This IP address has been reported a total of
12
times from
10 distinct
sources.
216.169.140.34 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
Malicious activity detected
Hacking
Web App Attack
Anonymous
Attack Signature Blocked: /wishlist/index/add/product/13624/form_key/qLJYLjrWEcdU8lMh/ (Magento Site ...
show moreAttack Signature Blocked: /wishlist/index/add/product/13624/form_key/qLJYLjrWEcdU8lMh/ (Magento Site) (Botnet activity attributed to: Angara Technologies Group / mikhail-smirnov-79830322)
show less
(mod_security) mod_security (id:225080) triggered by 216.169.140.34 (-): 1 in the last 300 secs; Por ...
show more(mod_security) mod_security (id:225080) triggered by 216.169.140.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 00:50:20.856746 2026] [security2:error] [pid 18205:tid 18205] [client 216.169.140.34:56448] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^[\\\\d\\\\.ab]+$" against "ARGS_GET:C" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "143"] [id "225080"] [rev "1"] [msg "COMODO WAF: XSS vulnerability in Plupload before 2.1.9 or MediaElement.js before 2.21.0, as used in WordPress before 4.5.2 (CVE-2016-4566 & CVE-2016-4567)||cffragrances.iee-usa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cffragrances.iee-usa.com"] [uri "/wp-includes/js/swfupload/"] [unique_id "af1rjMQC1sjL3HJ2d4G9AQAAAAI"]
show less
2026-03-29T06:48:25.600353 mail-honeypot postfix/submission/smtpd[32762]: warning: unknown[216.169.1 ...
show more2026-03-29T06:48:25.600353 mail-honeypot postfix/submission/smtpd[32762]: warning: unknown[216.169.140.34]: SASL LOGIN authentication failed: authentication failure
...
show less
Brute-Force
Anonymous
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show moreDistributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in thread-skip.asp
show less