AbuseIPDB » 180.243.3.180
180.243.3.180 was found in our database!
This IP was reported 7 times. Confidence of
Abuse
is 18% : ?
ISP
PT TELKOM INDONESIA
Usage Type
Fixed Line ISP
ASN
AS7713
Domain Name
telkom.co.id
Country
๐ฎ๐ฉ
Indonesia
City
Pasarkemis, West Java
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 180.243.3.180 :
This IP address has been reported a total of
7
times from
6 distinct
sources.
180.243.3.180 was first reported on
November 29th 2021 , and the most recent report was
23 hours ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
2026-07-27 10:09:27
(23 hours ago)
[redacted] 180.243.3.180 - - [27/Jul/2026:12:08:44 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "J ...
show more
[redacted] 180.243.3.180 - - [27/Jul/2026:12:08:44 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Jetpack/12.1; WordPress/6.2; http://site80963656.com"
[redacted] 180.243.3.180 - - [27/Jul/2026:12:08:54 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
[redacted] 180.243.3.180 - - [27/Jul/2026:12:09:05 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
[redacted] 180.243.3.180 - - [27/Jul/2026:12:09:16 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "WordPress.com; https://wordpress.com"
[redacted] 180.243.3.180 - - [27/Jul/2026:12:09:26 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.2)"
...
show less
Hacking
Web App Attack
Anonymous
2026-07-27 05:08:53
(1 day ago)
Fail2ban filtered
...
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-06-06 00:00:39
(1 month ago)
SIMASN Account Signin during non bussiness hour.. Threat Score: 8/10 (CRITICAL). Confidence: 60%. CV ...
show more
SIMASN Account Signin during non bussiness hour.. Threat Score: 8/10 (CRITICAL). Confidence: 60%. CVSS v3.1: 7.3/10 (High). CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 97%. MITRE ATT&CK: T1071 (Application Layer Protocol). Tactic: TA0001. Freshness: Fresh. Source Reputation: SUSPICIOUS. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-06-05 23:00:11
(1 month ago)
SIMASN Account Signin during non bussiness hour.. Threat Score: 6.8/10 (MEDIUM). Reported by Tangera ...
show more
SIMASN Account Signin during non bussiness hour.. Threat Score: 6.8/10 (MEDIUM). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
Anonymous
2025-06-03 00:44:49
(1 year ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐ฎ๐ฉ
hermawan
2025-05-22 06:22:10
(1 year ago)
[Thu May 22 13:21:24.625149 2025] [security2:error] [pid 556743:tid 140244364904128] [client 180.243 ...
show more
[Thu May 22 13:21:24.625149 2025] [security2:error] [pid 556743:tid 140244364904128] [client 180.243.3.180:38448] ModSecurity: Access denied with code 403 (phase 1). Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:_ga_93YCVS3TYV. [file "/etc/modsecurity/coreruleset-4.14.0/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "4625"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (8)"] [data "Matched Data: $o1$g0$t1747894883$j60$l0$h0$dEAX09qwjnm4HuzSSamr6Qwk6X3- found within REQUEST_COOKIES:_ga_93YCVS3TYV: GS2.1.s1747894883$o1$g0$t1747894883$j60$l0$h0$dEAX09qwjnm4HuzSSamr6Qwk6X3-Y1dQjpw"] [severity "WARNING"] [ver "OWASP_CRS/4.14.0"] [tag "application-multi"] [tag "language-multi"] [tag "platfo
...
show less
Hacking
Web App Attack
๐บ๐ธ
Hostlux LLC
2021-11-29 01:35:29
(4 years ago)
180.243.3.180 triggered Icarus honeypot on port 445. Check us out on github.
Port Scan
Hacking
Showing 1 to
7
of 7 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: