AbuseIPDB » 147.90.170.239
147.90.170.239 was found in our database!
This IP was reported 4 times. Confidence of
Abuse
is 20% : ?
ISP
VPN Consumer Macao, SAR
Usage Type
Data Center/Web Hosting/Transit
ASN
AS137409
Domain Name
vpnconsumer.com
Country
๐ธ๐ฌ
Singapore
City
Kampong Loyang
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 147.90.170.239 :
This IP address has been reported a total of
4
times from
3 distinct
sources.
147.90.170.239 was first reported on
August 20th 2026 , and the most recent report was
2 days ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ซ๐ท
dynamix
2026-08-25 03:39:48
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
macrob
2026-08-22 06:17:48
(5 days ago)
2026/08/22 06:17:47 [error] 2660803#2660803: *506962977 access forbidden by rule, client: 147.90.170 ...
show more
2026/08/22 06:17:47 [error] 2660803#2660803: *506962977 access forbidden by rule, client: 147.90.170.239, server: finami.com.ua, request: "GET /wp-content/themes/theme-check/main.php HTTP/1.1", host: "www.finami.com.ua"
2026/08/22 06:17:47 [error] 2660803#2660803: *506962992 access forbidden by rule, client: 147.90.170.239, server: finami.com.ua, request: "GET /wp-content/plugins/advanced-product-fields-for-woocommerce/db.php HTTP/1.1", host: "www.finami.com.ua"
2026/08/22 06:17:47 [error] 2660803#2660803: *506963001 access forbidden by rule, client: 147.90.170.239, server: finami.com.ua, request: "GET /wp-includes/blocks/nextpage/index.php HTTP/1.1", host: "www.finami.com.ua"
...
show less
Web App Attack
๐ฌ๐ท
setupgr
2026-08-20 15:14:27
(6 days ago)
(mod_security) mod_security (id:1000001) triggered by 147.90.170.239 (CN/China/Gansu/Lanzhou/-/[AS13 ...
show more
(mod_security) mod_security (id:1000001) triggered by 147.90.170.239 (CN/China/Gansu/Lanzhou/-/[AS137409 GSLNETWORKS-AS-AP GSL Networks Pty LTD]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Aug 20 18:14:22.668747 2026] [security2:error] [pid 3270:tid 3427] [client 147.90.170.239:35527] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/db.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "103"] [id "1000001"] [msg "Bad file blocked: /wp-content/plugins/seoplugins/db.php"] [severity "CRITICAL"] [tag "security"] [hostname "sea-sound.com"] [uri "/wp-content/plugins/seoplugins/db.php"] [unique_id "aocZzpsl4erg_rzjDO8HLgAABBA"]
show less
Port Scan
๐ซ๐ท
dynamix
2026-08-20 04:03:35
(1 week ago)
Multiple WAF Violations
Web App Attack
Showing 1 to
4
of 4 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: