This IP address has been reported a total of
13
times from
9 distinct
sources.
181.192.123.30 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
denied traffic to a honeypot network. destination port 15684.
[Fri Apr 17 07:48:20.360346 2026] [security2:error] [pid 162309:tid 140248639358656] [client 181.192 ...
show more[Fri Apr 17 07:48:20.360346 2026] [security2:error] [pid 162309:tid 140248639358656] [client 181.192.123.30:9124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.bmkg.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.25.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "623"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.bmkg.go.id found within REQUEST_HEADERS:Referer: https://www.bmkg.go.id/ request_line = GET /index.php HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php"] [unique_id "aeGDVA2resjV3IYR7nJ4twAACwI"], referer https://www.bmkg.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[162359] [OikeTt1OejU] [aeGDVA2resjV3IYR7nJ4twAACwI] keep_alive=[1] [2026-04-17 07:48:20.360350] [R:aeGDVA2resjV3IYR7nJ4twAACwI] UA:'Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Mobile Safari/537.36 EdgA/131.0.0.0' Host:'staklim-jatim.bmkg.go.
...
show less
Email Spam
Hacking
Anonymous
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show moreDistributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in thread-post.asp
show less
(mod_security) mod_security (id:210730) triggered by 181.192.123.30 (30-123-192-181.rev.egtechteleco ...
show more(mod_security) mod_security (id:210730) triggered by 181.192.123.30 (30-123-192-181.rev.egtechtelecom.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 15 22:33:52.697181 2025] [security2:error] [pid 6382:tid 6382] [client 181.192.123.30:35043] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||instituteofscience.com|F|2"] [data ".instituteofscience.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "instituteofscience.com"] [uri "/www.instituteofscience.com"] [unique_id "aRlGIFWoh9-uLu5dklHEAgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
scanning http requests from known botnet
Web App Attack
Anonymous
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show moreDistributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in thread-skip.asp
show less
Bad Web Bot
Exploited Host
Anonymous
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show moreDistributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in thread-skip.asp
show less
Bad Web Bot
Exploited Host
Anonymous
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.09.25 is noted in report tim ...
show moreAttempted brute force login to web vpn 1 time(s); last attempt for 2025.09.25 is noted in report timestamp
show less
Participating in DDoS Amplification Attack! Sending 14 requests over 52926s asking for ?0? of atlass ...
show moreParticipating in DDoS Amplification Attack! Sending 14 requests over 52926s asking for ?0? of atlassian.com, apple.com, cisco.com
show less
DNS Poisoning
DDoS Attack
Hacking
Brute-Force
Exploited Host
Participating in DDoS Amplification Attack! Sending 15 requests over 29312s asking for ?0? of apple. ...
show moreParticipating in DDoS Amplification Attack! Sending 15 requests over 29312s asking for ?0? of apple.com, cisco.com, atlassian.com
show less
DNS Poisoning
DDoS Attack
Hacking
Brute-Force
Exploited Host
Showing 1 to
13
of 13 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown 🚩