๐บ๐ธ
technojoe99
2026-04-23 07:12:44
(1 month ago)
Exploit scan from 149.56.150.249. GET /sitemap.xml HTTP/1.1.
Web App Attack
Anonymous
2026-04-21 14:44:43
(2 months ago)
149.56.150.249 - - [21/Apr/2026:16:44:42 +0200] "GET / HTTP/1.1" 301 169 "-" "Mozilla/5.0 (compatibl ...
show more
149.56.150.249 - - [21/Apr/2026:16:44:42 +0200] "GET / HTTP/1.1" 301 169 "-" "Mozilla/5.0 (compatible; )"
show less
Bad Web Bot
๐ฌ๐ง
Mendip_Defender
2026-01-26 10:17:30
(4 months ago)
149.56.150.249 - - [26/Jan/2026:10:17:26 +0000] "GET /ads.txt HTTP/1.0" 404 47598 "-" "Mozilla/5.0 ( ...
show more
149.56.150.249 - - [26/Jan/2026:10:17:26 +0000] "GET /ads.txt HTTP/1.0" 404 47598 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.249 - - [26/Jan/2026:10:17:26 +0000] "GET /llms.txt HTTP/1.0" 404 47598 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.249 - - [26/Jan/2026:10:17:27 +0000] "GET /humans.txt HTTP/1.0" 404 47598 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-14 19:17:47
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 149.56.150.249 (crawl-149-56-150-249.dataprovid ...
show more
(mod_security) mod_security (id:210730) triggered by 149.56.150.249 (crawl-149-56-150-249.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 14 14:17:43.081238 2026] [security2:error] [pid 3466875:tid 3466875] [client 149.56.150.249:53221] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||climasyequipos.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "climasyequipos.com"] [uri "/[email protected] "] [unique_id "aWfr1zAplrEsq66LBFzt0QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
chronos
2026-01-12 07:31:53
(5 months ago)
[AUTORAVALT][[12/01/2026 - 04:31:52 -03:00 UTC]
Attack from [OVH Hosting, Inc.]
[149.56.150.249][cra ...
show more
[AUTORAVALT][[12/01/2026 - 04:31:52 -03:00 UTC]
Attack from [OVH Hosting, Inc.]
[149.56.150.249][crawl-149-56-150-249.dataproviderbot.com]
Action: BLocKed
Hacking... Unauthorized attempts to access the server.
Web App Attack -> Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software]
...
show less
Hacking
Web App Attack
๐บ๐ธ
chronos
2026-01-11 07:11:14
(5 months ago)
[AUTORAVALT][[11/01/2026 - 04:11:14 -03:00 UTC]
Attack from [OVH Hosting, Inc.]
[149.56.150.249][cra ...
show more
[AUTORAVALT][[11/01/2026 - 04:11:14 -03:00 UTC]
Attack from [OVH Hosting, Inc.]
[149.56.150.249][crawl-149-56-150-249.dataproviderbot.com]
Action: BLocKed
Hacking... Unauthorized attempts to access the server.
Web App Attack -> Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software]
...
show less
Hacking
Web App Attack
๐ช๐ธ
librebit
2026-01-11 01:37:25
(5 months ago)
Brute force
Brute-Force
๐จ๐ญ
backslash
2026-01-03 21:10:11
(5 months ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
๐ซ๐ฎ
Shaik Sai Meera
2025-12-29 22:45:13
(5 months ago)
IM360 WAF: Request indicates a Headless browser
Brute-Force
Web App Attack
๐ฎ๐น
Progetto1
2025-12-28 09:05:03
(5 months ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2025-12-15 21:47:09
(6 months ago)
2025-12-15 @ 22:47:08 (CET) ~ Blocked based on risk assessment and prior abuse reports
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-23 06:11:31
(6 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.150.249 (crawl-149-56-150-249.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.150.249 (crawl-149-56-150-249.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 01:11:24.009234 2025] [security2:error] [pid 9687:tid 9687] [client 149.56.150.249:33127] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.pintoresdecasascdmx.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.pintoresdecasascdmx.com"] [uri "/contacto"] [unique_id "aSKljBmYKzajiN38n4IGGwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-21 13:03:41
(7 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.150.249 (crawl-149-56-150-249.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.150.249 (crawl-149-56-150-249.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 21 08:03:35.647143 2025] [security2:error] [pid 15890:tid 15890] [client 149.56.150.249:43487] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.lubbockknights.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.lubbockknights.com"] [uri "/registrationform.php"] [unique_id "aSBjJ1CADhIDteWTN7TVjQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-11-02 11:10:18
(7 months ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
Anonymous
2025-10-22 20:16:29
(7 months ago)
Excessive crawling/scraping
Hacking
Brute-Force