This IP address has been reported a total of
6
times from
4 distinct
sources.
192.140.12.184 was first reported on
September 10th 2025 , and the most recent report was
1 week ago .
In the last 60 days, the only reporter location was:
United States of America
with 1
report.
The most common categories in these recent reports were:
Bad Web Bot
1
time;
Brute-Force
1
time;
Web App Attack
1
time.
Old Reports
The most recent abuse report for this IP address is from
1 week ago . It is possible that this IP is no
longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐บ๐ธ
TPI-Abuse
2026-09-16 11:24:54
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 192.140.12.184 (184.12.140.192.kater.com.br): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 192.140.12.184 (184.12.140.192.kater.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 07:24:46.033998 2026] [security2:error] [pid 2553708:tid 2553708] [client 192.140.12.184:33518] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "automatebi.com"] [uri "/store/.env.local"] [unique_id "aqp8foHVkNwcu5R7WqaJRgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
hermawan
2026-06-22 18:47:46
(3 months ago)
[Tue Jun 23 01:47:43.865905 2026] [security2:error] [pid 944599:tid 140214327563968] [client 192.140 ...
show more
[Tue Jun 23 01:47:43.865905 2026] [security2:error] [pid 944599:tid 140214327563968] [client 192.140.12.184:46426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.yandex.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.yandex.go.id found within REQUEST_HEADERS:Referer: https://www.yandex.go.id/ request_line = GET /index.php/informasi-iklim/infografis-iklim/infografis-dasarian/infografis-dasarian-iklim HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/informasi-iklim/infografis-iklim/infografis-dasarian/infografis-dasarian-iklim"] [unique_id "ajmDT6TQi5Jt6cD0J1SUJwABhgE"], referer https://www.yandex.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[944601] [3UzYE9zgM3Y] [ajmDT6TQi5Jt6cD0J1SUJwABhgE] keep_alive=[1] [2026-06-23 01:47:43.865910] [R:ajmDT6TQi5Jt6cD0J1SUJw
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-06-01 02:50:29
(3 months ago)
[Mon Jun 01 09:50:25.088976 2026] [security2:error] [pid 1571035:tid 140573519369920] [client 192.14 ...
show more
[Mon Jun 01 09:50:25.088976 2026] [security2:error] [pid 1571035:tid 140573519369920] [client 192.140.12.184:58722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.google.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.google.go.id found within REQUEST_HEADERS:Referer: https://www.google.go.id/ request_line = GET /images/Klimatologi/Buletin/Bulanan/2026/04_April_2026/Buletin_Bulanan_Analisis_Hujan_Bulan_APRIL_Tahun_2026_dan_Prediksi_Hujan_Bulan_JUNI-JULI-AGUSTUS_Tahun_2026_Provinsi_Jawa_Timur.webp HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Buletin/Bulanan/2026/04_April_2026/Buletin_Bulanan_Analisis_Hujan_Bulan_APRIL_Tahun_2026_dan_Prediksi_Hujan_Bulan_JUNI-JULI-AGUSTUS_Tahun_2026_Provinsi_Jawa_Timur.webp"] [unique_id "ahzzcSDjnqr8oeqIJVy-4wAASwE"], referer https://w
...
show less
Email Spam
Hacking
Anonymous
2025-11-20 00:15:12
(10 months ago)
scanning http requests from known botnet
Web App Attack
๐ท๐ด
INTEQ
2025-10-31 06:21:02
(10 months ago)
Web attack from 192.140.12.184
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-10 22:25:55
(1 year ago)
(mod_security) mod_security (id:217210) triggered by 192.140.12.184 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:217210) triggered by 192.140.12.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 18:25:49.676719 2025] [security2:error] [pid 23452:tid 23452] [client 192.140.12.184:36222] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||christineohlman.net|F|4"] [data "GET http://christineohlman.net HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "christineohlman.net"] [uri "/"] [unique_id "aMH67RC_zsBFaUmkL621fwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Showing 1 to
6
of 6 reports