AbuseIPDB » 103.191.58.198
103.191.58.198 was found in our database!
This IP was reported 7 times. Confidence of
Abuse
is 0% : ?
ISP
PT Panjalu Sarana Data Indonesia
Usage Type
Fixed Line ISP
ASN
AS149909
Domain Name
panjalu.co.id
Country
๐ฎ๐ฉ
Indonesia
City
Gampengrejo, East Java
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 103.191.58.198 :
This IP address has been reported a total of
7
times from
6 distinct
sources.
103.191.58.198 was first reported on
July 13th 2024 , and the most recent report was
1 year ago .
Old Reports:
The most recent abuse report for this IP address is from
1 year ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐จ๐ฆ
TCP FAILED
2025-06-20 16:53:55
(1 year ago)
TCP Watch Auto Report: Detected a ddos attack and suspicious activity from this IP, indicating a pot ...
show more
TCP Watch Auto Report: Detected a ddos attack and suspicious activity from this IP, indicating a potential attack
show less
DDoS Attack
Hacking
IoT Targeted
๐ฌ๐ง
SuperEvilLuke
2025-06-18 19:39:56
(1 year ago)
Malicious activity detected from 149909 IDNIC-PANJALU-AS-ID PT Panjalu Sarana Data Indonesia towards ...
show more
Malicious activity detected from 149909 IDNIC-PANJALU-AS-ID PT Panjalu Sarana Data Indonesia towards host client.embotic.xyz (GET HTTP/2) @ 2025-06-18T19:39:56Z (8 occurrences)
show less
DDoS Attack
๐ฆ๐บ
MAGIC
2025-06-14 15:01:34
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฉ๐ช
Packets-Decreaser.NET
2025-06-13 11:53:18
(1 year ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐ฎ๐ฉ
hermawan
2025-04-27 21:45:56
(1 year ago)
[Mon Apr 28 04:45:55.307517 2025] [security2:error] [pid 195243:tid 140152970147520] [client 103.191 ...
show more
[Mon Apr 28 04:45:55.307517 2025] [security2:error] [pid 195243:tid 140152970147520] [client 103.191.58.198:33694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "WOW64" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.13.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "204"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: WOW64 found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36 request_line = GET /index.php/profil/meteorologi/geofisika/4209-gempa-terkini HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/geofisika/4209-gempa-terkini"] [unique_id "aA6lk531hhVLctJqTeI1XQAAAJU"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[195316] [Dv74fdEsQzw] [aA6lk531hhVLctJqTeI1XQAAAJU] keep_alive=[0] [2025-04-28 04:45:55.307521] [R:aA6lk531hhVLctJqTeI1XQAAAJU] UA:
...
show less
Hacking
Web App Attack
Anonymous
2025-02-11 08:44:49
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฎ๐ฉ
hermawan
2024-07-13 11:43:51
(1 year ago)
[Sat Jul 13 18:35:53.902586 2024] [security2:error] [pid 147201:tid 130917618157120] [client 103.191 ...
show more
[Sat Jul 13 18:35:53.902586 2024] [security2:error] [pid 147201:tid 130917618157120] [client 103.191.58.198:39646] [client 103.191.58.198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "zh-CN" at REQUEST_HEADERS:Accept-Language. [file "/etc/modsecurity/coreruleset-4.3.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "41"] [id "440001"] [msg "Seperti Ddos bahasa Rusia ada di ip vietnam 2.59.0.188 "] [data "Matched Data: zh-CN found within REQUEST_HEADERS:Accept-Language: id,en-US;q=0.9,en;q=0.8,zh-CN;q=0.7,zh;q=0.6,ms;q=0.5 request_line = GET /index.php/profil/meteorologi/list-of-all-tags/prakiraan-cuaca-kediri HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-of-all-tags/prakiraan-cuaca-kediri"] [unique_id "ZpJmmUGx2JlECT5mSXwZGwACTQQ"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[147206] [lDoQZq8mgP0] [ZpJmmUGx2JlECT5mSXwZGwACTQQ] keep_alive=[1] [2024-07-13 18:35:53.902592] [R:ZpJmmUGx2
...
show less
Hacking
Web App Attack
Showing 1 to
7
of 7 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: