๐บ๐ธ
TPI-Abuse
2026-07-18 07:14:45
(1 day ago)
(mod_security) mod_security (id:243420) triggered by 149.56.150.58 (crawl-149-56-150-58.dataprovider ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.150.58 (crawl-149-56-150-58.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 03:14:38.599364 2026] [security2:error] [pid 14587:tid 14587] [client 149.56.150.58:46883] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.crochetdoilies.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.crochetdoilies.com"] [uri "/index.html"] [unique_id "alsn3qawt0OkVEaMGeC-8gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
CryptoYakari
2026-04-24 05:35:04
(2 months ago)
149.56.150.58 - - [24/Apr/2026:08:34:55 +0300] "GET /sitemap.xml HTTP/1.0" 404 3185 "-" "Mozilla/5.0 ...
show more
149.56.150.58 - - [24/Apr/2026:08:34:55 +0300] "GET /sitemap.xml HTTP/1.0" 404 3185 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.58 - - [24/Apr/2026:08:35:01 +0300] "GET /llms.txt HTTP/1.0" 404 3185 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.58 - - [24/Apr/2026:08:35:02 +0300] "GET /humans.txt HTTP/1.0" 404 3185 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.58 - - [24/Apr/2026:08:35:02 +0300] "GET /security.txt HTTP/1.0" 404 3185 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.58 - - [24/Apr/2026:08:35:02 +0300] "GET /.well-known/security.txt HTTP/1.0" 404 3185 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
...
show less
Web Spam
Blog Spam
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-16 22:16:45
(3 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.150.58 (crawl-149-56-150-58.dataprovider ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.150.58 (crawl-149-56-150-58.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 18:16:41.655311 2026] [security2:error] [pid 1894330:tid 1894330] [client 149.56.150.58:51431] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.newisci.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.newisci.org"] [uri "/contact.html"] [unique_id "aeFfyTq7dC9FXD5UYQKONAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
bazter.pro
2026-03-08 22:59:21
(4 months ago)
Auto-Ban [2026-03-09 00:59:15]: CRITICAL: Sensitive files (1); DC: B.V., Dataprovider [Paths: 17] | ...
show more
Auto-Ban [2026-03-09 00:59:15]: CRITICAL: Sensitive files (1); DC: B.V., Dataprovider [Paths: 17] | Details: Sensitive files/paths: /author/admin/ | 404 errors (5): /security.txt, /.well-known/security.txt, /ads.txt, /humans.txt, /llms.txt | 403 errors (1): /author/admin/ | Other paths: /sitemap_index.xml, /windows/remote-desktop-services/start-button-not-work-windows-server-2016-2019/, /, /tag/%d0%bd%d0%b5-%d1%80%d0%b0%d0%b1%d0%be%d1%82%d0%b0%d0%b5%d1%82-%d0%bc%d0%b5%d0%bd%d1%8e-%d0%bf%d1%83%d1%81%d0%ba-windows-server-2019/, /category/windows/remote-desktop-services/, /windows/powershell/powershell_smena_parolya_dlya_lokalnykh_polzovateley/, /obo-mne/, /tag/ne-rabotayet-menyu-pusk/, /tag/%d0%bd%d0%b5-%d1%80%d0%b0%d0%b1%d0%be%d1%82%d0%b0%d0%b5%d1%82-%d0%bc%d0%b5%d0%bd%d1%8e-%d0%bf%d1%83%d1%81%d0%ba-windows-server-2016/, /author/bakshuha/
show less
Web App Attack
Hacking
๐จ๐ญ
Origon
2026-02-02 03:00:39
(5 months ago)
http-probing - IP: 149.56.150.58 - time="2026-02-02T04:00:39+01:00" level=info msg="(555f66b4f6a745 ...
show more
http-probing - IP: 149.56.150.58 - time="2026-02-02T04:00:39+01:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-probing by ip 149.56.150.58 (CA/16276) : 4h ban on Ip 149.56.150.58" module=db
show less
Web App Attack
๐ช๐ธ
librebit
2026-01-10 05:28:56
(6 months ago)
Brute force
Brute-Force
๐บ๐ธ
lavnet.net
2025-12-27 13:40:42
(6 months ago)
149.56.150.58 - - [27/Dec/2025:13:40:41 +0000] "GET /sitemap.xml HTTP/1.1" 404 743 "-" "Mozilla/5.0 ...
show more
149.56.150.58 - - [27/Dec/2025:13:40:41 +0000] "GET /sitemap.xml HTTP/1.1" 404 743 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.58 - - [27/Dec/2025:13:40:41 +0000] "GET /llms.txt HTTP/1.1" 404 743 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.58 - - [27/Dec/2025:13:40:41 +0000] "GET /ads.txt HTTP/1.1" 404 743 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.58 - - [27/Dec/2025:13:40:41 +0000] "GET /humans.txt HTTP/1.1" 404 743 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.58 - - [27/Dec/2025:13:40:42 +0000] "GET /security.txt HTTP/1.1" 404 743 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.58 - - [27/Dec/2025:13:40:42 +0000] "GET /.well-known/security.txt HTTP/1.1" 404 743 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-12-14 21:59:59
(7 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.150.58 (crawl-149-56-150-58.dataprovider ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.150.58 (crawl-149-56-150-58.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 14 16:59:52.120393 2025] [security2:error] [pid 15704:tid 15704] [client 149.56.150.58:44323] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.eaglesnestfuelfarm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.eaglesnestfuelfarm.com"] [uri "/contact/contact.php"] [unique_id "aT8zWJ_Sb8BzjBQBSpaS5wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2025-11-12 02:32:57
(8 months ago)
149.56.150.58 - - [12/Nov/2025:03:32:41 +0100] "GET /faq/ HTTP/2.0" 403 12161 "-" "Mozilla/5.0 (comp ...
show more
149.56.150.58 - - [12/Nov/2025:03:32:41 +0100] "GET /faq/ HTTP/2.0" 403 12161 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.58 - - [12/Nov/2025:03:32:55 +0100] "GET /llms.txt HTTP/2.0" 404 113 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.58 - - [12/Nov/2025:03:32:56 +0100] "GET /humans.txt HTTP/2.0" 404 113 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.58 - - [12/Nov/2025:03:32:56 +0100] "GET /ads.txt HTTP/2.0" 404 113 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.58 - - [12/Nov/2025:03:32:56 +0100] "GET /security.txt HTTP/2.0" 404 113 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
Greg Poulson
2025-09-08 14:18:10
(10 months ago)
Our website was hit by this DDOS at a rate of 25 in 5 minutes.
DDoS Attack
Web Spam
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-08-21 21:22:44
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 149.56.150.58 (crawl-149-56-150-58.dataprovider ...
show more
(mod_security) mod_security (id:210730) triggered by 149.56.150.58 (crawl-149-56-150-58.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 21 17:22:40.694621 2025] [security2:error] [pid 8645:tid 8666] [client 149.56.150.58:32857] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kerrfamilyassociation.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kerrfamilyassociation.com"] [uri "/[email protected] "] [unique_id "aKeOILzkUBBJlhplppcEpwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
JCB
2025-08-21 05:54:00
(10 months ago)
149.56.150.58 - - [20/Aug/2025:22:23:22 +0300] "GET /humans.txt HTTP/1.1" 404 196 "-" "Mozilla/5.0 ( ...
show more
149.56.150.58 - - [20/Aug/2025:22:23:22 +0300] "GET /humans.txt HTTP/1.1" 404 196 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.150.58 - - [20/Aug/2025:22:23:22 +0300] "GET /llms.txt HTTP/1.1" 404 196 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
...
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
Michael McCarthy
2025-08-16 07:08:27
(11 months ago)
Web Spam
๐จ๐ญ
backslash
2025-08-10 05:43:29
(11 months ago)
Bad Web Bot
Anonymous
2025-07-24 08:46:49
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH