This IP address has been reported a total of
424
times from
223 distinct
sources.
140.213.1.123 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
Access to sensitive configuration files detected.. Threat Score: 6.1/10 (MEDIUM). Reported by Tanger ...
show moreAccess to sensitive configuration files detected.. Threat Score: 6.1/10 (MEDIUM). Reported by TangerangKota-CSIRT
show less
Suspicious activity detected from IP 140.213.1.123 based on mailserver logs.
Sample logs:
2025-12-09 ...
show moreSuspicious activity detected from IP 140.213.1.123 based on mailserver logs.
Sample logs:
2025-12-09 17:06:35,031 INFO [ImapServer-1953] [ip=172.16.0.182;oip=140.213.1.123;via=com.google.android.gm,172.16.0.182(nginx/1.24.0);ua=Zimbra/24.9.7_ZEXTRAS_202410;cid=4815;] imap - LOGIN elapsed=1 (NIO)
2025-12-09 17:06:47,894 INFO [ImapServer-1953] [ip=172.16.0.182;cid=4816;oip=140.213.1.123;via=com.google.android.gm,172.16.0.182(nginx/1.24.0);ua=Zimbra/24.9.7_ZEXTRAS_202410;] imap - ID elapsed=0 (NIO)
2025-12-09 17:06:47,896 INFO [ImapServer-1956] [ip=172.16.0.182;oip=140.213.1.123;via=com.google.android.gm,172.16.0.182(nginx/1.24.0);ua=Zimbra/24.9.7_ZEXTRAS_202410;cid=4816;] imap - authentication failed for [**] (LDAP error: - unable to ldap authenticate: invalid credentials)
2025-12-09 17:06:47,896 INFO [ImapServer-1956] [ip=172.16.0.182;oip=140.213.1.123;via=com.google.android.gm,172.16.0.182(nginx/1.24.0);ua=Zimbra/24.9.7_ZEXTRAS_202410;cid=4816;] account - Error occurred during aut
show less
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 06-56.140.213.1.123.web-spamme ...
show moreIM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 06-56.140.213.1.123.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
[Sun Oct 12 17:55:37.589900 2025] [security2:error] [pid 337667:tid 139931052603072] [client 140.213 ...
show more[Sun Oct 12 17:55:37.589900 2025] [security2:error] [pid 337667:tid 139931052603072] [client 140.213.1.123:6010] ModSecurity: Access denied with code 403 (phase 1). Match of "pm matomo.staklim-malang.info " against "SERVER_NAME" required. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "164"] [id "440235"] [msg "BAD REQUEST Bro"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: %3a found within SERVER_NAME: staklim-malang.info request_line = GET /index.php/profil/arsip-artikel?catid=474&id=866%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-26-januari-1-pebruari-2016&start=40 HTTP/2.0 Request URI RAW = /index.php/profil/arsip-artikel?catid=474&id=866%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-26-januari-1-pebruari-2..."] [hostname "staklim-malang.info"] [uri "/index.php/profil/arsip-artikel"] [unique_id "aOuJKUT2UaoC01
...
show less
140.213.1.123 (ID/Indonesia/-), 2 distributed imapd attacks on account [[email protected]] in ...
show more140.213.1.123 (ID/Indonesia/-), 2 distributed imapd attacks on account [[email protected]] in the last 3600 secs
show less
Jan 23 07:44:50 hel01 sshd[2863230]: Invalid user gitworker from 140.213.1.123 port 1437
Jan 23 07:4 ...
show moreJan 23 07:44:50 hel01 sshd[2863230]: Invalid user gitworker from 140.213.1.123 port 1437
Jan 23 07:44:50 hel01 sshd[2863230]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=140.213.1.123
Jan 23 07:44:53 hel01 sshd[2863230]: Failed password for invalid user gitworker from 140.213.1.123 port 1437 ssh2
Jan 23 07:46:19 hel01 sshd[2863294]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=140.213.1.123 user=root
Jan 23 07:46:21 hel01 sshd[2863294]: Failed password for root from 140.213.1.123 port 3402 ssh2
...
show less
Brute-Force
SSH
Anonymous
$f2bV_matches
Brute-Force
SSH
Showing 1 to
15
of 424 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ