๐บ๐ธ
TPI-Abuse
2026-06-10 10:58:12
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 140.235.3.94 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 140.235.3.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 06:57:57.129520 2026] [security2:error] [pid 19819:tid 19819] [client 140.235.3.94:30855] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cidv.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cidv.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ailDNb0TJL4EeFiwLZl51gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-01 05:48:43
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 140.235.3.94 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 140.235.3.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 01:48:35.009619 2026] [security2:error] [pid 13724:tid 13724] [client 140.235.3.94:23319] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scadainthecloud.com"] [uri "/.env"] [unique_id "afQ-s2zg6-3E1z5PwuoNAQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 20:35:17
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 140.235.3.94 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 140.235.3.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 16:35:07.394007 2026] [security2:error] [pid 15634:tid 15634] [client 140.235.3.94:53189] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||scswat.org|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "scswat.org"] [uri "/s3cmd.ini"] [unique_id "afO8-7TG_VyQqKpJb00n_QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
seniorlinuxadmin
2026-04-29 08:37:42
(1 month ago)
140.235.3.94 - - [29/Apr/2026:09:37:40 +0100] "GET /s3cmd.ini HTTP/1.1" 404 158 "-" "Mozilla/5.0 (Wi ...
show more
140.235.3.94 - - [29/Apr/2026:09:37:40 +0100] "GET /s3cmd.ini HTTP/1.1" 404 158 "-" "Mozilla/5.0 (Windows NT 6.2; ARM; Trident/7.0; Touch; rv:11.0; WPDesktop; NOKIA; Lumia 635) like Gecko"
show less
Port Scan
Web App Attack
๐ซ๐ท
conseilgouz
2026-04-28 14:07:59
(1 month ago)
joe-7 : Trying access unauthorized files/dir=>/s3cmd.ini
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-28 03:58:24
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 140.235.3.94 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 140.235.3.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 23:58:13.395943 2026] [security2:error] [pid 27553:tid 27578] [client 140.235.3.94:18443] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||viasatsales.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "viasatsales.com"] [uri "/s3cmd.ini"] [unique_id "afAwVTmstmhiHZHxnYF5bwAAARM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-26 08:48:30
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 140.235.3.94 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 140.235.3.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 04:48:23.237956 2026] [security2:error] [pid 8193:tid 8193] [client 140.235.3.94:47097] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.krystalsgiftshopandboutique.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.krystalsgiftshopandboutique.net"] [uri "/s3cmd.ini"] [unique_id "ae3RV_u4eadgDVlnIlSoMAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-02-03 17:33:03
(4 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐ฎ๐ฉ
Burayot
2026-02-03 05:56:55
(4 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 140.235.3.94 (US/United States/-): ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 140.235.3.94 (US/United States/-): 2 in the last 3600 secs
show less
Web App Attack
Anonymous
2026-02-01 05:21:19
(4 months ago)
wordpress-trap
Web App Attack
๐ฑ๐ป
garmtech.com
2026-01-03 03:07:06
(5 months ago)
IM360 WAF: Attempt to upload malware
Hacking
๐ซ๐ท
masterguru
2025-12-23 11:05:45
(5 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 140.235.3.94 (US/United States/-): 1 in the la ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 140.235.3.94 (US/United States/-): 1 in the last 3600 secs (0-193)
show less
Hacking
๐ฑ๐ป
garmtech.com
2025-11-24 16:45:33
(6 months ago)
IM360 WAF: Attempt to upload malware
Hacking
๐บ๐ธ
fbarela
2025-11-14 00:01:16
(7 months ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
๐บ๐ธ
[email protected]
2025-10-24 00:04:27
(7 months ago)
Fail2Ban jail apache-json-scanners detected activity on 2025-10-24T00:04:27Z
Brute-Force