This IP address has been reported a total of
26
times from
19 distinct
sources.
217.19.215.1 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
denied traffic to a non-approved destination port. destination port 17705.
Port Scan
Anonymous
denied traffic to a honeypot network. destination port 6213.
DDoS flood attack against 31.56.58.0 (2026-08-20 19:05:36 -> 2026-08-20 19:20:36 UTC) targeting AS21 ...
show moreDDoS flood attack against 31.56.58.0 (2026-08-20 19:05:36 -> 2026-08-20 19:20:36 UTC) targeting AS215599. This IP (AS1547) sent ~414 packets (0.47 MB) during the attack window. Likely a compromised device (botnet).
show less
L7 DDoS: distributed flood on a shop's faceted search โ automated requests to search/sort URLs, one ...
show moreL7 DDoS: distributed flood on a shop's faceted search โ automated requests to search/sort URLs, one or two per address from thousands of addresses, no page assets loaded | path: /17-vtt | query: q=Type+de+v%C3%A9lo-Musculaire%2FFamille-Spark+RC-Spicy&resultsPerPage=12
show less
UDP flood (DDoS) vs AS215599: 228119 pkts / 326.21 MB to UDP 80/8443 across 511 dst IP(s), 2026-08-1 ...
show moreUDP flood (DDoS) vs AS215599: 228119 pkts / 326.21 MB to UDP 80/8443 across 511 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
UDP flood (DDoS) vs AS215599: 228119 pkts / 326.21 MB to UDP 80/8443 across 511 dst IP(s), 2026-08-1 ...
show moreUDP flood (DDoS) vs AS215599: 228119 pkts / 326.21 MB to UDP 80/8443 across 511 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
Auto-blocked by Seczar SecureOps โ Port Scan Detection (1858 events in 10min) at 2026-08-01 03:12
Port Scan
Anonymous
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show moreDistributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in thread-skip.asp
show less
2026-06-03T15:56:35.740727+08:00 [Host] sshd[140985]: banner exchange: Connection from 217.19.215.1 ...
show more2026-06-03T15:56:35.740727+08:00 [Host] sshd[140985]: banner exchange: Connection from 217.19.215.1 port 53040: invalid format
2026-06-03T15:58:09.369634+08:00 [Host] sshd[141063]: banner exchange: Connection from 217.19.215.1 port 55792: invalid format
2026-06-03T15:59:43.857010+08:00 [Host] sshd[141527]: banner exchange: Connection from 217.19.215.1 port 45440: invalid format
...
show less
Fail2Ban: 217.19.215.1 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5.0 ...
show moreFail2Ban: 217.19.215.1 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Bad Web Bot
Showing 1 to
15
of 26 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ