🇨🇭
blinx
2026-09-04 12:38:31
(15 hours ago)
Suspicious activity detected by Modsecurity
Web Spam
Port Scan
Hacking
Bad Web Bot
Web App Attack
🇺🇸
jcbriar
2026-08-29 13:28:12
(6 days ago)
Searching for vulnerable scripts
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-15 16:25:55
(2 weeks ago)
(mod_security) mod_security (id:243420) triggered by 144.217.135.182 (crawl-144-217-135-182.dataprov ...
show more
(mod_security) mod_security (id:243420) triggered by 144.217.135.182 (crawl-144-217-135-182.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 12:25:47.632702 2026] [security2:error] [pid 18794:tid 18794] [client 144.217.135.182:57127] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.30daysout.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.30daysout.com"] [uri "/links/index.html"] [unique_id "aoCTC8H_ybEd87c2WZItTAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-02 14:34:17
(1 month ago)
(mod_security) mod_security (id:243420) triggered by 144.217.135.182 (crawl-144-217-135-182.dataprov ...
show more
(mod_security) mod_security (id:243420) triggered by 144.217.135.182 (crawl-144-217-135-182.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 02 10:34:09.060035 2026] [security2:error] [pid 3308239:tid 3308239] [client 144.217.135.182:59673] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.jessehaupert.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.jessehaupert.com"] [uri "/"] [unique_id "am9VYXaCC5RgPs4UMpKyTAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-07-30 01:32:07
(1 month ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: www.astropot.space | URI: /wp-admin/ | UA: Mozilla/5.0 (compatible; Dataprovider.com) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇪🇸
librebit
2026-07-22 04:33:05
(1 month ago)
Brute force
Brute-Force
🇩🇪
filstal.org
2026-06-16 21:19:49
(2 months ago)
Unauthorized web crawling by known aggressive crawler or data harvesting bot detected by Fail2Ban
Bad Web Bot
🇩🇪
Skyrider
2026-06-15 01:42:58
(2 months ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
🇩🇪
filstal.org
2026-06-06 01:10:09
(2 months ago)
Unauthorized web crawling by known aggressive crawler or data harvesting bot detected by Fail2Ban
Bad Web Bot
🇩🇪
Viveronese
2026-04-24 08:29:39
(4 months ago)
HTTP vulnerability scanning
Web App Attack
🇸🇬
mypatricks
2026-04-03 05:33:44
(5 months ago)
144.217.135.182 | Port: 12953 | DNS: crawl-144-217-135-182.dataproviderbot.com 2026-04-03T13:33:43+0 ...
show more
144.217.135.182 | Port: 12953 | DNS: crawl-144-217-135-182.dataproviderbot.com 2026-04-03T13:33:43+08:00 America/Toronto | Bad Behavior Activity | UA: Mozilla/5.0 (compatible; Dataprovider.com) HTTP/1.1 443 GET | URL: / | Ref: - | Country: CA/Canada/-06:00 IP City: Beauharnois 9e65b3318f26ab6a-YYZ/Toronto, ON, Canada 1 hits/0 secs Robots 0
show less
Brute-Force
Web App Attack
Blog Spam
Web Spam
Exploited Host
🇫🇷
giulio gorobey
2026-03-20 06:14:40
(5 months ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /.well-known/security.txt
Web App Attack
🇳🇱
ParaBug
2025-11-24 20:18:13
(9 months ago)
144.217.135.182 - - [24/Nov/2025:21:18:13 +0100] "OPTIONS / HTTP/1.1" 200 3852 "-" "Mozilla/5.0 (com ...
show more
144.217.135.182 - - [24/Nov/2025:21:18:13 +0100] "OPTIONS / HTTP/1.1" 200 3852 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
...
show less
Phishing
Brute-Force
Web App Attack
🇵🇱
sefinek.net
2025-11-21 21:23:55
(9 months ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Linux; Android 10; SM-G981B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.162 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇨🇳
ThreatBook.io
2025-11-20 22:52:49
(9 months ago)
ThreatBook Intelligence: Zombie more details on http://threatbook.io/ip/144.217.135.182
2025-11-20 0 ...
show more
ThreatBook Intelligence: Zombie more details on http://threatbook.io/ip/144.217.135.182
2025-11-20 02:33:14 /sitemap.xml
2025-11-20 02:33:16 /docs/windows-service-howto.html
2025-11-20 02:33:16 /docs/web-socket-howto.html
2025-11-20 02:33:18 /docs/config/
2025-11-20 02:33:15 /docs/
2025-11-20 02:33:17 /docs/config/service.html
2025-11-20 02:33:15 /docs/proxy-howto.html
2025-11-20 02:33:18 /examples
2025-11-20 02:33:13 /
2025-11-20 02:33:14 /robots.txt
show less
Web App Attack