๐บ๐ธ
TPI-Abuse
2026-05-22 15:01:24
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 140.235.1.141 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 140.235.1.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 11:01:17.020800 2026] [security2:error] [pid 6638:tid 6638] [client 140.235.1.141:52669] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.art.mavikalem.org"] [uri "/wp-config.php.dist"] [unique_id "ahBvvSbWyvHMJ0KmuxGdlAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 10:54:04
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 140.235.1.141 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 140.235.1.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 06:53:55.665478 2026] [security2:error] [pid 17874:tid 17874] [client 140.235.1.141:38355] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nessmonsters.com|F|2"] [data ".inc"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nessmonsters.com"] [uri "/wp-config.inc"] [unique_id "ahA1w2LRdQP4_sr6Q88ZtgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 09:43:46
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 140.235.1.141 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 140.235.1.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 05:43:35.468875 2026] [security2:error] [pid 6092:tid 6092] [client 140.235.1.141:49705] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gerrytolentino.praemiumtech.com"] [uri "/wp-config.php.bak"] [unique_id "ahAlR3Swwl8SzRThzryqQQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
ptlab
2026-05-21 20:45:52
(3 weeks ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
๐จ๐ญ
backslash
2026-05-18 17:36:00
(3 weeks ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
NicoID
2026-05-02 00:10:00
(1 month ago)
140.235.1.141 - - [01/May/2026:00:30:18 -0600] "GET /wp-login.php HTTP/1.1" 200 5762 "-" "Mozilla/5. ...
show more
140.235.1.141 - - [01/May/2026:00:30:18 -0600] "GET /wp-login.php HTTP/1.1" 200 5762 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Brute-Force
๐จ๐ญ
4server
2026-04-30 20:11:05
(1 month ago)
[ThuApr3022:10:58.9330742026][security2:error][pid4107214:tid4108045][client140.235.1.141:0]ModSecur ...
show more
[ThuApr3022:10:58.9330742026][security2:error][pid4107214:tid4108045][client140.235.1.141:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:queryintrospectionquery\?\|__schema\\\\\\\\\?{\?\(\?:querytype\|types\?\)\)\?\\\\\\\\{\"atREQUEST_BODY.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"234\"][id\"344378\"][rev\"2\"][msg\"Atomicorp.comWAFRules:GraphQLInjectionAttackattempt\"][data\"MatchedData:__schema{types{foundwithinREQUEST_BODY:{\\\\x22query\\\\x22:\\\\x22{__schema{types{name}}}\\\\x22}\"][severity\"CRITICAL\"][tag\"SQLi\"][hostname\"mondo-it.ch\"][uri\"/index.php\"][unique_id\"afO3Uv2TkPf0MlDvGtRvwgAAANY\"]
show less
Hacking
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-04-15 13:02:32
(1 month ago)
(modsecurity) srv104 ModSecurity 140.235.1.141 (US/United States/-): 10 in the last 3600 secs; Ports ...
show more
(modsecurity) srv104 ModSecurity 140.235.1.141 (US/United States/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ซ๐ท
tilellit.pro
2026-04-01 00:44:32
(2 months ago)
Fail2Ban banned 140.235.1.141 for security violations in jail wp-armour. Log: 2026/04/01 00:44:32 [e ...
show more
Fail2Ban banned 140.235.1.141 for security violations in jail wp-armour. Log: 2026/04/01 00:44:32 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 140.235.1.141 | Target: wplogin" , client: 140.235.1.141, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://espsformacion.com/wp-login.php"
...
show less
Web Spam
๐บ๐ธ
oralunal
2026-03-31 18:27:39
(2 months ago)
IP banned by Fail2Ban in jail ente-suss ente.com-ssl_log mvfnds
...
Bad Web Bot
Web App Attack
Anonymous
2026-02-25 09:33:23
(3 months ago)
VPN password spraying
Brute-Force
๐ซ๐ท
masterguru
2025-12-23 11:01:28
(5 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 140.235.1.141 (US/United States/-): 1 in the l ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 140.235.1.141 (US/United States/-): 1 in the last 3600 secs (0-197)
show less
Hacking
Anonymous
2025-12-22 05:08:26
(5 months ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.12.22 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.12.22 is noted in report timestamp
show less
Hacking
Brute-Force
๐ง๐ช
voormedia
2025-11-19 08:29:07
(6 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-15 10:54:10
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 140.235.1.141 (140-235-1-141.cloudairone.com): ...
show more
(mod_security) mod_security (id:210350) triggered by 140.235.1.141 (140-235-1-141.cloudairone.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 15 06:54:05.134225 2025] [security2:error] [pid 28508:tid 28508] [client 140.235.1.141:32641] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||gp-cm.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "gp-cm.com"] [uri "/"] [unique_id "aO99TVUvLlmZdqPs6fJoJAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack