AbuseIPDB » 185.127.70.68
185.127.70.68 was found in our database!
This IP was reported 8 times. Confidence of
Abuse
is 12% : ?
ISP
Indert Connection LP
Usage Type
Data Center/Web Hosting/Transit
ASN
AS203443
Domain Name
indertconnection.com
Country
๐ฌ๐ง
United Kingdom of Great Britain and Northern Ireland
City
London, England
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 185.127.70.68 :
This IP address has been reported a total of
8
times from
3 distinct
sources.
185.127.70.68 was first reported on
May 5th 2026 , and the most recent report was
1 week ago .
Old Reports:
The most recent abuse report for this IP address is from
1 week ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ฎ๐ฉ
securejdprop
2026-08-26 07:18:04
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET DROP Spamhaus D ...
show more
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET DROP Spamhaus DROP Listed Traffic Inbound group 38).
show less
Hacking
Web App Attack
๐บ๐ธ
Zandro
2026-08-19 21:00:14
(1 week ago)
distributed harvester
DDoS Attack
Bad Web Bot
Exploited Host
๐ฎ๐ฉ
hermawan
2026-06-30 19:16:13
(2 months ago)
[Wed Jul 01 02:16:08.621842 2026] [security2:error] [pid 305401:tid 140187041519296] [client 185.127 ...
show more
[Wed Jul 01 02:16:08.621842 2026] [security2:error] [pid 305401:tid 140187041519296] [client 185.127.70.68:32214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.google.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "601"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.google.go.id found within REQUEST_HEADERS:Referer: https://www.google.go.id/ request_line = GET /index.php HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php"] [unique_id "akQV-EF4fBM3kWFqxjz71wAABQE"], referer https://www.google.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[305403] [kaQ8aP2Ou+s] [akQV-EF4fBM3kWFqxjz71wAABQE] keep_alive=[1] [2026-07-01 02:16:08.621852] [R:akQV-EF4fBM3kWFqxjz71wAABQE] UA:'Mozilla/5.0 (Linux; Android 14; Pixel 6 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.6261.119 Mobile Safari/537.36 OPR/81.2.4292.78581'
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-06-27 08:03:25
(2 months ago)
[Sat Jun 27 15:03:20.800092 2026] [security2:error] [pid 951362:tid 139939344725696] [client 185.127 ...
show more
[Sat Jun 27 15:03:20.800092 2026] [security2:error] [pid 951362:tid 139939344725696] [client 185.127.70.68:18426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.bing.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "601"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.bing.go.id found within REQUEST_HEADERS:Referer: https://www.bing.go.id/ request_line = GET /index.php/informasi-iklim/infografis-iklim/infografis-klimat-story/555561326-infografis-himbauan-waspada-suhu-udara-panas HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/informasi-iklim/infografis-iklim/infografis-klimat-story/555561326-infografis-himbauan-waspada-suhu-udara-panas"] [unique_id "aj-DyBUfZK2-6FKUuzQItAAN0xQ"], referer https://www.bing.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[951387] [ZOqTqDdR2UU] [aj-DyBUfZK2-6FKUuzQItAAN0xQ] keep_alive=[
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-06-25 11:49:54
(2 months ago)
[Thu Jun 25 18:49:51.472810 2026] [security2:error] [pid 116525:tid 140398270772928] [client 185.127 ...
show more
[Thu Jun 25 18:49:51.472810 2026] [security2:error] [pid 116525:tid 140398270772928] [client 185.127.70.68:32938] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.baidu.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.baidu.go.id found within REQUEST_HEADERS:Referer: http://www.baidu.go.id/ request_line = GET /index.php/prediksi-iklim/prediksi-dasarian/probabilistik-curah-hujan-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prediksi-iklim/prediksi-dasarian/probabilistik-curah-hujan-provinsi-jawa-timur"] [unique_id "aj0V37Cl7oDpK5tn9s3vVgACRxg"], referer http://www.baidu.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[116565] [owj9ltKLny0] [aj0V37Cl7oDpK5tn9s3vVgACRxg] keep_alive=[1] [2026-06-25 18:49:51.472814] [R:aj0V37Cl7oDpK5tn9s3vVgACRxg]
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-06-11 14:56:23
(2 months ago)
[Thu Jun 11 21:56:20.149430 2026] [security2:error] [pid 1769629:tid 139768546432704] [client 185.12 ...
show more
[Thu Jun 11 21:56:20.149430 2026] [security2:error] [pid 1769629:tid 139768546432704] [client 185.127.70.68:53992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.bmkg.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.bmkg.go.id found within REQUEST_HEADERS:Referer: https://www.bmkg.go.id/ request_line = GET /index.php/e-buletin-untuk-kota-dan-kabupaten-di-provinsi-jawa-timur HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/e-buletin-untuk-kota-dan-kabupaten-di-provinsi-jawa-timur"] [unique_id "airMlJJM6bHeHtpN9HUl4AAA0QU"], referer https://www.bmkg.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[1769635] [uNsWkHvbnZA] [airMlJJM6bHeHtpN9HUl4AAA0QU] keep_alive=[1] [2026-06-11 21:56:20.149435] [R:airMlJJM6bHeHtpN9HUl4AAA0QU] UA:'Mozilla/5.0 (Linux; Android 10; K) App
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-05-30 05:03:45
(3 months ago)
[Sat May 30 12:03:40.911699 2026] [authz_core:error] [pid 95964:tid 140573670311616] [client 185.127 ...
show more
[Sat May 30 12:03:40.911699 2026] [authz_core:error] [pid 95964:tid 140573670311616] [client 185.127.70.68:15824] AH01630: client denied by server configuration: /var/www/index.php [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[96001] [6A+E4gGoVPQ] [ahpvrFeKFrkyQlUMqcJJ8AABGBA] keep_alive=[1] [2026-05-30 12:03:40.911702] [R:ahpvrFeKFrkyQlUMqcJJ8AABGBA] UA:'Mozilla/5.0 (iPhone; CPU iPhone OS 17_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Mobile/15E148 Safari/604.1' Host:'staklim-jatim.bmkg.go.id:443' ACCEPT:'text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8' Accept-Encoding:'gzip, deflate, br Accept-Language:'en-US,en;q=0.9
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-05-05 09:40:30
(3 months ago)
[Tue May 05 12:55:00.967000 2026] [security2:error] [pid 426258:tid 140314823079616] [client 185.127 ...
show more
[Tue May 05 12:55:00.967000 2026] [security2:error] [pid 426258:tid 140314823079616] [client 185.127.70.68:33940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.baidu.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.25.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "623"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.baidu.go.id found within REQUEST_HEADERS:Referer: http://www.baidu.go.id/ request_line = GET /index.php/profil/meteorologi/list-all-categories HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-all-categories"] [unique_id "afmGNAhHY-07EQGN5oTp1gAAUAM"], referer http://www.baidu.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[426262] [/RoQsMv2Xqk] [afmGNAhHY-07EQGN5oTp1gAAUAM] keep_alive=[1] [2026-05-05 12:55:00.967005] [R:afmGNAhHY-07EQGN5oTp1gAAUAM] UA:'Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15
...
show less
Email Spam
Hacking
Showing 1 to
8
of 8 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: