This IP address has been reported a total of
30
times from
23 distinct
sources.
185.92.139.212 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Honeypot [fra-de-honeypot]: Unauthorized connection attempt detected on 22/SSH
Reported by DisPaisy ...
show moreHoneypot [fra-de-honeypot]: Unauthorized connection attempt detected on 22/SSH
Reported by DisPaisy Enterprises (dispaisy.systems) using: https://github.com/sefinek/T-Pot-To-AbuseIPDB
show less
Blocked by UFW on Jellyfin [23/tcp]
Source port: 14744
TTL: 50
Packet length: 60
TOS: 0x00
This rep ...
show moreBlocked by UFW on Jellyfin [23/tcp]
Source port: 14744
TTL: 50
Packet length: 60
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly as ...
show moreUFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly associated with port scanning, service discovery, or automated internet probing. Technical: source_ip=185.92.139.212; proto=TCP; source_port=24162; target_port=23; flags=SYN
show less
Port Scan
Anonymous
denied traffic to a honeypot network. destination port 23.
Honeypot detection: Telnet / IoT device brute-force or exploitation attempt on port 23. Severity: ME ...
show moreHoneypot detection: Telnet / IoT device brute-force or exploitation attempt on port 23. Severity: MEDIUM. Aaran.cloud
show less
(mod_security) mod_security (id:210730) triggered by 185.92.139.212 (-): 1 in the last 300 secs; Por ...
show more(mod_security) mod_security (id:210730) triggered by 185.92.139.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 17:56:51.693764 2026] [security2:error] [pid 716:tid 716] [client 185.92.139.212:4716] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||franzexpress.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "franzexpress.com"] [uri "/franzexpress.com"] [unique_id "afUhow4gWn2ABwHL4dhe6AAAAAI"], referer: https://franzexpress.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show moreDistributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in printer-friendly.asp
show less