This IP address has been reported a total of
4
times from
2 distinct
sources.
112.215.172.200 was first reported on
February 5th 2024 , and the most recent report was
1 week ago .
In the last 60 days, the only reporter location was:
Switzerland
with 1
report.
The most common categories in these recent reports were:
Exploited Host
1
time;
DDoS Attack
1
time.
Old Reports
The most recent abuse report for this IP address is from
1 week ago . It is possible that this IP is no
longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐จ๐ญ
ALPHANET
2026-10-02 01:30:13
(1 week ago)
Botnet or web spider not respecting robots.txt
DDoS Attack
Exploited Host
๐ฎ๐ฉ
hermawan
2026-05-24 06:09:51
(4 months ago)
05/24/2026-13:09:48.385843 [Drop] [**] [1:3100029454:0] Suricata match TLS ja3 scan Uniq Zeek no 29 ...
show more
05/24/2026-13:09:48.385843 [Drop] [**] [1:3100029454:0] Suricata match TLS ja3 scan Uniq Zeek no 29454 with hash_aa50c12a5dfa717d9d6ab34e97de79d5 [**] [Classification: (null)] [Priority: 3] {TCP} 112.215.172.200:40101 -> 103.166.156.58:443
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2024-02-06 09:24:55
(2 years ago)
[Tue Feb 06 16:24:53.143396 2024] [security2:error] [pid 916759:tid 131491904357952] [client 112.215 ...
show more
[Tue Feb 06 16:24:53.143396 2024] [security2:error] [pid 916759:tid 131491904357952] [client 112.215.172.200:33996] [client 112.215.172.200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "okhttp" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "12"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: okhttp found within REQUEST_HEADERS:User-Agent: okhttp/2.5.0 request_line = GET /favicon.ico HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/favicon.ico"] [unique_id "ZcH65ZPm65gRIp9a20-6GAAArwQ"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[916764] [elqQJpM5SAI] [ZcH65ZPm65gRIp9a20-6GAAArwQ] keep_alive=[1] [2024-02-06 16:24:53.143399] [R:ZcH65ZPm65gRIp9a20-6GAAArwQ] UA:'okhttp/2.5.0' Host:'staklim-jatim.bmkg.go.id' Accept-Encoding:'gzip
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2024-02-05 21:14:25
(2 years ago)
[Tue Feb 06 04:14:22.291279 2024] [security2:error] [pid 242261:tid 128518832784960] [client 112.215 ...
show more
[Tue Feb 06 04:14:22.291279 2024] [security2:error] [pid 242261:tid 128518832784960] [client 112.215.172.200:34028] [client 112.215.172.200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "okhttp" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "12"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: okhttp found within REQUEST_HEADERS:User-Agent: okhttp/2.5.0 request_line = GET /favicon.ico HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/favicon.ico"] [unique_id "ZcFPrmp8Ip6s1uAaAC9gbwABawU"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[242267] [3iUT8kAyeoI] [ZcFPrmp8Ip6s1uAaAC9gbwABawU] keep_alive=[1] [2024-02-06 04:14:22.291283] [R:ZcFPrmp8Ip6s1uAaAC9gbwABawU] UA:'okhttp/2.5.0' Host:'staklim-jatim.bmkg.go.id' Accept-Encoding:'gzip
...
show less
Hacking
Web App Attack
Showing 1 to
4
of 4 reports