AbuseIPDB » 72.63.20.202
72.63.20.202 was found in our database!
This IP was reported 7 times. Confidence of
Abuse
is 8% : ?
ISP
UAB code200
Usage Type
Data Center/Web Hosting/Transit
ASN
AS30058
Domain Name
code200.global
Country
๐บ๐ธ
United States of America
City
Ashburn, Virginia
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 72.63.20.202 :
This IP address has been reported a total of
7
times from
3 distinct
sources.
72.63.20.202 was first reported on
May 20th 2026 , and the most recent report was
2 weeks ago .
Old Reports:
The most recent abuse report for this IP address is from
2 weeks ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ต๐น
Subnet Shadow Specter
2026-08-05 13:11:58
(2 weeks ago)
[CRITICAL][Security Alert: Bot Masquerading] Spoofed Google-InspectionTool User-Agent from unverifie ...
show more
[CRITICAL][Security Alert: Bot Masquerading] Spoofed Google-InspectionTool User-Agent from unverified ASN/IP. [IP Address]: 72.63.20.202 [User-Agent]: Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.6099.199 Mobile Safari/537.36 (compatible; Google-InspectionTool/1.0) [IoA Datetime]: 2026-08-05 14:11:58 UTC +1.
show less
Port Scan
Hacking
Spoofing
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
hermawan
2026-07-03 20:38:30
(1 month ago)
[Sat Jul 04 03:38:25.335627 2026] [security2:error] [pid 593854:tid 140643572557504] [client 72.63.2 ...
show more
[Sat Jul 04 03:38:25.335627 2026] [security2:error] [pid 593854:tid 140643572557504] [client 72.63.20.202:34334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bing" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "273"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bing found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Linux; Android 15; SM-S938U1 Build/AP3A.240905.015.A2; ) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Mobile Safari/537.36 BingSapphire/32.4.430908006 request_line = GET /index.php/informasi-iklim/infografis-iklim/infografis-klimat-story/555561581-mengenal-fenomena-la-nina-si-pembawa-hujan HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/informasi-iklim/infografis-iklim/infografis-klimat-story/555561581-mengenal-fenomena-la-nina-si-pembawa-hujan"] [unique_id "akgdweEuCpDgW8hc88jkrAABEhU"], refe
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-06-08 02:55:27
(2 months ago)
[Mon Jun 08 09:55:22.856919 2026] [security2:error] [pid 599706:tid 140380279359168] [client 72.63.2 ...
show more
[Mon Jun 08 09:55:22.856919 2026] [security2:error] [pid 599706:tid 140380279359168] [client 72.63.20.202:6326] ModSecurity: Access denied with code 403 (phase 1). Match of "pm www.office.com powerpoint.officeapps.live.com /offline-service-worker-19-02-2025.js /offline-service-worker-27-01-2024-v5-0-1.js /offline-service-worker-01-08-2023-v4-5-1.js /OneSignalSDKWorker.js /worker-analytic-helper-27-11-2022.js/ /worker-analyti ..." against "REQUEST_HEADERS:Referer" required. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "580"] [id "440067"] [msg "BAD Referer"] [data "Matched Data: matomo.staklim-malang.info found within REQUEST_HEADERS:Referer: https://www.bing.info/ request_line = GET /gemini-jscompress-dev_13-05-2026_matomo_5_10_0.js HTTP/2.0"] [severity "NOTICE"] [hostname "matomo.staklim-malang.info"] [uri "/gemini-jscompress-dev_13-05-2026_matomo_5_10_0.js"] [unique_id "aiYvGo2lJYMmLiVQXLutzgACDgs"], referer https://www.bing.info/ [m
...
show less
Email Spam
Hacking
๐ฉ๐ช
HandyTreff.de
2026-06-02 11:10:17
(2 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -36.187 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -36.187 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (iPhone; CPU iPhone OS 17_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriO
show less
Web App Attack
Bad Web Bot
๐ฎ๐ฉ
hermawan
2026-06-02 05:17:49
(2 months ago)
[Tue Jun 02 12:17:31.542775 2026] [security2:error] [pid 162980:tid 139858222765760] [client 72.63.2 ...
show more
[Tue Jun 02 12:17:31.542775 2026] [security2:error] [pid 162980:tid 139858222765760] [client 72.63.20.202:25780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.bmkg.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.bmkg.go.id found within REQUEST_HEADERS:Referer: https://www.bmkg.go.id/ request_line = GET /index.php/informasi-iklim/infografis-iklim/infografis-bulanan/infografis-bulanan-iklim-ekstrim HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/informasi-iklim/infografis-iklim/infografis-bulanan/infografis-bulanan-iklim-ekstrim"] [unique_id "ah5na_tfK-PO7exPDCDeiAAAmAQ"], referer https://www.bmkg.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[162985] [8IOFbb5A2GA] [ah5na_tfK-PO7exPDCDeiAAAmAQ] keep_alive=[1] [2026-06-02 12:17:31.542780] [R:ah5na_tfK-PO7exPDCDe
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-06-01 12:31:42
(2 months ago)
[Mon Jun 01 19:31:39.711452 2026] [security2:error] [pid 119548:tid 140305629157056] [client 72.63.2 ...
show more
[Mon Jun 01 19:31:39.711452 2026] [security2:error] [pid 119548:tid 140305629157056] [client 72.63.20.202:4168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.yahoo.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.yahoo.go.id found within REQUEST_HEADERS:Referer: https://www.yahoo.go.id/ request_line = GET /index-v100.js HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index-v100.js"] [unique_id "ah17q0qzjg26Y0kUu6V-2QABEwc"], referer https://www.yahoo.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[119595] [bwpLYPCJmIs] [ah17q0qzjg26Y0kUu6V-2QABEwc] keep_alive=[1] [2026-06-01 19:31:39.711466] [R:ah17q0qzjg26Y0kUu6V-2QABEwc] UA:'Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/124.0 Mobile/15E148 Safari/605.1.15' Host
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-05-20 03:50:36
(3 months ago)
[Wed May 20 10:50:32.394726 2026] [security2:error] [pid 485869:tid 140082852816576] [client 72.63.2 ...
show more
[Wed May 20 10:50:32.394726 2026] [security2:error] [pid 485869:tid 140082852816576] [client 72.63.20.202:7984] ModSecurity: Access denied with code 403 (phase 1). Match of "eq 0" against "&REQUEST_HEADERS:Transfer-Encoding" required. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "857"] [id "920171"] [msg "GET or HEAD Request with Transfer-Encoding"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: GET found within REQUEST_HEADERS: 1 request_line = GET /index.php HTTP/2.0 Request URI RAW = /index.php Request Basename = index.php"] [severity "CRITICAL"] [ver "OWASP_CRS/4.26.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php"] [unique_id "ag0viFwGGh5hdfOfqKe02wAAghg"]
...
show less
Email Spam
Hacking
Showing 1 to
7
of 7 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: