Neutral Activity
There is no recent abuse activity, or the IP address is whitelisted.
Whitelisted Subnet
Whitelisted netblocks are typically owned by trusted entities, such as Google or Microsoft who
may use them for search engine spiders. However, these same entities sometimes also provide cloud
servers and mail services which are easily abused. Pay special attention when trusting or
distrusting these IPs.
This IP address has been reported a total of
13
times from
3 distinct
sources.
209.85.238.193 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Ukraine
with 11
reports;
France
with 1
report;
Portugal
with 1
report.
The most common categories in these recent reports were:
Web App Attack
13
times;
Bad Web Bot
12
times;
Port Scan
1
time;
Hacking
1
time;
Spoofing
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[02/Oct/2026:05:10:56 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more[02/Oct/2026:05:10:56 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.well-known/assetlinks.json HTTP/1.1
show less
[30/Sep/2026:05:10:40 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more[30/Sep/2026:05:10:40 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.well-known/assetlinks.json HTTP/1.1
show less
[29/Sep/2026:02:40:15 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more[29/Sep/2026:02:40:15 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.well-known/assetlinks.json HTTP/1.1
show less
[27/Sep/2026:05:09:10 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more[27/Sep/2026:05:09:10 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.well-known/assetlinks.json HTTP/1.1
show less
[26/Sep/2026:02:37:33 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more[26/Sep/2026:02:37:33 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.well-known/assetlinks.json HTTP/1.1
show less
[23/Sep/2026:02:35:31 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more[23/Sep/2026:02:35:31 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.well-known/assetlinks.json HTTP/1.1
show less
[21/Sep/2026:02:35:54 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more[21/Sep/2026:02:35:54 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.well-known/assetlinks.json HTTP/1.1
show less
[19/Sep/2026:05:07:46 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more[19/Sep/2026:05:07:46 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.well-known/assetlinks.json HTTP/1.1
show less
[18/Sep/2026:02:35:22 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more[18/Sep/2026:02:35:22 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.well-known/assetlinks.json HTTP/1.1
show less
[16/Sep/2026:05:04:03 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more[16/Sep/2026:05:04:03 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.well-known/assetlinks.json HTTP/1.1
show less
[Security] [Category: Bot Masquerading] FCrDNS mismatch detected. [IP Address]: 209.85.238.193 claim ...
show more[Security] [Category: Bot Masquerading] FCrDNS mismatch detected. [IP Address]: 209.85.238.193 claimed a fake identity but failed forward-confirmed reverse DNS verification. Automated scraping via spoofed User-Agent `Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_3) AppleWebKit/[WEBKIT_VERSION] (KHTML, like Gecko, Mediapartners-Google) Chrome/[CHROME_VERSION] Safari/[WEBKIT_VERSION]`. [Action]: IP block initiated. [User-Agent]: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_3) AppleWebKit/[WEBKIT_VERSION] (KHTML, like Gecko, Mediapartners-Google) Chrome/[CHROME_VERSION] Safari/[WEBKIT_VERSION] [IoA Datetime]: 2026-09-11 14:52:29 UTC +1.
show less
Port Scan
Hacking
Spoofing
Bad Web Bot
Web App Attack
[11/Sep/2026:09:04:27 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more[11/Sep/2026:09:04:27 +0300] -- 209.85.238.193 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.well-known/assetlinks.json HTTP/1.1
show less