This IP address has been reported a total of
11
times from
4 distinct
sources.
140.213.138.137 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
User login to application from malicious IP 140.213.138.137.. Threat Score: 0/10 (INFORMATIONAL). Re ...
show moreUser login to application from malicious IP 140.213.138.137.. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
User login to application from malicious IP 140.213.138.137.. Threat Score: 0/10 (INFORMATIONAL). Re ...
show moreUser login to application from malicious IP 140.213.138.137.. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
[Wed Oct 15 23:49:36.141778 2025] [security2:error] [pid 1050821:tid 140019875407552] [client 140.21 ...
show more[Wed Oct 15 23:49:36.141778 2025] [security2:error] [pid 1050821:tid 140019875407552] [client 140.213.138.137:3872] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i),.*?[\\"'\\\\)0-9`-f][\\"'`](?:[\\"'`].*?[\\"'`]|(?:\\\\r?\\\\n)?\\\\z|[^\\"'`]+)|[^0-9A-Z_a-z]select.+[^0-9A-Z_a-z]*?from|(?:alter|(?:(?:cre|trunc|upd)at|renam)e|d(?:e(?:lete|sc)|rop)|(?:inser|selec)t|load)[\\\\s\\\\x0b]*?\\\\([\\\\s\\\\x0b]*?space[\\\\s\\\\x0b]*?\\\\(" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "2129"] [id "942200"] [msg "Detects MySQL comment-/space-obfuscated injections and backtick termination"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: , like Gecko) Mobile/15E148 OcIdWebView ({\\x22isDarkTheme\\x22:true, found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (iPhone; CPU iPhone OS 17_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHT
...
show less