This IP address has been reported a total of
17
times from
7 distinct
sources.
140.246.120.143 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[ThuJul1623:53:43.7588102026][security2:error][pid1473269:tid1473551][client140.246.120.143:0]ModSec ...
show more[ThuJul1623:53:43.7588102026][security2:error][pid1473269:tid1473551][client140.246.120.143:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"aidweb.ch.81-17-25-250.cpanel.site\"][uri\"/.env.tmp\"][unique_id\"allS51EJcC0OZPhx3AedUAAAARE\"]
show less
(mod_security) mod_security (id:210492) triggered by 140.246.120.143 (-): 1 in the last 300 secs; Po ...
show more(mod_security) mod_security (id:210492) triggered by 140.246.120.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 13:31:07.771554 2026] [security2:error] [pid 5400:tid 5400] [client 140.246.120.143:56887] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bobfaw.com"] [uri "/.env.development.local"] [unique_id "alkVWyHyCsaNdGzUlSY9HAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
| [Dangerous/China] Aggressive IP 140.246.120.143 (~30 hits). Type: DoS Defender- Web server 400 err ...
show more| [Dangerous/China] Aggressive IP 140.246.120.143 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-25.
show less
Web App Attack
SSH
Hacking
Showing 1 to
15
of 17 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ