Log in to view charts and search reports for this IP.
Log In
Top Reporter Countries (Last 60 Days)
Example preview
Report Categories (Last 60 Days)
Example preview
Reports Activity
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 138.252.26.6:
This IP address has been reported a total of
18
times from
17 distinct
sources.
138.252.26.6 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 4
reports;
United States of America
with 3
reports;
Switzerland
with 1
report.
The most common categories in these recent reports were:
Bad Web Bot
5
times;
Brute-Force
3
times;
Port Scan
3
times;
DDoS Attack
1
time;
Exploited Host
1
time;
Other
3
times.
Old Reports
The most recent abuse report for this IP address is from
. It is possible that this IP is no
longer involved in abusive activities.
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0. ...
show moreMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
show less
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show moreDistributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in printer-friendly.asp
show less
Auto-blocked by Seczar SecureOps — High-Risk Port Probe (admin-managed entries) — SSH (5 events in 5 ...
show moreAuto-blocked by Seczar SecureOps — High-Risk Port Probe (admin-managed entries) — SSH (5 events in 5min) at 2026-08-21 06:09
show less
Web App Attack
Anonymous
denied Telnet access attempt. destination port 23.
Blocked by UFW (TCP on 23)
Source port: 36680
TTL: 51
Packet length: 60
TOS: 0x00
This report (for ...
show moreBlocked by UFW (TCP on 23)
Source port: 36680
TTL: 51
Packet length: 60
TOS: 0x00
This report (for 138.252.26.6) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Jul 04 09:58:37 rapi wings[29964]: 2026/07/04 09:58:36 http: TLS handshake error from 138.252.26.6:3 ...
show moreJul 04 09:58:37 rapi wings[29964]: 2026/07/04 09:58:36 http: TLS handshake error from 138.252.26.6:39096: tls: first record does not look like a TLS handshake
Jul 04 09:58:37 rapi wings[29964]: 2026/07/04 09:58:36 http: TLS handshake error from 138.252.26.6:39382: tls: first record does not look like a TLS handshake
Jul 04 09:58:49 rapi wings[29964]: 2026/07/04 09:58:49 http: TLS handshake error from 138.252.26.6:41934: tls: first record does not look like a TLS handshake
Jul 04 09:58:54 rapi wings[29964]: 2026/07/04 09:58:54 http: TLS handshake error from 138.252.26.6:42668: tls: first record does not look like a TLS handshake
Jul 04 09:59:06 rapi wings[29964]: 2026/07/04 09:59:06 http: TLS handshake error from 138.252.26.6:45344: tls: first record does not look like a TLS handshake
show less
Credential-stuffing / bot against Billease consumer login (auth/token): 5 distinct usernames sprayed ...
show moreCredential-stuffing / bot against Billease consumer login (auth/token): 5 distinct usernames sprayed with ~100% failure ratio during 2026-06-29..07-02 attack. Datacenter IP (Rapid Connect Networks Corporation t/a R-Connect); no legitimate customer traffic. Automated report.
show less