๐ฉ๐ช
LRob
2026-09-25 09:15:04
(9 hours ago)
This address crawls our sites under a User-Agent that belongs to a known abusive scraper, or under a ...
show more
This address crawls our sites under a User-Agent that belongs to a known abusive scraper, or under a placeholder identity no legitimate software uses. Such crawlers load servers with automated requests nobody asked for and often harvest content or e-mail addresses; blocked. Please check what runs on this address. | ua: Mozilla/5.0 (compatible; Dataprovider.com) | path: / | 2026-09-25 09:15 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-25 01:54:57
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 149.56.150.154 (crawl-149-56-150-154.dataprovid ...
show more
(mod_security) mod_security (id:210730) triggered by 149.56.150.154 (crawl-149-56-150-154.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 21:54:49.612205 2026] [security2:error] [pid 13194:tid 13194] [client 149.56.150.154:36695] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.aavondalervstorage.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.aavondalervstorage.com"] [uri "/[email protected] "] [unique_id "arXUacQIF8CcvBjvXxmqhQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-18 23:38:24
(6 days ago)
Abusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5 ...
show more
Abusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5.0 (compatible; Dataprovider.com) | path: / (+16 more) | 2026-09-18 23:38 UTC
show less
Bad Web Bot
๐ฆ๐บ
Bay13
2026-09-18 20:38:26
(6 days ago)
CrowdSec:custom/http-probing
Web App Attack
๐ฆ๐บ
ghel
2026-09-17 05:02:48
(1 week ago)
149.56.150.154 - - [17/Sep/2026:13:02:43 +0800] "GET /.well-known/ucp HTTP/1.1" 404 116584 "-" "Mozi ...
show more
149.56.150.154 - - [17/Sep/2026:13:02:43 +0800] "GET /.well-known/ucp HTTP/1.1" 404 116584 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.154 - - [17/Sep/2026:13:02:44 +0800] "GET /security.txt HTTP/1.1" 404 116584 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.154 - - [17/Sep/2026:13:02:45 +0800] "GET /.well-known/security.txt HTTP/1.1" 404 116908 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.154 - - [17/Sep/2026:13:02:46 +0800] "GET /humans.txt HTTP/1.1" 404 116908 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.154 - - [17/Sep/2026:13:02:47 +0800] "GET /ads.txt HTTP/1.1" 404 116908 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 17:25:30
(3 weeks ago)
(mod_security) mod_security (id:243420) triggered by 149.56.150.154 (crawl-149-56-150-154.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.150.154 (crawl-149-56-150-154.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 13:25:26.542293 2026] [security2:error] [pid 30587:tid 30587] [client 149.56.150.154:33315] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.godcontends.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.godcontends.com"] [uri "/index.php"] [unique_id "apr_BoqQn_0A-ACZ01BONwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2026-08-19 00:18:13
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action: MANAGED_CHALLENGE | Protocol: HTTP/2 (GET ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action: MANAGED_CHALLENGE | Protocol: HTTP/2 (GET) | Endpoint: / | UA: Mozilla/5.0 (Linux; Android 10; SM-G981B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.162 Mobile Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
AvonleaConsulting
2026-08-04 12:26:40
(1 month ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 06:13:57
(2 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.150.154 (crawl-149-56-150-154.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.150.154 (crawl-149-56-150-154.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 02:13:49.606188 2026] [security2:error] [pid 10892:tid 10892] [client 149.56.150.154:40747] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||relationshipecology.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "relationshipecology.com"] [uri "/consulting.html"] [unique_id "aj9qHXKptOu7vLRSi_9mJgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lavnet.net
2026-05-23 17:13:00
(4 months ago)
149.56.150.154 - - [23/May/2026:17:12:59 +0000] "GET /sitemap.xml HTTP/2.0" 404 286 "-" "Mozilla/5.0 ...
show more
149.56.150.154 - - [23/May/2026:17:12:59 +0000] "GET /sitemap.xml HTTP/2.0" 404 286 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.154 - - [23/May/2026:17:13:00 +0000] "GET /ads.txt HTTP/2.0" 404 287 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.154 - - [23/May/2026:17:13:00 +0000] "GET /llms.txt HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.154 - - [23/May/2026:17:13:00 +0000] "GET /security.txt HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.154 - - [23/May/2026:17:13:00 +0000] "GET /.well-known/security.txt HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.154 - - [23/May/2026:17:13:00 +0000] "GET /humans.txt HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
...
show less
Brute-Force
๐ณ๐ฑ
JCB
2026-04-24 07:48:00
(5 months ago)
149.56.150.154 - - [24/Apr/2026:10:27:12 +0300] "OPTIONS / HTTP/1.1" 403 239 "-" "Mozilla/5.0 (compa ...
show more
149.56.150.154 - - [24/Apr/2026:10:27:12 +0300] "OPTIONS / HTTP/1.1" 403 239 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-15 20:33:09
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 149.56.150.154 (crawl-149-56-150-154.dataprovid ...
show more
(mod_security) mod_security (id:210730) triggered by 149.56.150.154 (crawl-149-56-150-154.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 15 16:33:03.044056 2026] [security2:error] [pid 1729083:tid 1729094] [client 149.56.150.154:59843] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||condo.management|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "condo.management"] [uri "/contact/enlan.com"] [unique_id "ad_1_5e1yCoeGJcqB1giogAAAUc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
blinx
2026-03-02 15:09:19
(6 months ago)
Suspicious activity detected by Modsecurity
Web Spam
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐ธ๐ช
SkyDancer
2026-02-25 07:52:39
(7 months ago)
Multiple login attempts via RDP and/or SSH using wrong credentials. Attack automatically blocked by ...
show more
Multiple login attempts via RDP and/or SSH using wrong credentials. Attack automatically blocked by SkyDancer Ai via interface.
show less
Hacking
Brute-Force
SSH
๐ฉ๐ช
Viveronese
2026-02-19 15:05:27
(7 months ago)
HTTP vulnerability scanning
Web App Attack