Anonymous
2026-06-15 10:18:36
(1 day ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ช๐ธ
librebit
2026-06-04 06:26:36
(1 week ago)
Brute force
Brute-Force
๐ช๐ธ
librebit
2026-04-29 00:56:35
(1 month ago)
Brute force
Brute-Force
Anonymous
2026-04-02 06:41:48
(2 months ago)
(apache-useragents) Failed apache-useragents trigger with match [Mozilla/5.0 (compatible; Dataprovid ...
show more
(apache-useragents) Failed apache-useragents trigger with match [Mozilla/5.0 (compatible; Dataprovider.com)] from 149.56.160.153 (NL/The Netherlands/crawl-149-56-160-153.dataproviderbot.com): 5 in the last 300 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 149.56.160.153 - - [02/Apr/2026:08:41:26 +0200] "GET / HTTP/1.1" 301 519 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.160.153 - - [02/Apr/2026:08:41:27 +0200] "GET / HTTP/1.1" 301 3439 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.160.153 - - [02/Apr/2026:08:41:32 +0200] "GET / HTTP/1.1" 200 275323 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.160.153 - - [02/Apr/2026:08:41:37 +0200] "GET /robots.txt HTTP/1.1" 200 929 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.160.153 - - [02/Apr/2026:08:41:39 +0200] "GET / HTTP/1.1" 200 272791 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-03-31 00:05:43
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 149.56.160.153 (crawl-149-56-160-153.dataprovid ...
show more
(mod_security) mod_security (id:210730) triggered by 149.56.160.153 (crawl-149-56-160-153.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 20:05:38.423439 2026] [security2:error] [pid 17879:tid 17879] [client 149.56.160.153:52909] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.techspertnet.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.techspertnet.com"] [uri "/[email protected] "] [unique_id "acsP0ntoswYBzrID3Uhv9wAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lavnet.net
2026-01-26 06:58:44
(4 months ago)
[Mon Jan 26 06:58:42.424406 2026] [authz_core:error] [pid 3136689:tid 3136723] [client 149.56.160.15 ...
show more
[Mon Jan 26 06:58:42.424406 2026] [authz_core:error] [pid 3136689:tid 3136723] [client 149.56.160.153:56899] AH01630: client denied by server configuration: /var/www/thejunkymonkey.com/web/index.php
[Mon Jan 26 06:58:42.424618 2026] [authz_core:error] [pid 3136689:tid 3136723] [client 149.56.160.153:56899] AH01630: client denied by server configuration: /var/www/thejunkymonkey.com/web/index.php
[Mon Jan 26 06:58:43.408936 2026] [authz_core:error] [pid 3136691:tid 3136802] [client 149.56.160.153:58335] AH01630: client denied by server configuration: /var/www/thejunkymonkey.com/web/index.php
...
show less
Brute-Force
๐ต๐ฑ
IROK
2026-01-25 12:39:05
(4 months ago)
Firewall Blocked - Unauthorized Port Scanning
...
Port Scan
Anonymous
2025-11-01 02:07:00
(7 months ago)
Unauthorized connection attempt
Brute-Force
๐ฉ๐ช
Packets-Decreaser.NET
2025-10-31 05:08:59
(7 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-10-21 23:35:16
(7 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.160.153 (crawl-149-56-160-153.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.160.153 (crawl-149-56-160-153.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 21 19:35:09.135213 2025] [security2:error] [pid 12329:tid 12329] [client 149.56.160.153:53085] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.fitzcosound.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.fitzcosound.com"] [uri "/lrates.html"] [unique_id "aPgYrbMn821sU8sBqD4lqgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2025-10-18 01:14:01
(7 months ago)
Bad bot identified by user agent
Bad Web Bot
Anonymous
2025-10-06 22:25:20
(8 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฉ๐ช
Carsten
2025-09-28 06:21:02
(8 months ago)
bad web bot
Bad Web Bot
Anonymous
2025-09-14 07:44:10
(9 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-09-13 23:48:21
(9 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.160.153 (crawl-149-56-160-153.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.160.153 (crawl-149-56-160-153.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 13 19:48:15.422282 2025] [security2:error] [pid 3187608:tid 3187660] [client 149.56.160.153:53509] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.sportsoutreachnc.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.sportsoutreachnc.org"] [uri "/contact.html"] [unique_id "aMYCv26l7Au7g-A3_6PtFQAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack