AbuseIPDB » 138.94.219.216
138.94.219.216 was found in our database!
This IP was reported 4 times. Confidence of
Abuse
is 4% : ?
ISP
Philadelphia PA
Usage Type
Data Center/Web Hosting/Transit
ASN
AS263744
Domain Name
udasha.com
Country
๐บ๐ธ
United States of America
City
New York City, New York
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 138.94.219.216 :
This IP address has been reported a total of
4
times from
1 distinct
source.
138.94.219.216 was first reported on
March 24th 2026 , and the most recent report was
3 hours ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ฎ๐ฉ
hermawan
2026-06-22 10:49:11
(3 hours ago)
Captured JA4H: ge20n_0755824e4aff | Log: 138.94.219.216 - - [22/Jun/2026:17:48:36 +0700] "GET /index ...
show more
Captured JA4H: ge20n_0755824e4aff | Log: 138.94.219.216 - - [22/Jun/2026:17:48:36 +0700] "GET /index.php/prediksi-iklim/prediksi-dasarian/deterministik-curah-hujan-provinsi-jawa-timur HTTP/2.0" 200 28345 "-" "Mozilla/5.0 (Linux; Android 14; SM-A102U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.6045.66 Mobile Safari/537.36" ge20n_sec-ch-ua,sec-ch-ua-mobile,sec-ch-ua-platform,upgrade-insecure-requests,user-agent,accept,sec-fetch-site,sec-fetch-mode,sec-fetch-user,sec-fetch-dest,accept-encoding,accept-language,save-data,host...
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-06-01 06:46:31
(3 weeks ago)
[Mon Jun 01 13:46:23.966166 2026] [security2:error] [pid 1692871:tid 140650101073600] [client 138.94 ...
show more
[Mon Jun 01 13:46:23.966166 2026] [security2:error] [pid 1692871:tid 140650101073600] [client 138.94.219.216:27844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.yahoo.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.yahoo.go.id found within REQUEST_HEADERS:Referer: https://www.yahoo.go.id/ request_line = GET /ga-choise-v6.js HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/ga-choise-v6.js"] [unique_id "ah0qv_Jf6vwCNxEkGhRQkAAAAwQ"], referer https://www.yahoo.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[1692876] [NoaFjWuWmNo] [ah0qv_Jf6vwCNxEkGhRQkAAAAwQ] keep_alive=[1] [2026-06-01 13:46:23.966170] [R:ah0qv_Jf6vwCNxEkGhRQkAAAAwQ] UA:'Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/26.0 Chrome/122.0.0.0 Mobile Safari/537.36' Host
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-04-12 22:17:20
(2 months ago)
04/13/2026-04:34:16.811996 [Drop] [**] [1:3100003077:0] Suricata match TLS JA3 scan Uniq Zeek no 30 ...
show more
04/13/2026-04:34:16.811996 [Drop] [**] [1:3100003077:0] Suricata match TLS JA3 scan Uniq Zeek no 3077 with hash_f79b6bad2ad0641e1921aef10262856b [**] [Classification: (null)] [Priority: 3] {TCP} 138.94.219.216:2058 -> 103.166.156.58:443
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-03-24 07:23:03
(2 months ago)
1774336975.927052 Cj6ypl144vp6JWMuYj 138.94.219.216 59418 103.166.156.58 443 tcp - 3.039268 0 0 S0 F ...
show more
1774336975.927052 Cj6ypl144vp6JWMuYj 138.94.219.216 59418 103.166.156.58 443 tcp - 3.039268 0 0 S0 F F 0 S 3 180 0 0 - 6 887168488477278_53 (empty) 64240_2-4-8-1-3_1460_7 (empty) 03/24/2026-14:22:55.927052
...
show less
Email Spam
Hacking
Showing 1 to
4
of 4 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: