Welcome to the new IP check page! We're rolling it out gradually and would love your input. Spot a bug, or have a suggestion?
Share feedback
139.87.112.147
Neutral Activity
There is no recent abuse activity, or the IP address is whitelisted.
Whitelisted Subnet
Whitelisted netblocks are typically owned by trusted entities, such as Google or Microsoft who
may use them for search engine spiders. However, these same entities sometimes also provide cloud
servers and mail services which are easily abused. Pay special attention when trusting or
distrusting these IPs.
Log in to view charts and search reports for this IP.
Log In
Top Reporter Countries (Last 60 Days)
Example preview
Report Categories (Last 60 Days)
Example preview
Reports Activity
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 139.87.112.147:
This IP address has been reported a total of
18
times from
8 distinct
sources.
139.87.112.147 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Finland
with 2
reports;
Germany
with 1
report.
The most common categories in these recent reports were:
Hacking
3
times;
Web App Attack
3
times;
Bad Web Bot
2
times.
Old Reports
The most recent abuse report for this IP address is from
. It is possible that this IP is no
longer involved in abusive activities.
Part of the same coordinated mass vulnerability scan as 139.87.112.4/23/78/145 (reported minutes ear ...
show morePart of the same coordinated mass vulnerability scan as 139.87.112.4/23/78/145 (reported minutes earlier for the same fleet). Hitting adsproxycsp1 edge nodes with 403 probes for /rest/api/latest/repos (Bitbucket), /system/database/drivers/mssql/index.html, /system/login. Source: Oracle Public Cloud, same /24 subnet.
show less
Unsolicited web application vulnerability scan against our public HTTPS/HTTP endpoint. 2026-08-01 08 ...
show moreUnsolicited web application vulnerability scan against our public HTTPS/HTTP endpoint. 2026-08-01 08:17:02-08:30:04 UTC: 6952 requests, 543 distinct URLs, both port 80 and 443 (TLSv1.3), Host header set to the bare server IP. 1096 requests blocked with 403 and 178 with 405. Probed paths include /system/login, /status/phpinfo.php, /dynamiccontent.properties.jsf (Oracle WebLogic RCE probe), /level/42/exec/- (Cisco IOS), /userfiles/elements/text, plus overlong-UTF8 path traversal such as /status/%c0%ae%c0%ae/%c0%ae%c0%ae/. Non-standard HTTP methods used (BADMTHD, TRACE, OPTIONS). Requests carry scanner canary paths (/qualystest.xyz, /QUALYS730242). No business relationship with this source; scanning was not authorised by us. Same /24 previously scanned our infrastructure on 2026-07-07 from 139.87.112.70. Evidence from nginx access logs.
show less
{"level":"info","ts":1756869378.4069815,"logger":"http.log.access.log1","msg":"handled request","req ...
show more{"level":"info","ts":1756869378.4069815,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"139.87.112.147","remote_port":"40684","client_ip":"139.87.112.147","proto":"HTTP/1.1","method":"GET","host":"159.89.98.98","uri":"/","headers":{}},"bytes_read":0,"user_id":"","duration":0.00004857,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://159.89.98.98/"],"Content-Type":[]}}
{"level":"info","ts":1756869379.2706573,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"139.87.112.147","remote_port":"41254","client_ip":"139.87.112.147","proto":"HTTP/1.1","method":"GET","host":"159.89.98.98","uri":"/DeviceInformation","headers":{}},"bytes_read":0,"user_id":"","duration":0.00004936,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://159.89.98.98/DeviceInformation"],"Content-Type":[]}}
{"level":"info","ts":1756869379.558967,"logger":"http.log.
...
show less
{"level":"info","ts":1748444100.2169511,"logger":"http.log.access.log1","msg":"handled request","req ...
show more{"level":"info","ts":1748444100.2169511,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"139.87.112.147","remote_port":"60114","client_ip":"139.87.112.147","proto":"HTTP/1.1","method":"GET","host":"159.89.98.98","uri":"/","headers":{}},"bytes_read":0,"user_id":"","duration":0.000061948,"size":0,"status":308,"resp_headers":{"Content-Type":[],"Server":["Caddy"],"Connection":["close"],"Location":["https://159.89.98.98/"]}}
{"level":"info","ts":1748444101.0620582,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"139.87.112.147","remote_port":"60224","client_ip":"139.87.112.147","proto":"HTTP/1.1","method":"GET","host":"159.89.98.98","uri":"/DeviceInformation","headers":{}},"bytes_read":0,"user_id":"","duration":0.000046569,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://159.89.98.98/DeviceInformation"],"Content-Type":[]}}
{"level":"info","ts":1748444101.3467395,"logger":"http.l
...
show less
DDoS Attack
Web App Attack
Anonymous
| Common web attack.
Hacking
SQL Injection
Web App Attack
Anonymous
Blocked for log4j CVE-2021-44228
DDoS Attack
Bad Web Bot
Exploited Host
Web App Attack