๐ช๐ธ
librebit
2026-08-18 07:28:18
(1 week ago)
Brute force
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-16 22:07:31
(1 week ago)
(mod_security) mod_security (id:243420) triggered by 149.56.160.129 (crawl-149-56-160-129.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.160.129 (crawl-149-56-160-129.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 18:07:25.288216 2026] [security2:error] [pid 30093:tid 30093] [client 149.56.160.129:45219] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6649"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.kellymalone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.kellymalone.com"] [uri "/kellymalone%20demo/contact_kelly.htm"] [unique_id "aoI0nUlwEVptbj7mzqwjNgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
neron
2026-08-15 23:06:48
(1 week ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-10 21:35:48
(2 weeks ago)
(mod_security) mod_security (id:243420) triggered by 149.56.160.129 (crawl-149-56-160-129.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.160.129 (crawl-149-56-160-129.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 17:35:42.649064 2026] [security2:error] [pid 386931:tid 386931] [client 149.56.160.129:58173] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.hollistercomputer.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.hollistercomputer.com"] [uri "/music.htm"] [unique_id "anpELr2SiPHPLSfD7sKUNAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-16 09:04:11
(1 month ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐ฉ๐ช
Carsten
2026-07-04 18:56:22
(1 month ago)
Bad web bot [Mozilla/5.0 (compatible; Dataprovider.com)]
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-12 23:27:59
(2 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.160.129 (crawl-149-56-160-129.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.160.129 (crawl-149-56-160-129.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 19:27:55.778755 2026] [security2:error] [pid 1946:tid 1946] [client 149.56.160.129:58965] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.eaglesnestfuelfarm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.eaglesnestfuelfarm.com"] [uri "/contact/contact.php"] [unique_id "aiyV-_3pb6cjqkGfBtpMJgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dklueh79
2026-06-10 13:21:36
(2 months ago)
Probe for vulnerabilities. Path attempted: /security
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-14 07:22:57
(3 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.160.129 (crawl-149-56-160-129.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.160.129 (crawl-149-56-160-129.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 03:22:53.187812 2026] [security2:error] [pid 28644:tid 28663] [client 149.56.160.129:33365] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.sportsoutreachnc.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.sportsoutreachnc.org"] [uri "/contact.html"] [unique_id "agV4TcUL3EXNyj2AKXdF7QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-03-27 15:21:39
(4 months ago)
(apache-useragents) Failed apache-useragents trigger with match [Mozilla/5.0 (compatible; Dataprovid ...
show more
(apache-useragents) Failed apache-useragents trigger with match [Mozilla/5.0 (compatible; Dataprovider.com)] from 149.56.160.129 (NL/The Netherlands/crawl-149-56-160-129.dataproviderbot.com): 5 in the last 300 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 149.56.160.129 - - [27/Mar/2026:16:21:30 +0100] "GET / HTTP/1.1" 301 525 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.160.129 - - [27/Mar/2026:16:21:31 +0100] "GET / HTTP/1.1" 200 120231 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.160.129 - - [27/Mar/2026:16:21:33 +0100] "GET /robots.txt HTTP/1.1" 200 929 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.160.129 - - [27/Mar/2026:16:21:34 +0100] "GET / HTTP/1.1" 200 117691 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.160.129 - - [27/Mar/2026:16:21:36 +0100] "GET /sitemap.xml HTTP/1.1" 302 917 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
show less
Port Scan
๐ฉ๐ช
Viveronese
2026-03-26 23:06:25
(4 months ago)
HTTP vulnerability scanning
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-06 17:13:04
(6 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.160.129 (crawl-149-56-160-129.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.160.129 (crawl-149-56-160-129.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 12:12:57.829516 2026] [security2:error] [pid 847485:tid 847485] [client 149.56.160.129:37143] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.rogerloft.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.rogerloft.com"] [uri "/index.html"] [unique_id "aYYhGXUJYmVD5crga7krsQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-30 20:33:10
(7 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.160.129 (crawl-149-56-160-129.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.160.129 (crawl-149-56-160-129.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 30 15:32:52.299071 2025] [security2:error] [pid 2716:tid 2716] [client 149.56.160.129:45767] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.cortona.ws|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.cortona.ws"] [uri "/privacy_utilizzo_cookie_it.html"] [unique_id "aVQ29GbixtQmn0iqU44_AgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2025-12-30 01:10:01
(7 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-12-13 08:30:38
(8 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.160.129 (crawl-149-56-160-129.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.160.129 (crawl-149-56-160-129.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 13 03:30:33.326864 2025] [security2:error] [pid 28146:tid 28146] [client 149.56.160.129:48497] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.stewhist.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.stewhist.org"] [uri "/index.html"] [unique_id "aT0kKfdaRlei1B9dCKhKFAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack