AbuseIPDB » 140.245.56.99
140.245.56.99 was found in our database!
This IP was reported 6 times. Confidence of
Abuse
is 33% : ?
ISP
Oracle Corporation
Usage Type
Data Center/Web Hosting/Transit
ASN
AS31898
Domain Name
oracle.com
Country
πΈπ¬
Singapore
City
Singapore
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 140.245.56.99 :
This IP address has been reported a total of
6
times from
5 distinct
sources.
140.245.56.99 was first reported on
July 27th 2026 , and the most recent report was
1 hour ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
π±πΉ
NotACaptcha
2026-07-27 08:06:08
(1 hour ago)
webserver:443 [27/Jul/2026] "GET /xmlrpc.php HTTP/1.1" 404 463 "-" "Mozilla/5.0 (Windows NT 10.0; W ...
show more
webserver:443 [27/Jul/2026] "GET /xmlrpc.php HTTP/1.1" 404 463 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
webserver:443 [27/Jul/2026] "POST /xmlrpc.php HTTP/1.1" 404 5772 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 07:54:39
(1 hour ago)
(mod_security) mod_security (id:240335) triggered by 140.245.56.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 140.245.56.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 03:54:31.720106 2026] [security2:error] [pid 11768:tid 11768] [client 140.245.56.99:57756] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 140.245.56.99 (+1 hits since last alert)|ashleycroft.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ashleycroft.com"] [uri "/xmlrpc.php"] [unique_id "amcOt7UI3iuBwBJsB7x-WQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-27 07:17:11
(2 hours ago)
140.245.56.99 - - [27/Jul/2026:07:17:11 +0000] "POST /xmlrpc.php HTTP/1.1" 404 4054 "-" "Mozilla/5.0 ...
show more
140.245.56.99 - - [27/Jul/2026:07:17:11 +0000] "POST /xmlrpc.php HTTP/1.1" 404 4054 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 07:13:14
(2 hours ago)
(mod_security) mod_security (id:240335) triggered by 140.245.56.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 140.245.56.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 03:13:07.412625 2026] [security2:error] [pid 11856:tid 11856] [client 140.245.56.99:60148] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 140.245.56.99 (+1 hits since last alert)|ashwoodsecurity.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ashwoodsecurity.com"] [uri "/xmlrpc.php"] [unique_id "amcFA4GHcJB1t30iUXclygAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
masterguru
2026-07-27 06:43:21
(3 hours ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (5000900-122)
Web App Attack
π¬π·
setupgr
2026-07-27 06:23:11
(3 hours ago)
(XMLRPC) WP XMLRPC Attack 140.245.56.99 (SG/Singapore/-/Singapore (Jurong East)/-/[AS31898 ORACLE-BM ...
show more
(XMLRPC) WP XMLRPC Attack 140.245.56.99 (SG/Singapore/-/Singapore (Jurong East)/-/[AS31898 ORACLE-BMC-31898]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 140.245.56.99 - - [27/Jul/2026:09:14:37 +0300] "POST /xmlrpc.php HTTP/1.1" 503 7310 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
show less
Port Scan
Showing 1 to
6
of 6 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown π©
Recently Reported IPs: