This IP address has been reported a total of
14
times from
8 distinct
sources.
192.140.21.48 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
denied traffic to a honeypot network. destination port 18115.
[Fri May 29 07:53:39.610577 2026] [security2:error] [pid 1173978:tid 139852129625792] [client 192.14 ...
show more[Fri May 29 07:53:39.610577 2026] [security2:error] [pid 1173978:tid 139852129625792] [client 192.140.21.48:5433] ModSecurity: Access denied with code 403 (phase 1). Match of "eq 0" against "&REQUEST_HEADERS:Transfer-Encoding" required. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "815"] [id "920171"] [msg "GET or HEAD Request with Transfer-Encoding"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: GET found within REQUEST_HEADERS: 1 request_line = GET /index.php/analisis-iklim/analisis-bulanan/analisis-distribusi-hujan/analisis-distribusi-curah-hujan HTTP/2.0 Request URI RAW = /index.php/analisis-iklim/analisis-bulanan/analisis-distribusi-hujan/analisis-distribusi-curah-hujan Request Basename = analisis-distribusi-curah-hujan"] [severity "CRITICAL"] [ver "OWASP_CRS/4.26.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [ta
...
show less
Email Spam
Hacking
Anonymous
scanning http requests from known botnet
Web App Attack
Anonymous
Distributed web crawl (like Mellowtel), likely illicit scraping of AI training data to bypass firewa ...
show moreDistributed web crawl (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions (/forums/forums/thread-post.asp?action=reply&replyto=9897%22e%3Dyes)
show less
Participating in DDoS Amplification Attack! Sending 15 requests over 652s asking for ?0? of cisco.co ...
show moreParticipating in DDoS Amplification Attack! Sending 15 requests over 652s asking for ?0? of cisco.com, atlassian.com, apple.com
show less
DNS Poisoning
DDoS Attack
Hacking
Brute-Force
Exploited Host
Participating in DDoS Amplification Attack! Sending 39 requests over 43320s asking for ?0? of apple. ...
show moreParticipating in DDoS Amplification Attack! Sending 39 requests over 43320s asking for ?0? of apple.com, cisco.com, atlassian.com
show less
DNS Poisoning
DDoS Attack
Hacking
Brute-Force
Exploited Host
Participating in DDoS Amplification Attack! Sending 61 requests over 67395s asking for ?0? of cisco. ...
show moreParticipating in DDoS Amplification Attack! Sending 61 requests over 67395s asking for ?0? of cisco.com, atlassian.com, apple.com
show less
DNS Poisoning
DDoS Attack
Hacking
Brute-Force
Exploited Host
Participating in DDoS Amplification Attack! Sending 11 requests over 6800s asking for ?0? of cisco.c ...
show moreParticipating in DDoS Amplification Attack! Sending 11 requests over 6800s asking for ?0? of cisco.com, atlassian.com, apple.com
show less
DNS Poisoning
DDoS Attack
Hacking
Brute-Force
Exploited Host
Showing 1 to
14
of 14 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ