AbuseIPDB » 140.238.175.124
140.238.175.124 was found in our database!
This IP was reported 6 times. Confidence of
Abuse
is 3% : ?
ISP
Oracle Public Cloud
Usage Type
Data Center/Web Hosting/Transit
ASN
AS31898
Domain Name
oracleemaildelivery.com
Country
๐จ๐ญ
Switzerland
City
Zurich, Zurich
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 140.238.175.124 :
This IP address has been reported a total of
6
times from
3 distinct
sources.
140.238.175.124 was first reported on
July 14th 2025 , and the most recent report was
1 week ago .
Old Reports:
The most recent abuse report for this IP address is from
1 week ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐จ๐ฟ
lp
2026-08-25 03:20:14
(1 week ago)
Email account brute force: 1 attempts were recorded from 140.238.175.124
2026-08-25T03:58:26+02:00 w ...
show more
Email account brute force: 1 attempts were recorded from 140.238.175.124
2026-08-25T03:58:26+02:00 warning: unknown[140.238.175.124]: SASL PLAIN authentication failed: authentication failure, [email protected]
show less
Brute-Force
๐ฎ๐ฉ
hermawan
2025-07-15 16:18:15
(1 year ago)
[Tue Jul 15 23:15:45.685388 2025] [security2:error] [pid 55055:tid 140015044646592] [client 140.238. ...
show more
[Tue Jul 15 23:15:45.685388 2025] [security2:error] [pid 55055:tid 140015044646592] [client 140.238.175.124:60992] ModSecurity: Access denied with code 403 (phase 1). Match of "ipMatch 103.166.156.58" against "REMOTE_ADDR" required. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "372"] [id "440006"] [msg "Connection Close Header"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: close found within REMOTE_ADDR: 140.238.175.124 request_line = POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp%3a//input HTTP/1.1 Request URI RAW = /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp%3a//input Request Basename = index.php"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php"] [unique_id "aHZ-sfN3hl7mKGp-OjUz2gAAAMI"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[55109] [DM2oFrqU/vk] [aHZ-sfN3hl7mKGp-OjUz2gAAAMI] keep_alive=[0] [2025-07
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2025-07-15 15:41:09
(1 year ago)
Remote.CMD.Shell
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2025-07-15 15:19:08
(1 year ago)
PHP CGI-bin vulnerability attempt.-95
Web App Attack
๐ฎ๐ฉ
hermawan
2025-07-14 12:18:21
(1 year ago)
[Mon Jul 14 19:15:38.815738 2025] [security2:error] [pid 76652:tid 140272575858368] [client 140.238. ...
show more
[Mon Jul 14 19:15:38.815738 2025] [security2:error] [pid 76652:tid 140272575858368] [client 140.238.175.124:58648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "login" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "69"] [id "448101"] [msg "BAD REQUEST FILENAME - Detected and Blocked"] [data "Matched Data: login found within REQUEST_FILENAME: /fw.login.php request_line = GET /fw.login.php?apikey=%27UNION%20select%201,%27YToyOntzOjM6InVpZCI7czo0OiItMTAwIjtzOjIyOiJBQ1RJVkVfRElSRUNUT1JZX0lOREVYIjtzOjE6IjEiO30=%27; HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/fw.login.php"] [unique_id "aHT06sna7rdlp282mMM51gAAAEI"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[76681] [HPEjnqL3leY] [aHT06sna7rdlp282mMM51gAAAEI] keep_alive=[0] [2025-07-14 19:15:38.815744] [R:aHT06sna7rdlp282mMM51gAAAEI] UA:'Mozilla/5.0 (Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Ge
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-07-14 04:56:56
(1 year ago)
[Mon Jul 14 11:54:21.524389 2025] [security2:error] [pid 443823:tid 140523318789824] [client 140.238 ...
show more
[Mon Jul 14 11:54:21.524389 2025] [security2:error] [pid 443823:tid 140523318789824] [client 140.238.175.124:41820] ModSecurity: Access denied with code 403 (phase 1). Match of "ipMatch 103.166.156.58" against "REMOTE_ADDR" required. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "372"] [id "440006"] [msg "Connection Close Header"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: close found within REMOTE_ADDR: 140.238.175.124 request_line = POST /search/ HTTP/1.1 Request URI RAW = /search/ Request Basename = "] [hostname "staklim-jatim.bmkg.go.id"] [uri "/search/"] [unique_id "aHSNfVreGxIm5rEhN_wqMgAAABM"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[443869] [Eoz4c1zwxp4] [aHSNfVreGxIm5rEhN_wqMgAAABM] keep_alive=[0] [2025-07-14 11:54:21.524397] [R:aHSNfVreGxIm5rEhN_wqMgAAABM] UA:'Mozilla/5.0 (Fedora; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.0' Host:'s
...
show less
Hacking
Web App Attack
Showing 1 to
6
of 6 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: