Anonymous
2026-10-01 23:15:59
(6 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [Mozilla/5.0 (compatible; Dataprovid ...
show more
(apache-useragents) Failed apache-useragents trigger with match [Mozilla/5.0 (compatible; Dataprovider.com)] from 149.56.160.135 (NL/The Netherlands/crawl-149-56-160-135.dataproviderbot.com): 5 in the last 300 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 149.56.160.135 - - [02/Oct/2026:01:15:46 +0200] "GET / HTTP/1.1" 301 519 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.160.135 - - [02/Oct/2026:01:15:47 +0200] "GET / HTTP/2.0" 301 123 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.160.135 - - [02/Oct/2026:01:15:50 +0200] "GET / HTTP/2.0" 200 269690 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.160.135 - - [02/Oct/2026:01:15:54 +0200] "GET /robots.txt HTTP/2.0" 200 130 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.160.135 - - [02/Oct/2026:01:15:55 +0200] "GET /sitemap.xml HTTP/2.0" 302 93 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
show less
Port Scan
π΅π±
Budyn
2026-09-28 16:24:03
(3 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: www.teddypot.website | URI: /backup.sql | UA: Mozilla/5.0 (compatible; Dataprovider.com) | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
πͺπΈ
librebit
2026-09-28 00:51:23
(4 days ago)
Brute force
Brute-Force
π©πͺ
LRob
2026-09-28 00:16:12
(4 days ago)
Vulnerability scanning | method: GET | path: /sitemap.xml, /llms.txt, /security.txt (+2 more) | ua: ...
show more
Vulnerability scanning | method: GET | path: /sitemap.xml, /llms.txt, /security.txt (+2 more) | ua: Mozilla/5.0 (compatible; Dataprovider.com) | 2026-09-28 00:16 UTC
show less
Port Scan
Web App Attack
πͺπΈ
librebit
2026-09-22 17:47:45
(1 week ago)
Brute force
Brute-Force
π©πͺ
LRob
2026-09-18 11:31:03
(1 week ago)
Asking over plain http and never following the redirect served β a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served β a crawler that reads nothing it asks for | method: GET | path: / | ua: Mozilla/5.0 (compatible; Dataprovider.com) | 2026-09-18 11:31 UTC
show less
Bad Web Bot
Anonymous
2026-09-14 09:04:49
(2 weeks ago)
apache vulnerability scan
Web App Attack
π«π·
thilo
2026-08-27 10:02:45
(1 month ago)
Probe for vulnerabilities. Path attempted: /security
Web App Attack
π©πͺ
Lino Project
2026-08-25 04:18:56
(1 month ago)
149.56.160.135 - - [25/Aug/2026:06:18:56 +0200] "GET /new-media-tv/ HTTP/2.0" 200 101539 "-" "Mozill ...
show more
149.56.160.135 - - [25/Aug/2026:06:18:56 +0200] "GET /new-media-tv/ HTTP/2.0" 200 101539 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
πΉπ·
neron
2026-08-15 23:06:48
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
πΉπ·
neron
2026-08-11 03:06:49
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
π΅π±
Budyn
2026-08-08 10:32:17
(1 month ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: www.budyn.ovh | URI: /wp-admin/ | UA: Mozilla/5.0 (compatible; Dataprovider.com) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π¬π§
Mendip_Defender
2026-08-03 18:24:21
(1 month ago)
149.56.160.135 - - [03/Aug/2026:19:24:23 +0100] "GET /robots.txt HTTP/1.1" 404 6420 "-" "Mozilla/5.0 ...
show more
149.56.160.135 - - [03/Aug/2026:19:24:23 +0100] "GET /robots.txt HTTP/1.1" 404 6420 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.160.135 - - [03/Aug/2026:19:24:24 +0100] "GET /ads.txt HTTP/1.1" 404 6420 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
149.56.160.135 - - [03/Aug/2026:19:24:24 +0100] "GET /llms.txt HTTP/1.1" 404 6420 "-" "Mozilla/5.0 (compatible; Dataprovider.com)"
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-27 11:13:42
(3 months ago)
(mod_security) mod_security (id:243420) triggered by 149.56.160.135 (crawl-149-56-160-135.dataprovid ...
show more
(mod_security) mod_security (id:243420) triggered by 149.56.160.135 (crawl-149-56-160-135.dataproviderbot.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 07:13:37.476531 2026] [security2:error] [pid 11277:tid 11277] [client 149.56.160.135:57119] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "REQUEST_HEADERS:Accept-Encoding" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.lyounglaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.lyounglaw.com"] [uri "/contact.htm"] [unique_id "aj-wYfpiuRL8G8Oh-_dCiAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
librebit
2026-05-27 02:07:03
(4 months ago)
Brute force
Brute-Force