AbuseIPDB » 23.27.225.85
23.27.225.85 was found in our database!
This IP was reported 10 times. Confidence of
Abuse
is 28% : ?
ISP
code200, UAB
Usage Type
Data Center/Web Hosting/Transit
ASN
AS212238
Domain Name
code200.global
Country
๐ต๐ฑ
Poland
City
Warsaw, Mazovia
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 23.27.225.85 :
This IP address has been reported a total of
10
times from
8 distinct
sources.
23.27.225.85 was first reported on
October 16th 2025 , and the most recent report was
12 hours ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ต๐น
Subnet Shadow Specter
2026-07-27 23:29:24
(12 hours ago)
[Activity Alert] Distributed scraper bot trapped searching for exact phrases. IP automatically block ...
show more
[Activity Alert] Distributed scraper bot trapped searching for exact phrases. IP automatically blocked and banned. [User-Agent]: Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.1040.1573 Mobile Safari/537.36 [OS]: Unknown. [IP Address]: 23.27.225.85 [IoA Datetime]: 2026-07-28 00:29:24 UTC +1.
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-07-21 16:49:03
(6 days ago)
Malicious activity detected
Hacking
Web App Attack
๐ฎ๐น
A000Z
2026-07-10 15:35:13
(2 weeks ago)
Fail2Ban: 23.27.225.85 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5.0 ...
show more
Fail2Ban: 23.27.225.85 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.6806.1301 Safari/537.36
show less
Bad Web Bot
Anonymous
2026-07-10 11:14:00
(2 weeks ago)
"Packet Flood; Triggered WAF; Multiple attempts to access nonexistent vulnerable php files"
DDoS Attack
๐ฉ๐ช
Phenix Info
2026-06-23 00:36:59
(1 month ago)
SmallGuard.fr/Prestashop Massive 403
Web App Attack
๐ฉ๐ช
Phenix Info
2026-04-21 05:18:52
(3 months ago)
SmallGuard.fr/Prestashop Massive 403
Web App Attack
๐บ๐ธ
kosada.com
2026-04-16 22:55:54
(3 months ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
๐บ๐ธ
kosada.com
2026-03-30 01:58:38
(3 months ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
๐จ๐ญ
backslash
2025-12-01 01:05:14
(7 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐ฎ๐ฉ
hermawan
2025-10-16 22:38:12
(9 months ago)
[Fri Oct 17 05:36:43.998695 2025] [security2:error] [pid 1348147:tid 140597398582976] [client 23.27. ...
show more
[Fri Oct 17 05:36:43.998695 2025] [security2:error] [pid 1348147:tid 140597398582976] [client 23.27.225.85:40108] ModSecurity: Access denied with code 403 (phase 1). Match of "pm matomo.staklim-malang.info " against "SERVER_NAME" required. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "164"] [id "440235"] [msg "BAD REQUEST Bro"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: format= found within SERVER_NAME: staklim-jatim.bmkg.go.id request_line = GET /index.php/component/search/?Itemid=1944&format=opensearch HTTP/1.1 Request URI RAW = /index.php/component/search/?Itemid=1944&format=opensearch Request Basename = "] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/component/search/"] [unique_id "aPFze463sE20aVcu9xqbbQAAA9M"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[1348193] [fZRgQM60S6s] [aPFze463sE20aVcu9xqbbQAAA9M] keep_alive=[0] [2025-10-17 05:36:
...
show less
Hacking
Web App Attack
Showing 1 to
10
of 10 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: