๐ต๐ฑ
Budyn
2026-09-27 20:46:13
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: shop.teddypot.website | URI: /backup.sql | UA: Mozilla/5.0 (compatible; Dataprovider.com) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
HamSammich
2026-07-24 11:15:38
(2 months ago)
Automated sensor: 4 HTTP, HTTPS connection/probe attempts over the last 24h (latest 2026-07-24T11:15 ...
show more
Automated sensor: 4 HTTP, HTTPS connection/probe attempts over the last 24h (latest 2026-07-24T11:15Z).
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 20:05:23
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 144.217.135.166 (crawl-144-217-135-166.dataprov ...
show more
(mod_security) mod_security (id:210730) triggered by 144.217.135.166 (crawl-144-217-135-166.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 16:05:18.500937 2026] [security2:error] [pid 10451:tid 10463] [client 144.217.135.166:42653] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.barstowstationtoo.com|F|2"] [data ".barstow-station.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.barstowstationtoo.com"] [uri "/www.barstow-station.com"] [unique_id "al_Q_tJbTiZsOi-8WZ8_2QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
filstal.org
2026-06-23 01:25:55
(3 months ago)
Unauthorized web crawling by known aggressive crawler or data harvesting bot detected by Fail2Ban
Bad Web Bot
๐บ๐ธ
LSPCCU
2026-05-07 00:39:07
(4 months ago)
TSEC Honeypot Network report. Threat score: 90/100. Categories: Hacking. Honeypot: ssh-telnet, cowri ...
show more
TSEC Honeypot Network report. Threat score: 90/100. Categories: Hacking. Honeypot: ssh-telnet, cowrie. Context: Attacker IP 144.
show less
Hacking
๐ฆ๐บ
mjmouse
2026-04-04 16:44:04
(5 months ago)
Visited honeypot banned in robots.txt
144.217.135.166 darbybible.app - [04/Apr/2026:16:44:04 +0000] ...
show more
Visited honeypot banned in robots.txt
144.217.135.166 darbybible.app - [04/Apr/2026:16:44:04 +0000] "GET /[honeypot]/?from=/Job/ HTTP/1.0" 403 158 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
show less
Bad Web Bot
๐ฉ๐ช
Carsten
2026-02-28 09:30:43
(7 months ago)
Bad web bot [Mozilla/5.0 (compatible; Dataprovider.com)]
Bad Web Bot
Anonymous
2025-11-04 13:24:34
(10 months ago)
Malicious activity detected
Hacking
Web App Attack
๐จ๐ญ
backslash
2025-11-01 20:20:17
(10 months ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
๐ฌ๐ง
Mendip_Defender
2025-10-26 00:35:25
(11 months ago)
144.217.135.166 - - [26/Oct/2025:01:35:18 +0100] "GET /robots.txt HTTP/1.0" 404 5009 "-" "Mozilla/5. ...
show more
144.217.135.166 - - [26/Oct/2025:01:35:18 +0100] "GET /robots.txt HTTP/1.0" 404 5009 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
144.217.135.166 - - [26/Oct/2025:01:35:19 +0100] "GET /llms.txt HTTP/1.0" 404 5009 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
144.217.135.166 - - [26/Oct/2025:01:35:19 +0100] "GET /humans.txt HTTP/1.0" 404 5009 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
...
show less
Hacking
Web App Attack
Anonymous
2025-10-22 01:38:10
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-10-16 21:18:00
(11 months ago)
Unauthorized connection attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-09-16 23:45:33
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 144.217.135.166 (crawl-144-217-135-166.dataprov ...
show more
(mod_security) mod_security (id:210730) triggered by 144.217.135.166 (crawl-144-217-135-166.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 16 19:45:29.354298 2025] [security2:error] [pid 8711:tid 8711] [client 144.217.135.166:47471] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.becclesrestaurants.com|F|2"] [data ".html.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.becclesrestaurants.com"] [uri "/index.html.old"] [unique_id "aMn2mcQs8Om-5wT6mgHJuAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-11 02:03:37
(1 year ago)
(mod_security) mod_security (id:243420) triggered by 144.217.135.166 (crawl-144-217-135-166.dataprov ...
show more
(mod_security) mod_security (id:243420) triggered by 144.217.135.166 (crawl-144-217-135-166.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 10 22:03:29.640064 2025] [security2:error] [pid 11485:tid 11485] [client 144.217.135.166:58483] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.radionicships.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.radionicships.com"] [uri "/review.shtml"] [unique_id "aJlPccfrHdI5a1aUL8uGQAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-30 11:11:53
(1 year ago)
Excessive crawling/scraping
Hacking
Brute-Force