๐บ๐ธ
TPI-Abuse
2026-04-16 01:48:11
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 140.235.0.190 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 140.235.0.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 15 21:48:03.395559 2026] [security2:error] [pid 2246362:tid 2246362] [client 140.235.0.190:23617] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Kristin/Thumbs.db"] [unique_id "aeA_0z5NvKorL6k95peu9AAAAAg"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Kristin/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-14 10:14:55
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 140.235.0.190 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 140.235.0.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 06:14:47.024948 2026] [security2:error] [pid 11974:tid 11974] [client 140.235.0.190:48607] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Baldwin/Thumbs.db"] [unique_id "abU1FweOtpqqOkRwOe9y7gAAABk"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Baldwin/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-13 17:47:17
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 140.235.0.190 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 140.235.0.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 13:47:09.434453 2026] [security2:error] [pid 26114:tid 26114] [client 140.235.0.190:54367] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||secuencia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "secuencia.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abRNnTDUXnaOCYQum_hfWQAAABI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-02-25 09:40:54
(3 months ago)
Accessed trap at '/wp-login.php'
Web App Attack
๐ซ๐ฎ
Shaik Sai Meera
2026-02-18 08:45:21
(3 months ago)
IM360 WAF: Infectors: Suspicious access attempt (webshell)
Brute-Force
FTP Brute-Force
Open Proxy
๐ซ๐ท
tilellit.pro
2026-02-14 01:34:05
(4 months ago)
Fail2Ban banned 140.235.0.190 for security violations in jail wp-armour. Log: 2026/02/14 01:34:03 [e ...
show more
Fail2Ban banned 140.235.0.190 for security violations in jail wp-armour. Log: 2026/02/14 01:34:03 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 140.235.0.190 | Target: wplogin" , client: 140.235.0.190, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐จ๐ญ
backslash
2026-01-12 07:50:13
(5 months ago)
block ruleset 798ECF92F12ADC636D3520C2890AF17ADEFDE3BE
Bad Web Bot
Anonymous
2026-01-04 23:24:18
(5 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
nodepile
2025-12-24 07:37:52
(5 months ago)
Requests denied due to proxy/VPN risk (tenant=82 method=GET path=/lighting-hid-led-xenon/led-t10-168 ...
show more
Requests denied due to proxy/VPN risk (tenant=82 method=GET path=/lighting-hid-led-xenon/led-t10-168-194-ba9/luxen-5630-6smd-canbus-194-t10-6497.html ua='Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.2176.43 Safari/537.36')
show less
Open Proxy
VPN IP
๐จ๐ญ
backslash
2025-11-20 09:41:50
(6 months ago)
block ruleset 798ECF92F12ADC636D3520C2890AF17ADEFDE3BE
Bad Web Bot