🇺🇸
TPI-Abuse
2026-09-05 12:01:29
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 195.140.176.44 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 195.140.176.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 08:01:21.950680 2026] [security2:error] [pid 29001:tid 29001] [client 195.140.176.44:27633] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||americanexportimport.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "americanexportimport.com"] [uri "/mailto:[email protected] "] [unique_id "apwEkVUaAFSakYjwIBUMOgAAAAg"], referer: http://americanexportimport.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 13:03:00
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 195.140.176.44 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 195.140.176.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 09:02:52.205913 2026] [security2:error] [pid 30538:tid 30538] [client 195.140.176.44:39105] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "apgefO-2E-7YmA9neuRKewAAABQ"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-04 10:10:04
(1 month ago)
FortiWeb WAF: 32 attacks detected. Threat Score: 11225280. Types: Client Management(16), Signature D ...
show more
FortiWeb WAF: 32 attacks detected. Threat Score: 11225280. Types: Client Management(16), Signature Detection(16). Origin: United States.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-06-30 10:19:43
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 195.140.176.44 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 195.140.176.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 06:19:37.552333 2026] [security2:error] [pid 11232:tid 11232] [client 195.140.176.44:63027] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.americanexportimport.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.americanexportimport.com"] [uri "/mailto:[email protected] "] [unique_id "akOYORXEi99LlNPGA-jSOQAAAAU"], referer: http://www.americanexportimport.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
MAGIC
2026-06-18 01:07:10
(2 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
🇮🇩
hermawan
2026-05-27 11:50:36
(3 months ago)
05/27/2026-18:50:34.100993 [Drop] [**] [1:2028435:2] Suricata ET Hash - SCANNER: wordpress wp-logi ...
show more
05/27/2026-18:50:34.100993 [Drop] [**] [1:2028435:2] Suricata ET Hash - SCANNER: wordpress wp-login Firefox/40.1 [**] [Classification: Unknown Traffic] [Priority: 3] {TCP} 195.140.176.44:27015 -> 103.166.156.58:443
...
show less
Email Spam
Hacking
Anonymous
2026-04-22 15:08:00
(4 months ago)
Botnet. Scraping.
Brute-Force
Bad Web Bot
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-03-28 22:58:41
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 195.140.176.44 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 195.140.176.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 18:58:35.902405 2026] [security2:error] [pid 9788:tid 9788] [client 195.140.176.44:26389] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "achdG1N1JRhGDk4f_da8YAAAAAs"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-02-22 21:21:27
(6 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 23-21.195.140.176.44.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 23-21.195.140.176.44.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
🇺🇸
Starburst SysOp Team
2026-02-22 14:13:29
(6 months ago)
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 44.176.140.195.rbl.malw ...
show more
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 44.176.140.195.rbl.malware.expert succeeded at REQUEST_HEADERS:x-forwarded-for. (1001000-mnz6-3)
show less
Hacking
🇪🇸
gnom4ik
2026-02-21 14:11:53
(6 months ago)
ban-reviewer auto report; ip=195.140.176.44; scenario=http:scan; verdict=valid_ban; confidence=0.85; ...
show more
ban-reviewer auto report; ip=195.140.176.44; scenario=http:scan; verdict=valid_ban; confidence=0.85; categories=14,15,18,22; active_decisions=1; lookback_decisions=1; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=IP flagged for 'Port Scan' (category 14) in abuseipdb; IP flagged for 'Hacking' (category 15) in abuseipdb; IP flagged for 'Brute-Force' (category 18) in abuseipdb; IP flagged for 'SSH' (category 22) in abuseipdb; Scan scenario detected (http:scan)
show less
Port Scan
Hacking
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-01-09 15:31:42
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 195.140.176.44 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 195.140.176.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 09 10:31:37.449893 2026] [security2:error] [pid 532305:tid 532305] [client 195.140.176.44:65149] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.caferutadelaseda.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.caferutadelaseda.com"] [uri "/mysql.sql"] [unique_id "aWEfWYUvkLCND5X-LztJOQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-09 11:05:46
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 195.140.176.44 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 195.140.176.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 09 06:05:42.683070 2026] [security2:error] [pid 11752:tid 11752] [client 195.140.176.44:29711] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aWDhBoWvEBNn0YXm7GVmywAAABU"], referer: http://www.capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
kranem
2025-10-01 18:00:21
(11 months ago)
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 25288 (LIR-UKRAINE-AS)
Protocol: HTTP/1.1 ...
show more
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 25288 (LIR-UKRAINE-AS)
Protocol: HTTP/1.1 (HEAD method)
Endpoint: /
Timestamp: 2025-10-01T16:43:35Z
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36
show less
Bad Web Bot
🇨🇭
backslash
2025-09-27 20:05:19
(11 months ago)
block ruleset 798ECF92F12ADC636D3520C2890AF17ADEFDE3BE
Bad Web Bot