AbuseIPDB » 193.142.38.214
193.142.38.214 was found in our database!
This IP was reported 6 times. Confidence of
Abuse
is 22% : ?
ISP
Atlas Network Holdings LLC
Usage Type
Data Center/Web Hosting/Transit
ASN
AS213954
Domain Name
atlasnetworkholdings.online
Country
๐ซ๐ฎ
Finland
City
Helsinki, Uusimaa
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 193.142.38.214 :
This IP address has been reported a total of
6
times from
5 distinct
sources.
193.142.38.214 was first reported on
March 25th 2026 , and the most recent report was
3 hours ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ฉ๐ช
NxtGenIT
2026-09-11 12:04:56
(3 hours ago)
CiscoASA Honeypot hit, Payload: "GET /+CSCOE+/logon.html?fcadbadd=1 HTTP/1.1" 200 -,
Brute-Force
๐จ๐ญ
SOC [GOLINE SA]
2026-09-09 15:44:52
(2 days ago)
[RoutePulse | 2026-09-09T15:44:52Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 193.142.38. ...
show more
[RoutePulse | 2026-09-09T15:44:52Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 193.142.38.214 ยท AS213954 Global Transit Systems LLC ยท United States
EVIDENCE: Shunned on the Cisco FTD VPN gateway โ Cisco VPN RA Brute force on Cisco FTDv โ slow spray: 4 failed logins over 13 h (one every ~260 min, under every 15-min threshold and the FTD hold-down) โ rung 1-bis (doc 247 ยง10.2)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
๐จ๐ญ
SOC [GOLINE SA]
2026-09-09 02:50:39
(2 days ago)
[RoutePulse | 2026-09-09T02:50:39Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 193.142.38. ...
show more
[RoutePulse | 2026-09-09T02:50:39Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 193.142.38.214 ยท AS213954 Global Transit Systems LLC ยท United States
EVIDENCE: Shunned on the Cisco FTD VPN gateway โ Cisco VPN RA Brute force on Cisco FTDv โ distributed attack (3 attempts/15min) โ shun on the VPN gateway
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
๐ธ๐ช
OnTheEdge
2026-09-08 14:43:58
(3 days ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2026-06-27 00:08:23
(2 months ago)
[Sat Jun 27 07:08:22.698458 2026] [security2:error] [pid 654728:tid 139693760943808] [client 193.142 ...
show more
[Sat Jun 27 07:08:22.698458 2026] [security2:error] [pid 654728:tid 139693760943808] [client 193.142.38.214:56459] ModSecurity: Access denied with code 403 (phase 1). Match of "pm googlebot " against "REQUEST_HEADERS:From" required. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "136"] [id "448105"] [msg "BAD REQUEST Header From "] [data "Matched Data: host,user-agent,from,accept-language,cache-control,pragma,priority,sec-fetch-site,sec-fetch-mode,upgrade-insecure-requests,accept,accept-encoding found within REQUEST_HEADERS:From: bingbot(at)microsoft.com request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/3-bulan-ke-depan/555561746-prakiraan-bulanan-curah-hujan-bulan-mei-tahun-2025-update-dari-analisis-bulan-januari-tahun-2025-di-provinsi-jawa-timur HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/
...
show less
Email Spam
Hacking
๐ช๐ธ
el-brujo
2026-03-25 18:57:14
(5 months ago)
[Wed Mar 25 19:57:12.364901 2026] [proxy_fcgi:error] [pid 267653:tid 268183] [remote 193.142.38.214: ...
show more
[Wed Mar 25 19:57:12.364901 2026] [proxy_fcgi:error] [pid 267653:tid 268183] [remote 193.142.38.214:0] AH01071: Got error 'Primary script unknown\n', referer: https://www.google.com
[Wed Mar 25 19:57:14.175896 2026] [proxy_fcgi:error] [pid 267653:tid 268162] [remote 193.142.38.214:0] AH01071: Got error 'Primary script unknown\n', referer: https://www.google.com
...
show less
Hacking
Web App Attack
Showing 1 to
6
of 6 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: