This IP address has been reported a total of
10
times from
7 distinct
sources.
103.172.120.29 was first reported on
June 17th 2024 , and the most recent report was
9 hours ago .
In the last 60 days, the top reporter locations were:
Germany
with 1
report;
Poland
with 1
report.
The most common categories in these recent reports were:
Bad Web Bot
1
time;
SSH
1
time;
Port Scan
1
time;
Brute-Force
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ต๐ฑ
MatStef132
2026-09-25 00:43:48
(9 hours ago)
MatShield L7: blocked on test-clean.mathost.eu (ua-quarantined)
Bad Web Bot
๐ฉ๐ช
ghostwarriors
2026-09-24 12:20:25
(22 hours ago)
Unauthorized connection attempt detected, SSH Brute-Force
Brute-Force
Port Scan
SSH
๐ฆ๐บ
MAGIC
2025-12-04 03:11:58
(9 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2025-11-25 22:09:21
(9 months ago)
scanning http requests from known botnet
Web App Attack
Anonymous
2025-11-17 16:55:24
(10 months ago)
scanning http requests from known botnet
Web App Attack
๐ฎ๐ฉ
hermawan
2025-10-24 06:30:56
(11 months ago)
[Fri Oct 24 13:27:19.822733 2025] [security2:error] [pid 2502291:tid 139970401441472] [client 103.17 ...
show more
[Fri Oct 24 13:27:19.822733 2025] [security2:error] [pid 2502291:tid 139970401441472] [client 103.172.120.29:55710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".webm" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "69"] [id "448101"] [msg "BAD REQUEST FILENAME - Detected and Blocked"] [data "Matched Data: .webm found within REQUEST_FILENAME: /images/Klimatologi/Prakiraan/04_Prakiraan_6_Bulanan/Prakiraan_Musim/Prakiraan_Musim_Hujan/Provinsi_Jawa_Timur/2019-2020/Video_Peta_Prakiraan_Curah_Hujan_Musim_Hujan_Tahun_2019-2020_Zona_Musim_di_Provinsi_Jawa_Timur.webm request_line = GET /images/Klimatologi/Prakiraan/04_Prakiraan_6_Bulanan/Prakiraan_Musim/Prakiraan_Musim_Hujan/Provinsi_Jawa_Timur/2019-2020/Video_Peta_Prakiraan_Curah_Hujan_Musim_Hujan_Tahun_2019-2020_Zona_Musim_di_Provinsi_Jawa_Timur.we..."] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Prakiraan/04_Pr
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-10-20 22:03:57
(11 months ago)
[Tue Oct 21 05:03:11.774531 2025] [security2:error] [pid 588893:tid 140228055434944] [client 103.172 ...
show more
[Tue Oct 21 05:03:11.774531 2025] [security2:error] [pid 588893:tid 140228055434944] [client 103.172.120.29:36510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "HttpClient" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "228"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: HttpClient found within REQUEST_HEADERS:User-Agent: AndroidHttpClient (Linux; U; Android 12; in_ID; Infinix X6515; Build/SP1A.210812.016; Cronet/138.0.7156.0) request_line = GET /images/Klimatologi/Analisis/02-Analisis_Dasarian/Analisis_Distribusi_Curah_Hujan_Dasarian/Analisis_Distribusi_Curah_Hujan_Dasarian_Provinsi_Jawa_Timur/2024/11_November_2024/Das-III/Peta_Analisis-Dasarian_Distribusi_Curah_Hujan_Dasarian_III_November_2024_di_Provinsi_Jawa_Timur.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Analisis/02-Analisis_Dasarian/Analisis_Dist
...
show less
Hacking
Web App Attack
Anonymous
2024-10-20 04:12:33
(1 year ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐บ๐ธ
RAP
2024-06-17 09:50:09
(2 years ago)
2024-06-17 09:50:09 UTC Unauthorized activity to TCP port 445. SMB
Port Scan
Anonymous
2024-06-17 09:30:47
(2 years ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
Showing 1 to
10
of 10 reports