Log in to view charts and search reports for this IP.
Log In
Top Reporter Countries (Last 60 Days)
Example preview
Report Categories (Last 60 Days)
Example preview
Reports Activity
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 138.197.6.243:
This IP address has been reported a total of
20
times from
20 distinct
sources.
138.197.6.243 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 7
reports;
United States of America
with 4
reports;
Australia
with 2
reports.
The most common categories in these recent reports were:
Brute-Force
12
times;
SSH
6
times;
Port Scan
5
times;
Web App Attack
5
times;
Bad Web Bot
4
times;
Other
3
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2026-09-05T22:19:47.571285+02:00 srv postfix/submission/smtpd[486475]: improper command pipelining a ...
show more2026-09-05T22:19:47.571285+02:00 srv postfix/submission/smtpd[486475]: improper command pipelining after CONNECT from unknown[138.197.6.243]: \026\003\001\005\336\001\000\005\332\003\003j\006\320{\310e\365\324\254mE7\361\276Ts\362L\001.\313\b\233(\277O\v\271\036A\224\016 \nH\345\231\3600\020c3\343dT\373\240\343\347j\006<j\310L\336\336\225f\356f\255\2444\354\0002\300+\300/\300,\3000\314\251\314\250\300\t\300\023\300\n\300\024\000\234
2026-09-05T22:19:47.732760+02:00 srv postfix/submission/smtpd[486475]: lost connection after UNKNOWN from unknown[138.197.6.243]
2026-09-05T22:19:48.022169+02:00 srv postfix/submission/smtpd[486475]: lost connection after UNKNOWN from unknown[138.197.6.243]
...
show less
Auto-blocked by Seczar SecureOps — High-Risk Port Probe (admin-managed entries) — MySQL (193 events ...
show moreAuto-blocked by Seczar SecureOps — High-Risk Port Probe (admin-managed entries) — MySQL (193 events in 10min) at 2026-09-05 19:37
show less
2026-09-05T18:42:33.795412 mail2.akcurate.de sshd-session[167289]: Connection closed by 138.197.6.24 ...
show more2026-09-05T18:42:33.795412 mail2.akcurate.de sshd-session[167289]: Connection closed by 138.197.6.243 port 49552 [preauth]
2026-09-05T18:42:35.215689 mail2.akcurate.de sshd-session[167291]: banner exchange: Connection from 138.197.6.243 port 49558: invalid format
2026-09-05T18:42:35.405216 mail2.akcurate.de sshd-session[167292]: banner exchange: Connection from 138.197.6.243 port 49560: invalid format
...
show less
UFW BLOCK Report:
Total attempts: 13
Top ports and details:
- Port 22 (9x): SSH Brute-Force (e ...
show moreUFW BLOCK Report:
Total attempts: 13
Top ports and details:
- Port 22 (9x): SSH Brute-Force (e.g., CVE-2024-6387 regreSSHion, botnets like Mirai, Mozi)
- Port 3306 (4x): MySQL Brute / Exploit (e.g., weak root passwords, authentication bypass CVEs)
Source IP: 138.197.6.243
| this report is autogenerated by ZIME Cloud
show less
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-09-05T13:34:49.475048v22019037947384217 sshd[28190]: Connection closed by 138.197.6.243 port 38 ...
show more2026-09-05T13:34:49.475048v22019037947384217 sshd[28190]: Connection closed by 138.197.6.243 port 38218 [preauth]
2026-09-05T13:35:20.097225v22019037947384217 sshd[28199]: Bad protocol version identification '\026\003\001\005\336\001' from 138.197.6.243 port 46918
2026-09-05T13:35:20.290413v22019037947384217 sshd[28201]: Bad protocol version identification '\026\003\001' from 138.197.6.243 port 46930
...
show less
Brute-Force
SSH
Anonymous
Sep 05 11:34:56 imap-login: Info: Disconnected: Connection closed (no auth attempts in 3 secs): user ...
show moreSep 05 11:34:56 imap-login: Info: Disconnected: Connection closed (no auth attempts in 3 secs): user=<>, rip=138.197.6.243, lip=X.X.X.X, TLS: Connection closed, session=<BJA+xrpawKGKxQbz>
Sep 05 11:35:13 imap-login: Info: Disconnected: Too many invalid commands (no auth attempts in 0 secs): user=<>, rip=138.197.6.243, lip=X.X.X.X, session=</5s8x7paTO2KxQbz>
Sep 05 11:35:13 imap-login: Info: Disconnected: Too many invalid commands (no auth attempts in 0 secs): user=<>, rip=138.197.6.243, lip=X.X.X.X, session=<g7xDx7pauLqKxQbz>
...
show less