🇹🇷
neron
2026-08-15 23:06:48
(2 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
🇬🇧
AvonleaConsulting
2026-08-03 15:38:04
(4 weeks ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
Anonymous
2026-07-16 16:32:26
(1 month ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
🇨🇭
myguns.ch
2026-03-30 06:12:15
(5 months ago)
Searching for vulnerable scripts: /.well-known/security.txt
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-03-08 16:08:20
(5 months ago)
(mod_security) mod_security (id:243420) triggered by 144.217.135.241 (crawl-144-217-135-241.dataprov ...
show more
(mod_security) mod_security (id:243420) triggered by 144.217.135.241 (crawl-144-217-135-241.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 08 12:08:12.827457 2026] [security2:error] [pid 24827:tid 24827] [client 144.217.135.241:56015] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.serviciodepinturadecasas.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.serviciodepinturadecasas.com"] [uri "/contacto"] [unique_id "aa2e7FMNH_Q09_TH0bwznQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-04 05:44:05
(6 months ago)
(mod_security) mod_security (id:243420) triggered by 144.217.135.241 (crawl-144-217-135-241.dataprov ...
show more
(mod_security) mod_security (id:243420) triggered by 144.217.135.241 (crawl-144-217-135-241.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 04 00:44:00.157696 2026] [security2:error] [pid 28438:tid 28438] [client 144.217.135.241:37939] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.godcontends.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.godcontends.com"] [uri "/contact"] [unique_id "aYLcoKCHDtSCQ1j_vATOAQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
conseilgouz
2026-02-02 10:06:45
(7 months ago)
sce-Security key failure(Dataprovider)
Hacking
🇺🇸
TPI-Abuse
2026-02-02 01:21:10
(7 months ago)
(mod_security) mod_security (id:243420) triggered by 144.217.135.241 (crawl-144-217-135-241.dataprov ...
show more
(mod_security) mod_security (id:243420) triggered by 144.217.135.241 (crawl-144-217-135-241.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 20:21:03.019013 2026] [security2:error] [pid 21288:tid 21288] [client 144.217.135.241:51793] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.jessehaupert.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.jessehaupert.com"] [uri "/"] [unique_id "aX_7_94vkcR9C1G5kogcJwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
VanKoh
2026-01-06 06:17:27
(7 months ago)
144.217.135.241 - - [06/Jan/2026:00:17:25 -0600] "GET / HTTP/1.1" 200 615 "-" "Mozilla/5.0 (compatib ...
show more
144.217.135.241 - - [06/Jan/2026:00:17:25 -0600] "GET / HTTP/1.1" 200 615 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
144.217.135.241 - - [06/Jan/2026:00:17:25 -0600] "GET /robots.txt HTTP/1.1" 404 264 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
144.217.135.241 - - [06/Jan/2026:00:17:26 -0600] "OPTIONS / HTTP/1.1" 200 0 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
...
show less
DDoS Attack
Web App Attack
🇺🇸
lavnet.net
2025-11-30 07:20:45
(9 months ago)
144.217.135.241 - - [30/Nov/2025:07:20:42 +0000] "GET /sitemap.xml HTTP/1.1" 404 2083 "-" "Mozilla/5 ...
show more
144.217.135.241 - - [30/Nov/2025:07:20:42 +0000] "GET /sitemap.xml HTTP/1.1" 404 2083 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
144.217.135.241 - - [30/Nov/2025:07:20:44 +0000] "GET /llms.txt HTTP/1.1" 404 2083 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
144.217.135.241 - - [30/Nov/2025:07:20:45 +0000] "GET /humans.txt HTTP/1.1" 404 2083 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
144.217.135.241 - - [30/Nov/2025:07:20:45 +0000] "GET /ads.txt HTTP/1.1" 404 2083 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
144.217.135.241 - - [30/Nov/2025:07:20:45 +0000] "GET /security.txt HTTP/1.1" 404 2083 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
144.217.135.241 - - [30/Nov/2025:07:20:45 +0000] "GET /.well-known/security.txt HTTP/1.1" 404 2083 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
...
show less
Brute-Force
Anonymous
2025-10-16 21:21:00
(10 months ago)
Unauthorized connection attempt
Brute-Force
Anonymous
2025-09-24 01:30:49
(11 months ago)
Excessive crawling/scraping
Hacking
Brute-Force
Anonymous
2025-09-14 07:00:17
(11 months ago)
Excessive crawling/scraping
Hacking
Brute-Force
Anonymous
2025-08-31 15:04:02
(1 year ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /.well-known/security.txt
Web App Attack
🇨🇭
backslash
2025-08-10 05:43:12
(1 year ago)
Bad Web Bot