AbuseIPDB » 212.47.141.136
212.47.141.136 was found in our database!
This IP was reported 10 times. Confidence of
Abuse
is 26% : ?
ISP
Aztelekom LLC
Usage Type
Fixed Line ISP
ASN
AS8814
Domain Name
aztelekom.az
Country
π¦πΏ
Azerbaijan
City
Haji Zeynalabdin, Sumqayit
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 212.47.141.136 :
This IP address has been reported a total of
10
times from
8 distinct
sources.
212.47.141.136 was first reported on
January 13th 2021 , and the most recent report was
3 days ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
πͺπΈ
alferez
2026-07-27 14:17:50
(3 days ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 13:49:49
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 212.47.141.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 212.47.141.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 09:49:42.957787 2026] [security2:error] [pid 704566:tid 704566] [client 212.47.141.136:1842] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 212.47.141.136 (+1 hits since last alert)|newcitypark.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "newcitypark.com"] [uri "/xmlrpc.php"] [unique_id "amdh9jzK85WDMWzYZhcQewAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 12:46:20
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 212.47.141.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 212.47.141.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 08:46:16.470507 2026] [security2:error] [pid 3886173:tid 3886173] [client 212.47.141.136:1818] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 212.47.141.136 (+1 hits since last alert)|fractalsky.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fractalsky.com"] [uri "/xmlrpc.php"] [unique_id "amdTGKpTZMRNMTo5oM3n8AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 11:17:19
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 212.47.141.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 212.47.141.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 07:17:12.888453 2026] [security2:error] [pid 1891201:tid 1891218] [client 212.47.141.136:7317] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 212.47.141.136 (+1 hits since last alert)|chelseyrae.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "chelseyrae.com"] [uri "/xmlrpc.php"] [unique_id "amc-ONjaO9OCNab2YGvswgAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
Nick Lewis
2026-07-27 10:40:18
(3 days ago)
(wordpress) Failed wordpress login from 212.47.141.136 (AZ/Azerbaijan/-)
Brute-Force
πΊπΈ
kosada.com
2026-06-29 10:43:46
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
Anonymous
2025-11-25 16:47:29
(8 months ago)
scanning http requests from known botnet
Web App Attack
π©πͺ
botreporter
2025-03-20 07:48:15
(1 year ago)
botnet ignoring robots.txt
Bad Web Bot
πΊπΈ
DiodeDave
2023-10-30 18:35:29
(2 years ago)
Multiple sign in attempts from blocked location
Hacking
π©πͺ
www.blocklist.de
2021-01-13 08:05:08
(5 years ago)
Lines containing failures of 212.47.141.136 (max 1000)
Jan 13 13:49:21 seraph sshd[17036]: Did not r ...
show more
Lines containing failures of 212.47.141.136 (max 1000)
Jan 13 13:49:21 seraph sshd[17036]: Did not receive identification string from 212.47.141.136 port 26998
Jan 13 13:53:39 seraph sshd[17990]: Invalid user default from 212.47.141.136 port 42125
Jan 13 13:53:39 seraph sshd[17990]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=212.47.141.136
Jan 13 13:53:41 seraph sshd[17990]: Failed password for invalid user default from 212.47.141.136 port 42125 ssh2
Jan 13 13:53:41 seraph sshd[17990]: Connection closed by invalid user default 212.47.141.136 port 42125 [preauth]
........
-----------------------------------------------
https://www.blocklist.de/en/view.html?ip=212.47.141.136
show less
FTP Brute-Force
Hacking
Showing 1 to
10
of 10 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown π©
Recently Reported IPs: