This IP address has been reported a total of
7
times from
7 distinct
sources.
102.215.249.52 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Indonesia
with 1
report;
Russian Federation
with 1
report.
The most common categories in these recent reports were:
Hacking
2
times;
Bad Web Bot
1
time;
Email Spam
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[Sun Oct 11 12:20:58.738798 2026] [security2:error] [pid 623350:tid 140630172886720] [client 102.215 ...
show more[Sun Oct 11 12:20:58.738798 2026] [security2:error] [pid 623350:tid 140630172886720] [client 102.215.249.52:0] ModSecurity: Access denied with code 403 (phase 1). Match of "pm matomo.staklim-malang.info " against "SERVER_NAME" required. [file "/etc/modsecurity/coreruleset-4.29.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "224"] [id "440235"] [msg "BAD REQUEST Bro"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: %3a found within SERVER_NAME: staklim-jatim.bmkg.go.id request_line = GET /index.php/profil/arsip-artikel?catid=498&id=1130%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-6-12-september-2016&start=50 HTTP/1.1 Request URI RAW = /index.php/profil/arsip-artikel?catid=498&id=1130%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-6-12-september-2016&sta..."] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/arsip-artikel"] [unique_id "asscuriOQzT
...
show less
Email Spam
Hacking
Anonymous
Large-scale coordinated botnet (5M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/S ...
show moreLarge-scale coordinated botnet (5M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/Shursky [yordim|LIS|MOW]): Retaliation after theft; Attacker: Mikhail Smirnov (mikhail-smirnov-79830323/Aidan [MOW]): Employed by Angara Technologies Group | Catalog Search Abuse Blocked: /catalogsearch/result/?cat=5++&product_vc_mcu=105&product_vc_type=98&q=DVI+104+Tx%2FRx&stock=2 | UA: Mozilla/5.0 (Windows NT 11.0) AppleWebKit/535.2 (KHTML, like Gecko) Chrome/15.0.824.0 Safari/535.2 | (Magento Site)
show less
Hacking
Bad Web Bot
Anonymous
Automated bot traffic โ residential proxy, fake browser fingerprint. UA="Mozilla/5.0 (Windows NT 10. ...
show moreAutomated bot traffic โ residential proxy, fake browser fingerprint. UA="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
show less
(mod_security) mod_security (id:210730) triggered by 102.215.249.52 (-): 1 in the last 300 secs; Por ...
show more(mod_security) mod_security (id:210730) triggered by 102.215.249.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 15:26:10.384287 2026] [security2:error] [pid 3769:tid 3769] [client 102.215.249.52:50452] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bahamascruisersguide.com|F|2"] [data ".greatmysterious.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bahamascruisersguide.com"] [uri "/Blogs-Websites/ www.greatmysterious.com"] [unique_id "aZtmYgDPw4JXP3XkBPx9QwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
scanning http requests from known botnet
Web App Attack
Anonymous
High-volume requests from many IP-addresses to similar non-existent URLs indicating distributed deni ...
show moreHigh-volume requests from many IP-addresses to similar non-existent URLs indicating distributed denial-of-service (DDoS) activity against website.
show less
DDoS Attack
Anonymous
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.25 is noted in report tim ...
show moreAttempted brute force login to web vpn 2 time(s); last attempt for 2025.10.25 is noted in report timestamp
show less
Hacking
Brute-Force
Showing 1 to
7
of 7 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ