AbuseIPDB » 38.135.25.97
38.135.25.97 was found in our database!
This IP was reported 251 times. Confidence of
Abuse
is 77% : ?
ISP
Fourplex Telecom LLC
Usage Type
Data Center/Web Hosting/Transit
ASN
AS27284
Domain Name
fourplex.net
Country
๐บ๐ธ
United States of America
City
Heritage Hills, New York
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 38.135.25.97 :
This IP address has been reported a total of
251
times from
92 distinct
sources.
38.135.25.97 was first reported on
November 4th 2025 , and the most recent report was
1 week ago .
Old Reports:
The most recent abuse report for this IP address is from
1 week ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐บ๐ธ
TPI-Abuse
2025-11-10 22:17:56
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 38.135.25.97 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 38.135.25.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 10 17:17:50.249927 2025] [security2:error] [pid 2934:tid 2934] [client 38.135.25.97:58926] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||test.nationalccl.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "test.nationalccl.com"] [uri "/scripts/db/users.dat"] [unique_id "aRJkjqaaEzZUi1Sn0vZR-gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2025-11-10 21:58:21
(6 months ago)
Form spam
Web Spam
๐ธ๐ฌ
ANTI SCANNER
2025-11-10 20:25:52
(6 months ago)
Scanner : /admin/
Web Spam
๐บ๐ธ
antlac1
2025-11-10 18:40:13
(6 months ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
gu-alvareza
2025-11-10 07:05:04
(6 months ago)
Nessus.Scanner
Port Scan
๐ฆ๐บ
GreyWatch - Honeypot Intelligence
2025-11-10 04:22:01
(6 months ago)
ASN: 27284 (FOURPLEX-ASN)
Botnet Zombie: This IP has been detected as a botnet zombie | Outbound DDo ...
show more
ASN: 27284 (FOURPLEX-ASN)
Botnet Zombie: This IP has been detected as a botnet zombie | Outbound DDoS attack source | Malicious
show less
DDoS Attack
Bad Web Bot
๐บ๐ธ
gu-alvareza
2025-11-09 07:05:03
(6 months ago)
Primetek.Primefaces.5.Remote.Code.Execution
Hacking
Web App Attack
๐บ๐ธ
gu-alvareza
2025-11-08 07:05:08
(6 months ago)
Nessus.Scanner
Port Scan
๐บ๐ธ
xmission.com
2025-11-06 01:09:24
(6 months ago)
Blocked by UFW (TCP on 8080)
Source port: 36600
TTL: 49
Packet length: 60
TOS: 0x08
This report (fo ...
show more
Blocked by UFW (TCP on 8080)
Source port: 36600
TTL: 49
Packet length: 60
TOS: 0x08
This report (for 38.135.25.97) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
๐ต๐ฑ
sefinek.net
2025-11-05 15:38:43
(6 months ago)
Triggered Cloudflare WAF (firewallCustom) from T1.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from T1.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /blocklist-generator/noip
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐จ๐ญ
backslash
2025-11-04 23:10:20
(6 months ago)
block ruleset Badbot using very old user-agents 5CF3CDB778C7D82564405B86B9242E612F378C68
Bad Web Bot
Showing 241 to
251
of 251 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: