๐ต๐ฑ
Budyn
2026-07-29 14:54:46
(17 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: URI: /wp-admin/ | UA: Mozilla/5.0 (compatible; Dataprovider.com) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐น๐ท
neron
2026-07-29 00:19:38
(1 day ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 13:48:33
(1 day ago)
(mod_security) mod_security (id:243420) triggered by 149.56.150.134 (crawl-149-56-150-134.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.150.134 (crawl-149-56-150-134.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 09:48:25.533019 2026] [security2:error] [pid 1135379:tid 1135379] [client 149.56.150.134:42833] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.cortona.ws|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.cortona.ws"] [uri "/privacy_utilizzo_cookie_it.html"] [unique_id "amizKS1ml2ZOGVSs3C5cqQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
neron
2026-07-27 12:19:38
(2 days ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-05 13:16:32
(3 weeks ago)
(mod_security) mod_security (id:243420) triggered by 149.56.150.134 (crawl-149-56-150-134.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.150.134 (crawl-149-56-150-134.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 09:16:24.461605 2026] [security2:error] [pid 12959:tid 12959] [client 149.56.150.134:45935] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.godcontends.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.godcontends.com"] [uri "/index.php"] [unique_id "akpZKEfb6W0pK_GksgUOmQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
dominioz
2026-06-22 12:11:13
(1 month ago)
2026-06-22 12:11:02 GET /robots.txt - - 149.56.150.134 HTTP/1.1 Mozilla/5.0+(compatible;+Dataprovide ...
show more
2026-06-22 12:11:02 GET /robots.txt - - 149.56.150.134 HTTP/1.1 Mozilla/5.0+(compatible;+Dataprovider.com) - 404 1440
2026-06-22 12:11:02 GET /sitemap.xml - - 149.56.150.134 HTTP/1.1 Mozilla/5.0+(compatible;+Dataprovider.com) - 404 1440
2026-06-22 12:11:02 GET /ads.txt - - 149.56.150.134 HTTP/1.1 Mozilla/5.0+(compatible;+Dataprovider.com) - 404 1440
2026-06-22 12:11:03 GET /llms.txt - - 149.56.150.134 HTTP/1.1 Mozilla/5.0+(compatible;+Dataprovider.com) - 404 1440
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 07:11:48
(1 month ago)
(mod_security) mod_security (id:243420) triggered by 149.56.150.134 (crawl-149-56-150-134.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.150.134 (crawl-149-56-150-134.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 03:11:43.171117 2026] [security2:error] [pid 9564:tid 9564] [client 149.56.150.134:49947] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.i-slim.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.i-slim.net"] [uri "/chiniese/index.htm"] [unique_id "ajOaL5edwit06X85toCvVwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-05-04 16:15:11
(2 months ago)
149.56.150.134 - - [04/May/2026:17:15:07 +0100] "GET /ads.txt HTTP/1.0" 404 66804 "-" "Mozilla/5.0 ( ...
show more
149.56.150.134 - - [04/May/2026:17:15:07 +0100] "GET /ads.txt HTTP/1.0" 404 66804 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.134 - - [04/May/2026:17:15:08 +0100] "GET /llms.txt HTTP/1.0" 404 66804 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.134 - - [04/May/2026:17:15:08 +0100] "GET /humans.txt HTTP/1.0" 404 66804 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
...
show less
Hacking
Web App Attack
๐ฉ๐ช
main.ows
2026-04-13 18:45:50
(3 months ago)
2026-04-13 19:11:59,221 fail2ban.actions [109868]: NOTICE [plesk-apache] Ban 149.56.150.134
...
show more
2026-04-13 19:11:59,221 fail2ban.actions [109868]: NOTICE [plesk-apache] Ban 149.56.150.134
...
show less
Hacking
๐บ๐ธ
Charlesiv
2026-04-04 08:01:10
(3 months ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
ASN: 16276 (OVH)
Protocol: HT ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
ASN: 16276 (OVH)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-04-04T07:43:29Z
Ray ID: 9e6eaeb40d03c730
UA: Mozilla/5.0 (compatible; Dataprovider.com)
show less
Bad Web Bot
๐ณ๐ฑ
i-turnradio.nl
2026-04-03 14:06:41
(3 months ago)
2026-04-03 16:06:40 (CET) ~ Blocked by abusescan risk assessment
Web App Attack
๐ฉ๐ช
Hary74656
2026-03-05 17:03:10
(4 months ago)
[Thu Mar 05 18:03:02.112149 2026] [core:info] [pid 142474:tid 142544] [client 149.56.150.134:38431] ...
show more
[Thu Mar 05 18:03:02.112149 2026] [core:info] [pid 142474:tid 142544] [client 149.56.150.134:38431] AH00128: File does not exist: /home/harald/www/ads.txt
...
show less
Bad Web Bot
๐ฏ๐ต
S.O.B.A. Dev.
2026-02-17 19:08:27
(5 months ago)
Web vulnerability scanning
Brute-Force
Web Spam
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-02-02 12:41:33
(5 months ago)
149.56.150.134 - - [02/Feb/2026:12:41:27 +0000] "GET /robots.txt HTTP/1.0" 404 4938 "-" "Mozilla/5.0 ...
show more
149.56.150.134 - - [02/Feb/2026:12:41:27 +0000] "GET /robots.txt HTTP/1.0" 404 4938 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.134 - - [02/Feb/2026:12:41:28 +0000] "GET /ads.txt HTTP/1.0" 404 4938 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.134 - - [02/Feb/2026:12:41:30 +0000] "GET /llms.txt HTTP/1.0" 404 4938 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
...
show less
Hacking
Web App Attack
๐จ๐ญ
backslash
2026-01-26 10:10:10
(6 months ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot