This IP address has been reported a total of
7
times from
3 distinct
sources.
140.213.26.161 was first reported on
January 21st 2025 , and the most recent report was
2 days ago .
In the last 60 days, the only reporter location was:
Indonesia
with 1
report.
The most common categories in these recent reports were:
Email Spam
1
time;
Hacking
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ฎ๐ฉ
hermawan
2026-09-24 05:13:46
(2 days ago)
[Thu Sep 24 12:13:28.861776 2026] [security2:error] [pid 110827:tid 139649143940800] [client 140.213 ...
show more
[Thu Sep 24 12:13:28.861776 2026] [security2:error] [pid 110827:tid 139649143940800] [client 140.213.26.161:0] ModSecurity: Access denied with code 403 (phase 1). Match of "pm matomo.staklim-malang.info " against "SERVER_NAME" required. [file "/etc/modsecurity/coreruleset-4.29.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "208"] [id "440235"] [msg "BAD REQUEST Bro"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: 7% found within SERVER_NAME: staklim-jatim.bmkg.go.id request_line = GET /index.php/profil/arsip-artikel?catid=480&id=837%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-5-11-januari-2016&start=20 HTTP/1.1 Request URI RAW = /index.php/profil/arsip-artikel?catid=480&id=837%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-5-11-januari-2016&start=20 R..."] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/arsip-artikel"] [unique_id "arSxeN3WEtU
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
sockominfo
2026-05-30 17:00:47
(3 months ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-05-13 21:00:40
(4 months ago)
User login to application during non-business hours. Threat Score: 6.2/10 (MEDIUM). Confidence: 40%. ...
show more
User login to application during non-business hours. Threat Score: 6.2/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 84%. MITRE ATT&CK: T1046 (Network Service Scanning). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-05-13 20:00:40
(4 months ago)
User login to application during non-business hours. Threat Score: 6.3/10 (MEDIUM). Confidence: 40%. ...
show more
User login to application during non-business hours. Threat Score: 6.3/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 83%. MITRE ATT&CK: T1046 (Network Service Scanning). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-05-13 19:00:14
(4 months ago)
User login to application during non-business hours. Threat Score: 6/10 (MEDIUM). Reported by Tanger ...
show more
User login to application during non-business hours. Threat Score: 6/10 (MEDIUM). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฉ๐ช
Grizzlytools
2025-10-07 05:10:37
(11 months ago)
Kingcopy(AI-IDS)RouterOS: Portscanner detected.
Port Scan
๐ฎ๐ฉ
hermawan
2025-01-21 19:23:57
(1 year ago)
[Tue Jan 21 15:29:00.026664 2025] [security2:error] [pid 450488:tid 132974029420224] [client 140.213 ...
show more
[Tue Jan 21 15:29:00.026664 2025] [security2:error] [pid 450488:tid 132974029420224] [client 140.213.26.161:25386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "myactivity.google.com" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.10.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "303"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: myactivity.google.com found within REQUEST_HEADERS:Referer: https://myactivity.google.com/ request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2024/12_Desember_2024/Infografis_Bulanan_Curah_Hujan_Maksimum_Bulan_Desember_2024.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2024/12_Desember_2024/Infografis_Bulanan_Curah_Hujan_Maksimum_Bulan_Desember_2024.jpg"] [unique_id "Z49azFz4oISNDgKjWQXwbwACCEI"], referer https://myactivity.google.com/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] to
...
show less
Hacking
Web App Attack
Showing 1 to
7
of 7 reports