๐บ๐ธ
cwytech
2026-07-29 18:32:02
(12 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/tpot-web-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 04:04:27
(2 months ago)
(mod_security) mod_security (id:243420) triggered by 144.217.135.206 (crawl-144-217-135-206.dataprov ...
show more
(mod_security) mod_security (id:243420) triggered by 144.217.135.206 (crawl-144-217-135-206.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 00:04:21.858681 2026] [security2:error] [pid 14056:tid 14056] [client 144.217.135.206:35649] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.monteriggioni.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.monteriggioni.net"] [uri "/privacy_utilizzo_cookie_it.html"] [unique_id "agADxRRLNFlL3CWg57AVuwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
omc
2026-04-06 14:29:34
(3 months ago)
Exploit of unauthorized endpoint [QS]
Bad Web Bot
DDoS Attack
๐ณ๐ฑ
CryptoYakari
2026-03-25 08:31:27
(4 months ago)
144.217.135.206 - - [25/Mar/2026:11:31:18 +0300] "GET /sitemap.xml HTTP/1.0" 404 3185 "-" "Mozilla/5 ...
show more
144.217.135.206 - - [25/Mar/2026:11:31:18 +0300] "GET /sitemap.xml HTTP/1.0" 404 3185 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
144.217.135.206 - - [25/Mar/2026:11:31:25 +0300] "GET /security.txt HTTP/1.0" 404 3185 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
144.217.135.206 - - [25/Mar/2026:11:31:25 +0300] "GET /.well-known/security.txt HTTP/1.0" 404 3185 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
144.217.135.206 - - [25/Mar/2026:11:31:26 +0300] "GET /llms.txt HTTP/1.0" 404 3185 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
144.217.135.206 - - [25/Mar/2026:11:31:26 +0300] "GET /humans.txt HTTP/1.0" 404 3185 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
...
show less
Web Spam
Blog Spam
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-20 02:11:28
(4 months ago)
(mod_security) mod_security (id:243420) triggered by 144.217.135.206 (crawl-144-217-135-206.dataprov ...
show more
(mod_security) mod_security (id:243420) triggered by 144.217.135.206 (crawl-144-217-135-206.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:11:24.726648 2026] [security2:error] [pid 7610:tid 7610] [client 144.217.135.206:37883] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.pswebsite.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.pswebsite.com"] [uri "/pswebsite/ProjectStartUp2/privacypolicy.htm"] [unique_id "abyszKMrHoxR3Mn6ftJEVgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-13 20:27:14
(4 months ago)
(mod_security) mod_security (id:243420) triggered by 144.217.135.206 (crawl-144-217-135-206.dataprov ...
show more
(mod_security) mod_security (id:243420) triggered by 144.217.135.206 (crawl-144-217-135-206.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 16:27:08.000732 2026] [security2:error] [pid 6465:tid 6483] [client 144.217.135.206:33621] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.sportsoutreachnc.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.sportsoutreachnc.org"] [uri "/contact.html"] [unique_id "abRzGw4Vdp13p-rMygiZnQAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
conseilgouz
2026-03-02 10:35:55
(4 months ago)
sie-Security key failure(Dataprovider)
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-23 17:07:05
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 144.217.135.206 (crawl-144-217-135-206.dataprov ...
show more
(mod_security) mod_security (id:210730) triggered by 144.217.135.206 (crawl-144-217-135-206.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 12:07:02.517735 2026] [security2:error] [pid 30438:tid 30438] [client 144.217.135.206:38065] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ilikeabe.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ilikeabe.com"] [uri "/michleencollins.com"] [unique_id "aZyJNsR3Cj_wZLHwfOD6DwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
webadmin
2026-02-20 10:39:01
(5 months ago)
2026/02/20 11:38:50 [error] 3754887#3754887: *3114 open() "/var/www/saisolutions.pl/robots.txt" fail ...
show more
2026/02/20 11:38:50 [error] 3754887#3754887: *3114 open() "/var/www/saisolutions.pl/robots.txt" failed (2: No such file or directory), client: 144.217.135.206, server: saisolutions.pl, request: "GET /robots.txt HTTP/1.1", host: "www.saisolutions.pl"
2026/02/20 11:38:59 [error] 3754887#3754887: *3117 open() "/var/www/saisolutions.pl/security.txt" failed (2: No such file or directory), client: 144.217.135.206, server: saisolutions.pl, request: "GET /security.txt HTTP/1.1", host: "www.saisolutions.pl"
2026/02/20 11:39:00 [error] 3754887#3754887: *3121 open() "/var/www/saisolutions.pl/.well-known/security.txt" failed (2: No such file or directory), client: 144.217.135.206, server: saisolutions.pl, request: "GET /.well-known/security.txt HTTP/1.1", host: "www.saisolutions.pl"
2026/02/20 11:39:00 [error] 3754887#3754887: *3123 open() "/var/www/saisolutions.pl/llms.txt" failed (2: No such file or directory), client: 144.217.135.206, server: saisolutions.pl, request: "GET /llms.txt HTTP/1.1",
...
show less
Web App Attack
Anonymous
2026-01-11 05:20:48
(6 months ago)
(apache-useragents) Failed apache-useragents trigger with match [Mozilla/5.0 (compatible; Dataprovid ...
show more
(apache-useragents) Failed apache-useragents trigger with match [Mozilla/5.0 (compatible; Dataprovider.com)] from 144.217.135.206 (NL/The Netherlands/crawl-144-217-135-206.dataproviderbot.com): 5 in the last 300 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 144.217.135.206 - - [11/Jan/2026:06:20:23 +0100] "GET / HTTP/1.1" 301 350 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
144.217.135.206 - - [11/Jan/2026:06:20:26 +0100] "GET / HTTP/1.1" 200 413907 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
144.217.135.206 - - [11/Jan/2026:06:20:31 +0100] "GET /robots.txt HTTP/1.1" 200 929 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
144.217.135.206 - - [11/Jan/2026:06:20:36 +0100] "GET /sitemap.xml HTTP/1.1" 302 922 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
144.217.135.206 - - [11/Jan/2026:06:20:40 +0100] "GET /wp-sitemap.xml HTTP/1.1" 200 1941 "https://www.clasicococktails.nl/sitemap.xml" "Mozilla/5.0 (compatible; Dataprovider.com)"
show less
Port Scan
๐ฉ๐ฐ
SaltySoftworks
2026-01-06 05:50:17
(6 months ago)
User agent spoofing
Spoofing
๐บ๐ธ
TPI-Abuse
2025-11-22 14:57:08
(8 months ago)
(mod_security) mod_security (id:243420) triggered by 144.217.135.206 (crawl-144-217-135-206.dataprov ...
show more
(mod_security) mod_security (id:243420) triggered by 144.217.135.206 (crawl-144-217-135-206.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 22 09:57:04.429612 2025] [security2:error] [pid 22653:tid 22653] [client 144.217.135.206:51951] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.fitzcosound.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.fitzcosound.com"] [uri "/lrates.html"] [unique_id "aSHPQFeB-kZci7jIxgAZmAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-05 05:39:00
(9 months ago)
Unauthorized connection attempt
Brute-Force
๐จ๐ญ
backslash
2025-08-10 05:43:08
(11 months ago)
Bad Web Bot
๐บ๐ธ
COMPLEX
2025-07-11 16:25:39
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: MANAGED_CHALLENGE
ASN: 16276 (OVH)
...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: MANAGED_CHALLENGE
ASN: 16276 (OVH)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
show less
Bad Web Bot