AbuseIPDB » 72.63.18.107
72.63.18.107 was found in our database!
This IP was reported 6 times. Confidence of
Abuse
is 0%: ?
| ISP |
UAB code200
|
| Usage Type |
Data Center/Web Hosting/Transit
|
| ASN |
AS30058
|
| Domain Name |
code200.global
|
| Country |
๐บ๐ธ
United States of America
|
| City |
Ashburn, Virginia
|
IP info including ISP, Usage Type, and Location provided
by IPInfo. Updated weekly.
IP Abuse Reports for 72.63.18.107:
This IP address has been reported a total of
6
times from
3 distinct
sources.
72.63.18.107 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
| Reporter |
IoA Timestamp (UTC)
|
Comment |
Categories |
|
|
๐ฉ๐ช
PhishDestroy
|
|
Automated scanning of phishdestroy.io for sensitive files (.env, config, credentials). Blocked by Cl ...
show more
Automated scanning of phishdestroy.io for sensitive files (.env, config, credentials). Blocked by Cloudflare WAF rule a85b24fd4b2b4574b9ac23a37dbd7d01. 1 blocked requests. Paths: /domain/executors.cloud/. UA: Mozilla/5.0 (Android 13; Mobile; rv:128.0) Gecko/128.0 Firefox/128.0
show less
|
Web App Attack
|
|
|
๐ฎ๐ฉ
hermawan
|
|
[Sat Jun 20 03:49:21.845175 2026] [security2:error] [pid 1470708:tid 140501289256640] [client 72.63. ...
show more
[Sat Jun 20 03:49:21.845175 2026] [security2:error] [pid 1470708:tid 140501289256640] [client 72.63.18.107:39492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.google.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.google.go.id found within REQUEST_HEADERS:Referer: https://www.google.go.id/ request_line = GET /index.php/informasi-iklim/infografis-iklim/infografis-dasarian/infografis-dasarian-analisis-kejadian-hujan-lebat HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/informasi-iklim/infografis-iklim/infografis-dasarian/infografis-dasarian-analisis-kejadian-hujan-lebat"] [unique_id "ajWrUSg-iuSre28349yiXgABEwI"], referer https://www.google.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[1470711] [/4tVbaHkeVM] [ajWrUSg-iuSre28349yiXgABEwI] keep_alive=[1] [2026-
...
show less
|
Email Spam
Hacking
|
|
|
๐ฎ๐ฉ
hermawan
|
|
[Fri Jun 05 12:40:18.380517 2026] [security2:error] [pid 775879:tid 140021634942656] [client 72.63.1 ...
show more
[Fri Jun 05 12:40:18.380517 2026] [security2:error] [pid 775879:tid 140021634942656] [client 72.63.18.107:29918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.bmkg.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.bmkg.go.id found within REQUEST_HEADERS:Referer: https://www.bmkg.go.id/ request_line = GET /index.php/profil/alamat-kantor/list-all-categories/555556811-mengakses-halaman-web-https-karangploso-jatim-bmkg-go-id-secara-offline-dan-menginstallnya-di-hp-android-atau-di-komputer HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/alamat-kantor/list-all-categories/555556811-mengakses-halaman-web-https-karangploso-jatim-bmkg-go-id-secara-offline-dan-menginstallnya-di-hp-android-atau-di-komputer"] [unique_id "aiJhQjdlbWER5uyABT_RtgAARwU"], referer https://www.bmkg.go.id/ [s
...
show less
|
Email Spam
Hacking
|
|
|
๐ฎ๐ฉ
hermawan
|
|
[Wed Jun 03 21:32:34.629561 2026] [security2:error] [pid 10131:tid 140148628690624] [client 72.63.18 ...
show more
[Wed Jun 03 21:32:34.629561 2026] [security2:error] [pid 10131:tid 140148628690624] [client 72.63.18.107:53044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.yahoo.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.yahoo.go.id found within REQUEST_HEADERS:Referer: https://www.yahoo.go.id/ request_line = GET /index-v100.js HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index-v100.js"] [unique_id "aiA7An_39yXJJRXPYr-3xAAAigI"], referer https://www.yahoo.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[10154] [FSdnTJqj2vE] [aiA7An_39yXJJRXPYr-3xAAAigI] keep_alive=[1] [2026-06-03 21:32:34.629566] [R:aiA7An_39yXJJRXPYr-3xAAAigI] UA:'Mozilla/5.0 (iPhone; CPU iPhone OS 17_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) EdgiOS/122.0.2365.99 Version/17.0 Mobile/15E148 Saf
...
show less
|
Email Spam
Hacking
|
|
|
๐ฎ๐ฉ
hermawan
|
|
[Tue May 19 10:26:35.680214 2026] [security2:error] [pid 304300:tid 140059121538752] [client 72.63.1 ...
show more
[Tue May 19 10:26:35.680214 2026] [security2:error] [pid 304300:tid 140059121538752] [client 72.63.18.107:22274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.yandex.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "624"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.yandex.go.id found within REQUEST_HEADERS:Referer: https://www.yandex.go.id/ request_line = GET /index.php/profil/meteorologi/geofisika/555558584-poster-skala-gempa-mmi HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/geofisika/555558584-poster-skala-gempa-mmi"] [unique_id "agvYa3Vk0EimuNyBAdg1PAABxwI"], referer https://www.yandex.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[304303] [lG8LP6ON7S8] [agvYa3Vk0EimuNyBAdg1PAABxwI] keep_alive=[1] [2026-05-19 10:26:35.680224] [R:agvYa3Vk0EimuNyBAdg1PAABxwI] UA:'Mozilla/5.0 (Linux; Andro
...
show less
|
Email Spam
Hacking
|
|
|
Anonymous
|
|
Multiple Violations by Bot
|
Port Scan
Web App Attack
|
|
Showing 1 to
6
of 6 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: