - [05/Jun/2026:15:17:52 -0600] "GET / HTTP/1.1" 301 5 "-" "Mozilla/5.0 (compatible; ...
show more
149.56.150.118 - - [05/Jun/2026:15:17:52 -0600] "GET / HTTP/1.1" 301 5 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.118 - - [05/Jun/2026:15:17:52 -0600] "GET / HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.118 - - [05/Jun/2026:15:17:56 -0600] "GET /robots.txt HTTP/1.1" 301 5 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
...
show less
Port Scan
Web App Attack
๐ซ๐ฎ
YF
2026-05-12 14:03:51
(3 months ago)
WordPress directory enumeration
Web App Attack
๐ฉ๐ช
Viveronese
2026-05-11 04:04:34
(3 months ago)
HTTP vulnerability scanning
Web App Attack
Anonymous
2026-05-03 22:05:50
(3 months ago)
149.56.150.118 - - [04/May/2026:00:05:50 +0200] "GET / HTTP/1.1" 301 169 "-" "Mozilla/5.0 (compatibl ...
show more
149.56.150.118 - - [04/May/2026:00:05:50 +0200] "GET / HTTP/1.1" 301 169 "-" "Mozilla/5.0 (compatible; )"
show less
Bad Web Bot
๐ฉ๐ช
netclix.gr
2026-04-09 03:39:53
(4 months ago)
(aggressive_scan) Aggressive Web Exploit Scan 149.56.150.118 (CA/Canada/crawl-149-56-150-118.datapro ...
show more
(aggressive_scan) Aggressive Web Exploit Scan 149.56.150.118 (CA/Canada/crawl-149-56-150-118.dataproviderbot.com): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: default:80 149.56.150.118 - - [09/Apr/2026:06:39:50 +0300] "GET /sitemap.xml HTTP/1.0" 404 424 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
show less
Port Scan
Anonymous
2026-03-30 05:14:55
(4 months ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-14 22:00:43
(5 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.150.118 (crawl-149-56-150-118.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.150.118 (crawl-149-56-150-118.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 18:00:37.406461 2026] [security2:error] [pid 12960:tid 12966] [client 149.56.150.118:47371] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.earthtravel.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.earthtravel.net"] [uri "/index.php"] [unique_id "abXaheqxg5Z4b06oxIoBCQAAAQE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
librebit
2026-02-10 05:22:23
(6 months ago)
Brute force
Brute-Force
๐ช๐ธ
librebit
2026-02-07 10:21:08
(6 months ago)
Brute force
Brute-Force
Anonymous
2026-01-19 09:25:49
(7 months ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-27 19:09:50
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 149.56.150.118 (crawl-149-56-150-118.dataprovid ...
show more
(mod_security) mod_security (id:210730) triggered by 149.56.150.118 (crawl-149-56-150-118.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 14:09:45.832939 2025] [security2:error] [pid 13462:tid 13462] [client 149.56.150.118:58269] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ilikeabe.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ilikeabe.com"] [uri "/michleencollins.com"] [unique_id "aVAu-btanboIr8AmkT45EQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-15 03:15:00
(11 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.150.118 (crawl-149-56-150-118.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.150.118 (crawl-149-56-150-118.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 14 23:14:53.926585 2025] [security2:error] [pid 18169:tid 18169] [client 149.56.150.118:53423] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6649"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.wisconsinstatehuntingexpo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.wisconsinstatehuntingexpo.com"] [uri "/contact.html"] [unique_id "aMeErWfHUCfnCevM0kMU0wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack