AbuseIPDB » 185.127.70.28
185.127.70.28 was found in our database!
This IP was reported 6 times. Confidence of
Abuse
is 4% : ?
ISP
Indert Connection LP
Usage Type
Fixed Line ISP
ASN
AS203443
Domain Name
indertconnection.com
Country
๐ฌ๐ง
United Kingdom of Great Britain and Northern Ireland
City
London, England
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 185.127.70.28 :
This IP address has been reported a total of
6
times from
1 distinct
source.
185.127.70.28 was first reported on
May 16th 2026 , and the most recent report was
2 days ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ฎ๐ฉ
hermawan
2026-06-18 12:05:52
(2 days ago)
[Thu Jun 18 19:05:47.985345 2026] [security2:error] [pid 447893:tid 140711060993728] [client 185.127 ...
show more
[Thu Jun 18 19:05:47.985345 2026] [security2:error] [pid 447893:tid 140711060993728] [client 185.127.70.28:14240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.yandex.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.yandex.go.id found within REQUEST_HEADERS:Referer: https://www.yandex.go.id/ request_line = GET /index.php/prediksi-iklim/prediksi-dasarian/probabilistik-curah-hujan-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prediksi-iklim/prediksi-dasarian/probabilistik-curah-hujan-provinsi-jawa-timur"] [unique_id "ajPfG4aHcAcT4s4GhoD4AAABgRg"], referer https://www.yandex.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[447918] [4aIc/0XQXvs] [ajPfG4aHcAcT4s4GhoD4AAABgRg] keep_alive=[1] [2026-06-18 19:05:47.985352] [R:ajPfG4aHcAcT4s4GhoD4AAA
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-06-07 08:19:11
(2 weeks ago)
[Sun Jun 07 15:19:10.545422 2026] [security2:error] [pid 820894:tid 140593670829760] [client 185.127 ...
show more
[Sun Jun 07 15:19:10.545422 2026] [security2:error] [pid 820894:tid 140593670829760] [client 185.127.70.28:46464] ModSecurity: Access denied with code 403 (phase 1). Match of "pm www.office.com powerpoint.officeapps.live.com /offline-service-worker-19-02-2025.js /offline-service-worker-27-01-2024-v5-0-1.js /offline-service-worker-01-08-2023-v4-5-1.js /OneSignalSDKWorker.js /worker-analytic-helper-27-11-2022.js/ /worker-analyti ..." against "REQUEST_HEADERS:Referer" required. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "580"] [id "440067"] [msg "BAD Referer"] [data "Matched Data: staklim-malang.info found within REQUEST_HEADERS:Referer: http://www.baidu.info/ request_line = GET /images/Klimatologi/Analisis/03-Analisis_Bulanan/Analisis_Distibusi_Curah_Hujan_Bulanan/Analisis_Distibusi_Curah_Hujan_Bulanan_Provinsi_Jawa_Timur/2024/09_September_2024/Analisis_Bulanan_Distribusi_Curah_Hujan_Bulan_September_Tahun_2024_di_Provinsi_Jawa_Timur.we
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-05-29 14:02:34
(3 weeks ago)
[Fri May 29 21:02:27.130999 2026] [security2:error] [pid 38362:tid 140230026835648] [client 185.127. ...
show more
[Fri May 29 21:02:27.130999 2026] [security2:error] [pid 38362:tid 140230026835648] [client 185.127.70.28:52384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.bmkg.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.bmkg.go.id found within REQUEST_HEADERS:Referer: https://www.bmkg.go.id/ request_line = GET /disquss-v5.js HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/disquss-v5.js"] [unique_id "ahmcc9rxuRbdXZVzCrk-rQAAygU"], referer https://www.bmkg.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[38384] [Got3S/Wswe4] [ahmcc9rxuRbdXZVzCrk-rQAAygU] keep_alive=[1] [2026-05-29 21:02:27.131006] [R:ahmcc9rxuRbdXZVzCrk-rQAAygU] UA:'Mozilla/5.0 (iPhone; CPU iPhone OS 17_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) EdgiOS/122.0.2365.99 Version/17.0 Mobile/15E148 Safari
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-05-27 06:58:47
(3 weeks ago)
[Wed May 27 13:58:46.966375 2026] [security2:error] [pid 641163:tid 139874887767744] [client 185.127 ...
show more
[Wed May 27 13:58:46.966375 2026] [security2:error] [pid 641163:tid 139874887767744] [client 185.127.70.28:48724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.baidu.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.baidu.go.id found within REQUEST_HEADERS:Referer: http://www.baidu.go.id/ request_line = GET /index.php/prediksi-iklim/prediksi-dasarian/monitoring-dan-prediksi-curah-hujan HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prediksi-iklim/prediksi-dasarian/monitoring-dan-prediksi-curah-hujan"] [unique_id "ahaWJlgyltwXzI6R0tm8FAAAAdM"], referer http://www.baidu.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[641209] [M8efJEfP7nM] [ahaWJlgyltwXzI6R0tm8FAAAAdM] keep_alive=[0] [2026-05-27 13:58:46.966379] [R:ahaWJlgyltwXzI6R0tm8FAAAAdM] UA:'Mozilla/5.0 (Lin
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-05-25 05:56:10
(3 weeks ago)
[Mon May 25 12:56:05.660696 2026] [security2:error] [pid 772980:tid 140518613837504] [client 185.127 ...
show more
[Mon May 25 12:56:05.660696 2026] [security2:error] [pid 772980:tid 140518613837504] [client 185.127.70.28:36320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.baidu.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "624"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.baidu.go.id found within REQUEST_HEADERS:Referer: http://www.baidu.go.id/ request_line = GET /index.php/informasi-iklim/infografis-iklim/infografis-tahunan HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/informasi-iklim/infografis-iklim/infografis-tahunan"] [unique_id "ahPkdWUaR0Y0hNd3cjnTewACQQA"], referer http://www.baidu.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[772981] [0uS/CF530yY] [ahPkdWUaR0Y0hNd3cjnTewACQQA] keep_alive=[1] [2026-05-25 12:56:05.660716] [R:ahPkdWUaR0Y0hNd3cjnTewACQQA] UA:'Mozilla/5.0 (Linux; Android 10; SM-S901B) AppleWeb
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-05-16 13:29:11
(1 month ago)
05/16/2026-12:45:03.645674 [Drop] [**] [1:2100000417:0] Suricata match TLS JA4 scan Uniq Zeek no 41 ...
show more
05/16/2026-12:45:03.645674 [Drop] [**] [1:2100000417:0] Suricata match TLS JA4 scan Uniq Zeek no 417 with hash_t12d1209h2_d34a8e72043a_e08eabe7240f [**] [Classification: (null)] [Priority: 3] {TCP} 185.127.70.28:46854 -> 103.166.156.58:443
...
show less
Email Spam
Hacking
Showing 1 to
6
of 6 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: