๐ฉ๐ช
LRob
2026-10-02 18:39:11
(3 days ago)
Abusive crawler | ua: Mozilla/5.0 (compatible; Dataprovider.com) | path: /
Bad Web Bot
๐ฆ๐บ
nzhost.co.nz
2026-09-27 07:53:39
(1 week ago)
$f2bV_matches
Hacking
Brute-Force
๐ช๐ธ
librebit
2026-08-21 12:52:10
(1 month ago)
Brute force
Brute-Force
๐น๐ท
neron
2026-08-15 23:06:48
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-08-10 00:29:22
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-07-31 03:06:18
(2 months ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 06:41:08
(3 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.160.236 (crawl-149-56-160-236.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.160.236 (crawl-149-56-160-236.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 02:41:00.985879 2026] [security2:error] [pid 20514:tid 20514] [client 149.56.160.236:50583] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.radionicships.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.radionicships.com"] [uri "/review.shtml"] [unique_id "aie1fNRghTEHwXpaCq-UCwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 21:14:38
(4 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.160.236 (crawl-149-56-160-236.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.160.236 (crawl-149-56-160-236.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 17:14:34.905007 2026] [security2:error] [pid 14722:tid 14722] [client 149.56.160.236:50217] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.homecheckinmaine.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.homecheckinmaine.com"] [uri "/contact.php"] [unique_id "ahdeusDjXMY7HUL9Jn0HIwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-01 09:38:06
(5 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.160.236 (crawl-149-56-160-236.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.160.236 (crawl-149-56-160-236.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 05:38:01.926766 2026] [security2:error] [pid 5873:tid 5873] [client 149.56.160.236:48603] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.dollybambi.click|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dollybambi.click"] [uri "/makeup/"] [unique_id "afR0eY4ovAKXhb0hWJR66AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 13:01:22
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 149.56.160.236 (crawl-149-56-160-236.dataprovid ...
show more
(mod_security) mod_security (id:210730) triggered by 149.56.160.236 (crawl-149-56-160-236.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 08:01:15.071263 2026] [security2:error] [pid 2646784:tid 2646784] [client 149.56.160.236:51365] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||climasyequipos.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "climasyequipos.com"] [uri "/[email protected] "] [unique_id "aY8gm4mNjwKySUJ3krvTLwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
debaba
2026-01-28 21:26:24
(8 months ago)
[28/Jan/2026:21:26:07.162144 +0000] aXp-7sfn7odRArWIhEeFkQAAAEU 149.56.160.
...
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-15 07:24:47
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 149.56.160.236 (crawl-149-56-160-236.dataprovid ...
show more
(mod_security) mod_security (id:210730) triggered by 149.56.160.236 (crawl-149-56-160-236.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 15 02:24:43.141560 2026] [security2:error] [pid 11227:tid 11227] [client 149.56.160.236:42201] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.qualityelevatorcabs.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.qualityelevatorcabs.com"] [uri "/[email protected] "] [unique_id "aWiWOxGpMQxQaDiEq0snkwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-01-14 21:41:47
(8 months ago)
149.56.160.236 - - [14/Jan/2026:21:41:44 +0000] "GET /sitemap.xml HTTP/1.0" 404 4370 "-" "Mozilla/5. ...
show more
149.56.160.236 - - [14/Jan/2026:21:41:44 +0000] "GET /sitemap.xml HTTP/1.0" 404 4370 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.160.236 - - [14/Jan/2026:21:41:45 +0000] "GET /ads.txt HTTP/1.0" 404 4370 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.160.236 - - [14/Jan/2026:21:41:46 +0000] "GET /llms.txt HTTP/1.0" 404 4370 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.160.236 - - [14/Jan/2026:21:41:46 +0000] "GET /humans.txt HTTP/1.0" 404 4370 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
...
show less
Web App Attack
๐จ๐ญ
backslash
2026-01-02 13:50:11
(9 months ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
๐ฒ๐พ
syokadmin
2025-12-03 18:02:29
(10 months ago)
149.56.160.236 (NL/The Netherlands/crawl-149-56-160-236.dataproviderbot.com), more than 2 Apache 403 ...
show more
149.56.160.236 (NL/The Netherlands/crawl-149-56-160-236.dataproviderbot.com), more than 2 Apache 403 hits in the last 3600 secs
show less
Brute-Force