AbuseIPDB » 139.5.242.242
139.5.242.242 was found in our database!
This IP was reported 13 times. Confidence of
Abuse
is 25%: ?
| ISP |
PIYUSH NETWORKS
|
| Usage Type |
Fixed Line ISP
|
| ASN |
AS133982
|
| Domain Name |
excitel.com
|
| Country |
๐ฎ๐ณ
India
|
| City |
Delhi, Delhi
|
IP info including ISP, Usage Type, and Location provided
by IPInfo. Updated weekly.
IP Abuse Reports for 139.5.242.242:
This IP address has been reported a total of
13
times from
9 distinct
sources.
139.5.242.242 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
| Reporter |
IoA Timestamp (UTC)
|
Comment |
Categories |
|
|
๐บ๐ธ
jcbriar
|
|
Searching for vulnerable scripts
|
Hacking
Web App Attack
|
|
|
๐บ๐ธ
TAY
|
|
139.5.242.242 - - [15/Jul/2026:21:34:02 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5979 "-" "Jetpack/13. ...
show more
139.5.242.242 - - [15/Jul/2026:21:34:02 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5979 "-" "Jetpack/13.0; WordPress/6.2; http://site30153813.com"
139.5.242.242 - - [15/Jul/2026:21:34:12 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5979 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.2)"
139.5.242.242 - - [15/Jul/2026:21:34:23 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5979 "-" "Jetpack by WordPress.com"
...
show less
|
Brute-Force
|
|
|
๐ฉ๐ช
Marc
|
|
139.5.242.242 - - [15/Jul/2026:10:47:37 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4841 "-" "Jetpack by ...
show more
139.5.242.242 - - [15/Jul/2026:10:47:37 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4841 "-" "Jetpack by WordPress.com" 139.5.242.242 - - [15/Jul/2026:10:47:48 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4842 "-" "WordPress.com; https://wordpress.com" 139.5.242.242 - - [15/Jul/2026:10:47:58 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4842 "-" "Jetpack by WordPress.com"
show less
|
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:240335) triggered by 139.5.242.242 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 139.5.242.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 03:18:16.278943 2026] [security2:error] [pid 2623:tid 2623] [client 139.5.242.242:55818] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 139.5.242.242 (+1 hits since last alert)|slimlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "slimlaw.com"] [uri "/xmlrpc.php"] [unique_id "alc0OGlXAgGQ__eGx9_9FAAAAAs"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ณ๐ฑ
exxos
|
|
HTTP1.x attacks
|
DDoS Attack
|
|
|
๐ณ๐ฑ
exxos
|
|
HTTP1.x attacks
|
DDoS Attack
|
|
|
๐ณ๐ฑ
exxos
|
|
HTTP1.x attacks
|
DDoS Attack
|
|
|
๐ณ๐ฑ
exxos
|
|
HTTP1.x attacks
|
DDoS Attack
|
|
|
๐ณ๐ฑ
exxos
|
|
HTTP1.x attacks
|
DDoS Attack
|
|
|
๐ซ๐ท
oonux.net
|
|
RouterOS: Scanning detected TCP 139.5.242.242:30221 > x.x.x.x:445
|
Port Scan
|
|
|
๐ฑ๐น
NotACaptcha
|
|
Unauthorised access (Oct 13 07:32) SRC=139.5.242.242 LEN=52 TTL=114 ID=29713 DF TCP DPT=445 WINDOW=8 ...
show more
Unauthorised access (Oct 13 07:32) SRC=139.5.242.242 LEN=52 TTL=114 ID=29713 DF TCP DPT=445 WINDOW=8192 SYN
show less
|
Port Scan
|
|
|
๐ณ๐ฑ
taivas.nl
|
|
Spammer
|
Email Spam
|
|
|
๐ฉ๐ช
lukgth
|
|
139.5.242.242 triggered Icarus honeypot. Check us out on github.
|
Port Scan
Hacking
|
|
Showing 1 to
13
of 13 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: