This IP address has been reported a total of
12
times from
9 distinct
sources.
125.166.0.242 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 1
report;
Indonesia
with 1
report;
United States of America
with 1
report.
The most common categories in these recent reports were:
DDoS Attack
2
times;
Web App Attack
1
time;
Bad Web Bot
1
time;
Email Spam
1
time;
Hacking
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[Sat Mar 22 21:33:30.649814 2025] [security2:error] [pid 220605:tid 140431905470144] [client 125.166 ...
show more[Sat Mar 22 21:33:30.649814 2025] [security2:error] [pid 220605:tid 140431905470144] [client 125.166.0.242:28533] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<(?:a|abbr|acronym|address|applet|area|audioscope|b|base|basefront|bdo|bgsound|big|blackface|blink|blockquote|body|bq|br|button|caption|center|cite|code|col|colgroup|comment|dd|del|dfn|dir|div|dl|dt|em|embed|fieldset|fn|font|form|frame|frameset|h1|head ..." at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.10.0/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "1872"] [id "941321"] [msg "Possible XSS Attack Detected - HTML Tag Handler"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: <link found within REQUEST_FILENAME: /index.php/component/tags/tag/<link rel= request_line = GET /index.php/component/tags/tag/%3Clink%20rel= HTTP/2.0 Request URI RAW = /index.php/component/tags/tag/%3Clink%20rel= Request Basename = <link rel="] [seve
...
show less
[Mon Feb 24 11:20:14.428954 2025] [security2:error] [pid 896015:tid 140114402469568] [client 125.166 ...
show more[Mon Feb 24 11:20:14.428954 2025] [security2:error] [pid 896015:tid 140114402469568] [client 125.166.0.242:22575] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "ms" at REQUEST_HEADERS:Accept-Language. [file "/etc/modsecurity/coreruleset-4.10.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "189"] [id "440001"] [msg "Seperti Ddos bahasa Rusia ada di ip vietnam 2.59.0.188 "] [data "Matched Data: ms found within REQUEST_HEADERS:Accept-Language: en-US,en;q=0.9,id;q=0.8,ms;q=0.7 request_line = GET /images/Klimatologi/Prakiraan/03-Prakiraan-Bulanan/Prakiraan_Curah_Hujan_Bulanan/Prakiraan_Curah_Hujan_Bulanan_Provinsi_Jawa_Timur/2024/05_Mei_2024/01_Prakiraan_Curah_Hujan_Bulan_JULI_2024_di_Provinsi_Jawa_Timur-Update_dari_Analisis_Bulan_Mei_2024.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Prakiraan/03-Prakiraan-Bulanan/Prakiraan_Curah_Hujan_Bulanan/Prakiraan_Curah_Hujan_Bulanan_Provinsi_Jawa_Timur/2024/05_Mei_2024/0
...
show less