This IP address has been reported a total of
5
times from
3 distinct
sources.
213.209.140.149 was first reported on
May 2nd 2025 , and the most recent report was
2 weeks ago .
In the last 60 days, the only reporter location was:
France
with 1
report.
The only category in these recent reports was:
Bad Web Bot
1
time.
Old Reports
The most recent abuse report for this IP address is from
2 weeks ago . It is possible that this IP is no
longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ซ๐ท
LRob
2026-09-12 19:44:56
(2 weeks ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: /v3/api-docs | 2026-09-12 19:44 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-10 16:55:32
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 213.209.140.149 (undefined.hostname.localhost): ...
show more
(mod_security) mod_security (id:210350) triggered by 213.209.140.149 (undefined.hostname.localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 10 12:55:27.527062 2026] [security2:error] [pid 2118613:tid 2118613] [client 213.209.140.149:42447] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||circleinthesquare.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "circleinthesquare.org"] [uri "/about"] [unique_id "adkrf5ltW7Hu80UacsF2FQAAADU"], referer: https://circleinthesquare.org/about
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 14:07:59
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 213.209.140.149 (undefined.hostname.localhost): ...
show more
(mod_security) mod_security (id:210350) triggered by 213.209.140.149 (undefined.hostname.localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 10:07:50.881614 2026] [security2:error] [pid 202119:tid 202119] [client 213.209.140.149:52651] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||brandsrepairandremodeling.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "brandsrepairandremodeling.com"] [uri "/who-we-are"] [unique_id "adZhNn41249bLmXXQdQ2KwAAAAk"], referer: https://brandsrepairandremodeling.com/who-we-are
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-26 17:54:41
(11 months ago)
HTTPS vulnerability scan attempt detected. Port 443.
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-02 04:56:22
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 213.209.140.149 (undefined.hostname.localhost): ...
show more
(mod_security) mod_security (id:210492) triggered by 213.209.140.149 (undefined.hostname.localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 02 00:56:18.394518 2025] [security2:error] [pid 2838715:tid 2838715] [client 213.209.140.149:37387] [client 213.209.140.149] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "raette.com"] [uri "/core/.env"] [unique_id "aBRQcqN58E6wv9xyp48gFwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Showing 1 to
5
of 5 reports