๐ฆ๐บ
nzhost.co.nz
2026-08-27 15:16:05
(7 hours ago)
$f2bV_matches
Hacking
Brute-Force
Anonymous
2026-08-25 19:18:48
(2 days ago)
(apache-useragents) Failed apache-useragents trigger with match [Mozilla/5.0 (compatible; Dataprovid ...
show more
(apache-useragents) Failed apache-useragents trigger with match [Mozilla/5.0 (compatible; Dataprovider.com)] from 149.56.150.129 (NL/The Netherlands/crawl-149-56-150-129.dataproviderbot.com): 5 in the last 300 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 149.56.150.129 - - [25/Aug/2026:21:18:37 +0200] "GET / HTTP/1.1" 301 525 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.129 - - [25/Aug/2026:21:18:38 +0200] "GET / HTTP/2.0" 200 115651 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.129 - - [25/Aug/2026:21:18:40 +0200] "GET /robots.txt HTTP/2.0" 200 129 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.129 - - [25/Aug/2026:21:18:40 +0200] "GET /sitemap.xml HTTP/2.0" 302 75 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.129 - - [25/Aug/2026:21:18:42 +0200] "GET /wp-sitemap.xml HTTP/2.0" 200 727 "https://www.1883-routin.nl/sitemap.xml" "Mozilla/5.0 (compatible; Dataprovider.com)"
show less
Port Scan
๐น๐ท
neron
2026-08-15 23:06:48
(1 week ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-08-10 04:29:22
(2 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ต๐ฑ
Budyn
2026-08-01 11:24:01
(3 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: www.budyn.ovh | URI: /wp-admin/ | UA: Mozilla/5.0 (compatible; Dataprovider.com) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐น๐ท
neron
2026-07-29 16:19:38
(4 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ฆ๐บ
nzhost.co.nz
2026-07-25 04:17:37
(1 month ago)
$f2bV_matches
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-15 21:01:37
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 149.56.150.129 (crawl-149-56-150-129.dataprovid ...
show more
(mod_security) mod_security (id:210492) triggered by 149.56.150.129 (crawl-149-56-150-129.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 17:01:29.485295 2026] [security2:error] [pid 1737583:tid 1737583] [client 149.56.150.129:51823] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.needtoorder.us"] [uri "/USE-To-BLOCKwww.countryipblocks.net.htaccess"] [unique_id "alf1KdwAB79xeCxr0pa_tQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 02:13:16
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 149.56.150.129 (crawl-149-56-150-129.dataprovid ...
show more
(mod_security) mod_security (id:210730) triggered by 149.56.150.129 (crawl-149-56-150-129.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 22:13:10.757961 2026] [security2:error] [pid 20381:tid 20381] [client 149.56.150.129:35139] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.lionheartpublications.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.lionheartpublications.com"] [uri "/[email protected] "] [unique_id "ajyOtpZtZZ81ejTv01bgSgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
filstal.org
2026-06-21 18:05:12
(2 months ago)
Unauthorized web crawling by known aggressive crawler or data harvesting bot detected by Fail2Ban
Bad Web Bot
๐ช๐ธ
librebit
2026-06-18 05:58:34
(2 months ago)
Brute force
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-19 01:10:40
(3 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.150.129 (crawl-149-56-150-129.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.150.129 (crawl-149-56-150-129.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 21:10:35.458115 2026] [security2:error] [pid 22117:tid 22117] [client 149.56.150.129:47603] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.stenbot.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.stenbot.com"] [uri "/index.html"] [unique_id "agu4i1JbTBAghU3_YqHalwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-05-17 04:31:53
(3 months ago)
149.56.150.129 - - [17/May/2026:06:31:41 +0200] "GET /robots.txt HTTP/2.0" 404 162 "-" "Mozilla/5.0 ...
show more
149.56.150.129 - - [17/May/2026:06:31:41 +0200] "GET /robots.txt HTTP/2.0" 404 162 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.129 - - [17/May/2026:06:31:41 +0200] "GET /sitemap.xml HTTP/2.0" 404 162 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.129 - - [17/May/2026:06:31:51 +0200] "GET /ads.txt HTTP/2.0" 404 162 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.129 - - [17/May/2026:06:31:52 +0200] "GET /security.txt HTTP/2.0" 404 162 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.129 - - [17/May/2026:06:31:52 +0200] "GET /.well-known/security.txt HTTP/2.0" 404 162 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-05-09 23:16:51
(3 months ago)
WordPress directory enumeration
Web App Attack
๐ช๐ธ
librebit
2026-04-04 04:27:08
(4 months ago)
Brute force
Brute-Force