π©πͺ
LRob
2026-10-04 12:18:15
(2 days ago)
Abusive crawler | ua: Mozilla/5.0 (compatible; Dataprovider.com) | path: / | 2026-10-04 12:18 UTC
Bad Web Bot
π΅π±
Budyn
2026-10-01 16:21:42
(5 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: www.sweetpuddingtrap.top | URI: /wp-admin/ | UA: Mozilla/5.0 (compatible; Dataprovider.com) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-09-29 16:56:13
(1 week ago)
Abusive crawler | ua: Mozilla/5.0 (compatible; Dataprovider.com) | path: /
Bad Web Bot
π¬π·
setupgr
2026-09-29 07:12:29
(1 week ago)
(mod_security) mod_security (id:11000011) triggered by 149.56.150.67 (CA/Canada/Quebec/Montreal/-/[A ...
show more
(mod_security) mod_security (id:11000011) triggered by 149.56.150.67 (CA/Canada/Quebec/Montreal/-/[AS16276 OVH SAS]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Tue Sep 29 10:12:26.254602 2026] [security2:error] [pid 1263096:tid 1263231] [client 149.56.150.67:42545] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "dataproviderbot.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: crawl-149-56-150-67.dataproviderbot.com"] [severity "CRITICAL"] [hostname "www.tavernadimitris.com"] [uri "/"] [unique_id "artk2ewDVci0LR0ILxO9_AAAAsg"]
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-09-26 16:33:56
(1 week ago)
(mod_security) mod_security (id:243420) triggered by 149.56.150.67 (crawl-149-56-150-67.dataprovider ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.150.67 (crawl-149-56-150-67.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 12:33:49.017284 2026] [security2:error] [pid 12320:tid 12320] [client 149.56.150.67:60323] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.bordalo-es.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.bordalo-es.com"] [uri "/index.html"] [unique_id "arfz7Vp3NKZyKEfnFogRfAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΉπ·
neron
2026-08-15 23:06:48
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
πΉπ·
neron
2026-08-09 22:29:21
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
π·πΈ
Smel
2026-08-02 06:22:05
(2 months ago)
HTTP/80/443/8080 Unauthorized Probe, Hack -
Hacking
Web App Attack
πΉπ·
ycoskun41
2026-07-03 06:25:26
(3 months ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
Anonymous
2026-05-19 01:00:05
(4 months ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
Anonymous
2026-03-10 17:12:25
(6 months ago)
ALTB WEBFORM SPAM 149.56.150.67 (crawl-149-56-150-67.dataproviderbot.com)
Web Spam
π΅πΉ
Subnet Shadow Specter
2026-03-09 08:30:05
(6 months ago)
[Security Alert] Attempted to access sensitive configuration files. [Method]: GET. [Request]: => /. ...
show more
[Security Alert] Attempted to access sensitive configuration files. [Method]: GET. [Request]: => /. IP banned. [User-Agent]: Mozilla/5.0 (compatible; Dataprovider.com). [OS]: unknown. [IP Address]: 149.56.150.67. [Date]: 2026-03-09 05:45:08 UTC.
show less
Hacking
Web App Attack
Anonymous
2026-03-05 00:40:07
(7 months ago)
Malicious activity detected
Hacking
Web App Attack
πΉπ
thaizone.com
2026-01-25 05:01:23
(8 months ago)
Brute Force Attack on a Web Resources (repeated 404) #1
DDoS Attack
Web Spam
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-13 12:08:38
(8 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.150.67 (crawl-149-56-150-67.dataprovider ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.150.67 (crawl-149-56-150-67.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 13 07:08:32.578759 2026] [security2:error] [pid 21964:tid 21964] [client 149.56.150.67:35077] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.emeraldhighlands.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.emeraldhighlands.org"] [uri "/Board.html"] [unique_id "aWY1wPdnvKRLxKATVBrNRQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack