AbuseIPDB » 180.254.65.243
180.254.65.243 was found in our database!
This IP was reported 8 times. Confidence of
Abuse
is 14% : ?
ISP
PT TELKOM INDONESIA
Usage Type
Fixed Line ISP
ASN
AS7713
Domain Name
telkom.co.id
Country
๐ฎ๐ฉ
Indonesia
City
Tangerang, Banten
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 180.254.65.243 :
This IP address has been reported a total of
8
times from
7 distinct
sources.
180.254.65.243 was first reported on
July 20th 2021 , and the most recent report was
4 hours ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ซ๐ฎ
6kilowatti
2026-07-24 22:42:24
(4 hours ago)
2026-07-25T01:42:23.050983+03:00 mummo kernel: [UFW BLOCK] IN=enp0s25 OUT= MAC=6c:62:6d:d6:a5:bc:00: ...
show more
2026-07-25T01:42:23.050983+03:00 mummo kernel: [UFW BLOCK] IN=enp0s25 OUT= MAC=6c:62:6d:d6:a5:bc:00:00:5e:00:01:58:08:00 SRC=180.254.65.243 DST=83.148.240.21 LEN=44 TOS=0x00 PREC=0x00 TTL=244 ID=58710 DF PROTO=TCP SPT=60790 DPT=23 WINDOW=65535 RES=0x00 SYN URGP=0
...
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-06 07:50:09
(2 weeks ago)
(mod_security) mod_security (id:211180) triggered by 180.254.65.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211180) triggered by 180.254.65.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 06 03:50:01.803635 2026] [security2:error] [pid 18943:tid 18943] [client 180.254.65.243:49313] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "50"] [id "211180"] [rev "3"] [msg "COMODO WAF: Session Fixation: SessionID Parameter Name with No Referer||www.etransfer.com|F|2"] [data "Matched Data: cftoken found within REQUEST_HEADERS: 0"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.etransfer.com"] [uri "/index.cfm"] [unique_id "akteKWgHnX_LPoMpv3W-IQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-01-25 20:00:17
(5 months ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-01-25 19:00:02
(5 months ago)
CRITICAL: Privileged access during non-business hours - Jakarta timezone (WIB). Threat Score: 7.9/10 ...
show more
CRITICAL: Privileged access during non-business hours - Jakarta timezone (WIB). Threat Score: 7.9/10 (HIGH). CVSS: 7/10 (High). Bayesian: 87%. MITRE: T1190. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
Anonymous
2025-09-20 02:22:54
(10 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐ฆ๐บ
crispi
2023-05-19 01:50:40
(3 years ago)
Unauthorized connection attempt detected from IP address 180.254.65.243 to TCP port 445
Port Scan
Anonymous
2022-01-16 14:01:52
(4 years ago)
Attacks websites by trying to access known vulnerables of plugins, brute-force of backends or probin ...
show more
Attacks websites by trying to access known vulnerables of plugins, brute-force of backends or probing of administrative tools
show less
Brute-Force
Web App Attack
๐ฉ๐ช
ManagedStack
2021-07-20 11:11:03
(5 years ago)
Unauthorized path/IP Access (full log not revealed as it contains sensitive data)
Hacking
Web App Attack
Showing 1 to
8
of 8 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: