🇸🇪
SkyDancer
2026-09-11 18:57:24
(23 hours ago)
Multiple login attempts via RDP and/or SSH using wrong credentials. Attack automatically blocked by ...
show more
Multiple login attempts via RDP and/or SSH using wrong credentials. Attack automatically blocked by SkyDancer Ai via interface.
show less
Hacking
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-07-23 17:29:45
(1 month ago)
(mod_security) mod_security (id:243420) triggered by 144.217.135.223 (crawl-144-217-135-223.dataprov ...
show more
(mod_security) mod_security (id:243420) triggered by 144.217.135.223 (crawl-144-217-135-223.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 13:29:40.575971 2026] [security2:error] [pid 2478774:tid 2478871] [client 144.217.135.223:43887] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.castaspell.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.castaspell.com"] [uri "/contact.html"] [unique_id "amJPhKxB1X64am_GYo4D5AAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇺
OK
2026-07-22 15:10:14
(1 month ago)
HTTP/HTTPS
Hacking
Web App Attack
🇩🇪
HERA - Operations
2026-07-05 15:37:25
(2 months ago)
scelly - searching for vulnerable scripts: security.txt 2026/07/05 15:37:24
Web App Attack
🇺🇸
TPI-Abuse
2026-05-20 20:35:31
(3 months ago)
(mod_security) mod_security (id:243420) triggered by 144.217.135.223 (crawl-144-217-135-223.dataprov ...
show more
(mod_security) mod_security (id:243420) triggered by 144.217.135.223 (crawl-144-217-135-223.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 16:35:24.303521 2026] [security2:error] [pid 4625:tid 4625] [client 144.217.135.223:46279] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.makeupandwardrobe.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.makeupandwardrobe.com"] [uri "/index.htm"] [unique_id "ag4bDENm07BTgBkBRmK2PQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-05-01 19:12:09
(4 months ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
🇸🇬
mypatricks
2026-05-01 03:02:23
(4 months ago)
144.217.135.223 | Port: 10652 | DNS: crawl-144-217-135-223.dataproviderbot.com 2026-05-01T11:02:22+0 ...
show more
144.217.135.223 | Port: 10652 | DNS: crawl-144-217-135-223.dataproviderbot.com 2026-05-01T11:02:22+08:00 America/Toronto | FETCH Sproofing Activity Detetced. | UA: Mozilla/5.0 (compatible; Dataprovider.com) HTTP/1.1 443 GET | URL: / | Ref: - | Country: CA/Canada/-06:00 IP City: Beauharnois 9f4b8bffbbae378a-YYZ/Toronto, ON, Canada 1 hits/0 secs Robots 0
show less
Brute-Force
Web App Attack
Blog Spam
Web Spam
Exploited Host
🇬🇧
Mendip_Defender
2026-04-05 06:09:54
(5 months ago)
144.217.135.223 - - [05/Apr/2026:07:09:50 +0100] "GET /ads.txt HTTP/1.0" 404 5017 "-" "Mozilla/5.0 ( ...
show more
144.217.135.223 - - [05/Apr/2026:07:09:50 +0100] "GET /ads.txt HTTP/1.0" 404 5017 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
144.217.135.223 - - [05/Apr/2026:07:09:50 +0100] "GET /security.txt HTTP/1.0" 404 5017 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
144.217.135.223 - - [05/Apr/2026:07:09:50 +0100] "GET /.well-known/security.txt HTTP/1.0" 404 5017 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
...
show less
Hacking
Web App Attack
🇰🇷
MW
2026-04-04 03:22:52
(5 months ago)
144.217.135.223 - - [04/Apr/2026:12:22:46 +0900] "GET /robots.txt HTTP/1.1" 404 514 "-" "Mozilla/5.0 ...
show more
144.217.135.223 - - [04/Apr/2026:12:22:46 +0900] "GET /robots.txt HTTP/1.1" 404 514 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
144.217.135.223 - - [04/Apr/2026:12:22:49 +0900] "GET /sitemap.xml HTTP/1.1" 404 1047 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
144.217.135.223 - - [04/Apr/2026:12:22:50 +0900] "GET /ads.txt HTTP/1.1" 404 514 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
show less
Bad Web Bot
Web App Attack
Anonymous
2026-03-28 16:02:21
(5 months ago)
144.217.135.223 - - [28/Mar/2026:17:02:21 +0100] "GET / HTTP/1.1" 301 169 "-" "Mozilla/5.0 (compatib ...
show more
144.217.135.223 - - [28/Mar/2026:17:02:21 +0100] "GET / HTTP/1.1" 301 169 "-" "Mozilla/5.0 (compatible; )"
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-03-14 15:19:17
(5 months ago)
(mod_security) mod_security (id:243420) triggered by 144.217.135.223 (crawl-144-217-135-223.dataprov ...
show more
(mod_security) mod_security (id:243420) triggered by 144.217.135.223 (crawl-144-217-135-223.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 11:19:12.937190 2026] [security2:error] [pid 7291:tid 7291] [client 144.217.135.223:39829] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.fatlandtheplay.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.fatlandtheplay.com"] [uri "/guestbook.htm"] [unique_id "abV8cFLEbp0qzc5TaaHjfwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-20 18:07:17
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 144.217.135.223 (crawl-144-217-135-223.dataprov ...
show more
(mod_security) mod_security (id:210730) triggered by 144.217.135.223 (crawl-144-217-135-223.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 13:07:10.400192 2026] [security2:error] [pid 21432:tid 21965] [client 144.217.135.223:51385] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.barstowstationtoo.com|F|2"] [data ".barstow-station.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.barstowstationtoo.com"] [uri "/www.barstow-station.com"] [unique_id "aZiizt9h-jn2g1LANJALRgAAAo0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Hazael
2026-01-02 22:33:01
(8 months ago)
SNOOPING - intended to probe for or exploit website vulnerabilities. From: Beauharnois, Canada - OVH ...
show more
SNOOPING - intended to probe for or exploit website vulnerabilities. From: Beauharnois, Canada - OVH Hosting (AS16276 OVH SAS) - Agent: Mozilla/5.0 (compatible; Dataprovider.com)
show less
Web App Attack
🇮🇹
Progetto1
2025-12-15 02:25:01
(8 months ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
🇺🇸
rsa
2025-11-26 00:49:00
(9 months ago)
scanning vuln
Web App Attack