This IP address has been reported a total of
9
times from
9 distinct
sources.
38.25.2.59 was first reported on
September 23rd 2025 , and the most recent report was
1 month ago .
In the last 60 days, the only reporter location was:
Spain
with 1
report.
The most common categories in these recent reports were:
DDoS Attack
1
time;
Hacking
1
time.
Old Reports
The most recent abuse report for this IP address is from
1 month ago . It is possible that this IP is no
longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ช๐ธ
el-brujo
2026-08-14 02:42:01
(1 month ago)
38.25.2.59 - - [14/Aug/2026:04:04:02 +0200] "7\xc4\n" 400 226 "-" "-"
38.25.2.59 - - [14/Aug/2026:04 ...
show more
38.25.2.59 - - [14/Aug/2026:04:04:02 +0200] "7\xc4\n" 400 226 "-" "-"
38.25.2.59 - - [14/Aug/2026:04:04:05 +0200] "-\xcfF\xdc\xb8n>`d\xdb\xf7\xacf\xb8G\x0f]\x9e\x91\xa2\n" 400 226 "-" "-"
38.25.2.59 - - [14/Aug/2026:04:04:08 +0200] "\x8a\x16\n" 400 226 "-" "-"
38.25.2.59 - - [14/Aug/2026:04:04:09 +0200] "\x88y6%\xffD\xc6>\xc9\xf0\xd3i\x0e\r\x9b\x16 \x9d\xdf\xba5\x86\x03\xc3\x83\xbf\x0c\x9fyjtU\xcb\x9e\x95\xcd\b\x11\xa6s%m\xd7| Vy\x9de*S\x06\x1e\x81B\x94\x88D5r\x8e`" 400 226 "-" "-"
38.25.2.59 - - [14/Aug/2026:04:04:19 +0200] "\xa3k$\xeb\xe7y\x7f=\xbd@t\xd1\xc628[I\xc7\xcbcY\x83\xb8t\x97;fvF\xd0Nj~\x1a\x01\x93\xe1\x12\xd2K\xd8\xaa\xbc\xfd\xbc\xe4\x91\xf8p\x1a\xb8\xbf\x8f\xbbO!\x8ec\x17\xb0x\xfe`\x8c\x0e[I@\x8f\vC\x80\x9c\xba\xf7\xd3\varr\x1a~\x19\x8b0\xcb\xeeSXCw)\xa3\xa9\xd0\xdaU= (v/\xf4\x01O\xcb\xe3\xa5#\x06\xdf\xc2\x06" 400 226 "-" "-"
38.25.2.59 - - [14/Aug/2026:04:04:23 +0200] "@\x8aG\xd2\x04X-\xfa\x88v9" 400 226 "-" "-"
38.25.2.59 - - [14/Aug/2026:04:04:24 +0200] "\xe70\xf4h\xf8\
...
show less
DDoS Attack
Hacking
๐บ๐ธ
cwytech
2026-07-18 00:35:39
(2 months ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/pf-geofence-high.
Hacking
๐ณ๐ฑ
EGP Abuse Dept
2026-07-14 01:48:43
(2 months ago)
Unauthorized connection to Telnet port 23
Port Scan
Hacking
Anonymous
2026-07-10 02:59:16
(2 months ago)
Unauthorized connection attempt on Port 23
Port Scan
Hacking
Exploited Host
๐ต๐ฑ
mkey
2026-07-09 22:15:02
(2 months ago)
Verified scan activity detected by local IDS/firewall correlation. SCAN: HIGHRISK_SINGLEPORT | PORTS ...
show more
Verified scan activity detected by local IDS/firewall correlation. SCAN: HIGHRISK_SINGLEPORT | PORTS=23 | HITS=2 | IPSET=ADD | FIRST=2026-07-10 00:13:50 | LAST=2026-07-10 00:13:51. Last seen 2026-07-10 00:13:51.
show less
Port Scan
๐บ๐ธ
cybsecaoccol
2026-07-09 05:13:48
(2 months ago)
unauthorized connection or malicious port scan attempted on tcp port - corp
Port Scan
Hacking
Anonymous
2026-06-21 21:00:25
(3 months ago)
Large-scale coordinated botnet (200+k IPs). Attacker: mikhail-smirnov-79830323 (LinkedIn/profile ID) ...
show more
Large-scale coordinated botnet (200+k IPs). Attacker: mikhail-smirnov-79830323 (LinkedIn/profile ID) employed by Angara Technologies Group (Explicitly identified himself as enemy a week before attack began) | Attack Signature Blocked: /wishlist/index/add/product/233/form_key/S1aBTK9Bh8yANDk1/ | UA: Mozilla/5.0 (X11; Linux i686) AppleWebKit/533.1 (KHTML, like Gecko) Chrome/37.0.863.0 Safari/533.1 | (Magento Site)
show less
Hacking
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
hermawan
2025-11-04 06:22:56
(10 months ago)
[Tue Nov 04 13:22:11.514904 2025] [security2:error] [pid 391370:tid 139804592195264] [client 38.25.2 ...
show more
[Tue Nov 04 13:22:11.514904 2025] [security2:error] [pid 391370:tid 139804592195264] [client 38.25.2.59:7188] ModSecurity: Access denied with code 403 (phase 2). Pattern match "." at ARGS_NAMES:start. [file "/etc/modsecurity/coreruleset-4.19.0/rules/REQUEST-921-PROTOCOL-ATTACK.conf"] [line "711"] [id "921170"] [msg "deny 921170"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: s found within ARGS_NAMES:start: start request_line = GET /index.php/informasi-iklim/infografis-iklim/infografis-harian/monitoring-kualitas-udara?start=40 HTTP/1.1 Request URI RAW = /index.php/informasi-iklim/infografis-iklim/infografis-harian/monitoring-kualitas-udara?start=40 Request Basename = monitoring-kualitas-udara"] [ver "OWASP_CRS/4.19.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ATTACK"] [tag "capec/1000/152/137/15/460"] [hostname "staklim-mal
...
show less
Hacking
Web App Attack
๐จ๐ญ
ALPHANET
2025-09-23 20:56:03
(11 months ago)
Botnet or web spider not respecting robots.txt
DDoS Attack
Exploited Host
Showing 1 to
9
of 9 reports