Anonymous
2026-08-29 08:06:58
(1 day ago)
Scanner hitting /robots.txt on picsou.cloud (OVH-CUST-2528059) — aaguard
Brute-Force
Port Scan
🇹🇷
neron
2026-08-15 23:06:48
(2 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
🇫🇮
YF
2026-08-05 10:30:34
(3 weeks ago)
Distributed subnet attack — coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
🇹🇷
neron
2026-08-01 03:06:26
(4 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
🇵🇱
Budyn
2026-07-29 12:40:00
(1 month ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: URI: /wp-admin/ | UA: Mozilla/5.0 (compatible; Dataprovider.com) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-19 22:34:05
(1 month ago)
(mod_security) mod_security (id:243420) triggered by 149.56.150.33 (crawl-149-56-150-33.dataprovider ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.150.33 (crawl-149-56-150-33.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 18:34:02.312792 2026] [security2:error] [pid 14941:tid 14941] [client 149.56.150.33:60481] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.lubbockknights.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.lubbockknights.com"] [uri "/registrationform.php"] [unique_id "al1Q2jCcovMmjYk13ED-sAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-03 06:28:22
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 149.56.150.33 (crawl-149-56-150-33.dataprovider ...
show more
(mod_security) mod_security (id:210730) triggered by 149.56.150.33 (crawl-149-56-150-33.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 02:28:16.624856 2026] [security2:error] [pid 14065:tid 14065] [client 149.56.150.33:59507] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||glassclublake.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "glassclublake.com"] [uri "/[email protected] "] [unique_id "akdWgCuyijK2VKFWPIoSGgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Viveronese
2026-06-22 11:19:23
(2 months ago)
HTTP vulnerability scanning
Web App Attack
🇺🇸
TPI-Abuse
2026-04-21 03:10:12
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 149.56.150.33 (crawl-149-56-150-33.dataprovider ...
show more
(mod_security) mod_security (id:210730) triggered by 149.56.150.33 (crawl-149-56-150-33.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 20 23:10:05.122347 2026] [security2:error] [pid 3793133:tid 3793133] [client 149.56.150.33:47849] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.chicagowca.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.chicagowca.com"] [uri "/[email protected] "] [unique_id "aebqjbOlPbBSpTal5qHmagAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
conrad10781
2026-04-17 06:50:01
(4 months ago)
nginx-4xx
Web App Attack
🇺🇸
RCS
2025-12-12 14:57:03
(8 months ago)
fail2ban apache-badbots
...
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-21 13:44:42
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 149.56.150.33 (crawl-149-56-150-33.dataprovider ...
show more
(mod_security) mod_security (id:210730) triggered by 149.56.150.33 (crawl-149-56-150-33.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 21 08:44:39.170999 2025] [security2:error] [pid 25306:tid 25306] [client 149.56.150.33:50805] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.raintechgutters.com|F|2"] [data ".raintechgutters.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.raintechgutters.com"] [uri "/local-gutter-services-orlando/www.raintechgutters.com"] [unique_id "aSBsx1nHb2g2aWUEvoc41AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
cyfordtechnologies.com
2025-08-26 08:37:39
(1 year ago)
Rate limit exceeded : Reported by Cyford API
DDoS Attack
🇨🇭
backslash
2025-08-10 05:43:26
(1 year ago)
Bad Web Bot
🇬🇧
Mendip_Defender
2025-08-03 17:49:52
(1 year ago)
149.56.150.33 - - [03/Aug/2025:18:49:36 +0100] "GET /security.txt HTTP/1.0" 404 82349 "-" "Mozilla/5 ...
show more
149.56.150.33 - - [03/Aug/2025:18:49:36 +0100] "GET /security.txt HTTP/1.0" 404 82349 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.33 - - [03/Aug/2025:18:49:36 +0100] "GET /.well-known/security.txt HTTP/1.0" 404 82340 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.33 - - [03/Aug/2025:18:49:37 +0100] "GET /ads.txt HTTP/1.0" 404 82322 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
...
show less
Hacking
Web App Attack