Go
197.254.38.250
is an
Open Proxy
used by
Abusers
100 %
Kenya
Report Abuse
41abuse reported
12Email SpamBrute-Force
10Email Spam
7Web SpamForum Spam
3Email SpamExploited Host
3uncategorized
2Bad Web BotWeb SpamBlog Spam
1Email SpamHacking
1Bad Web BotWeb App Attack
1Web Spam
1Web SpamBad Web BotBlog SpamForum Spam
32attacks reported
10uncategorized
7Brute-ForceMailserver Attack
4Brute-Force
2Brute-ForceExploited Host
2DDoS AttackEmail SpamBrute-Force
2Email Spam
1SQL Injection
1Fraud OrdersEmail Spam
1SSH
1Web App AttackCMS Attack
...
19anonymizers reported
19Open Proxy
6spam reported
5uncategorized
1Email Spam
from 30 distinct reporters
and 15 distinct sources : CleanTalk, FireHOL, Charles Haley, sblam.com, Free Proxy List, StopForumSpam.com, GPF Comics, BadIPs.com, Blocklist.de, ProxyLists.net, ProxyRSS.com, ProxZ.com, blocklist.net.ua, darklist.de, AbuseIPDB
197.254.38.250 was first signaled at 2019-02-21 23:50 and last record was at 2019-09-12 13:45.
IP

197.254.38.250

Organization
AccessKenya Group Ltd
Localisation
Kenya
NetRange : First & Last IP
197.254.0.0 - 197.254.127.255
Network CIDR
197.254.0.0/17

Cybercrime IP Feeds

Date UTC Category Sub Categories Source List Source Logs
2019-09-12 13:45 abuse Email Spam AbuseIPDB Mail sent to address hacked/leaked from Last.fm
2019-09-12 05:18 attacks Brute-Force AbuseIPDB Postfix Brute-Force reported by Fail2Ban
2019-09-11 09:17 abuse Email SpamBrute-Force AbuseIPDB proto=tcp . spt=49890 . dpt=25 . (listed on Blocklist de Sep 11) (711)
2019-09-07 03:42 abuse Email SpamExploited Host AbuseIPDB [ER hit] Tried to deliver spam. Already well known.
2019-09-06 09:00 abuse Email Spam AbuseIPDB Sent mail to address hacked/leaked from Dailymotion
2019-09-03 02:21 attacks Brute-Force AbuseIPDB Unauthorized connection attempt from IP address 197.254.38.250 on Port 25(SMTP)
2019-09-01 08:11 abuse Email Spam AbuseIPDB blacklist
2019-08-29 07:46 attacks Brute-ForceExploited Host AbuseIPDB Brute force attempt
2019-08-27 10:38 abuse Email SpamHacking AbuseIPDB IP: 197.254.38.250 ASN: AS15808 ACCESSKENYA GROUP LTD is an ISP serving Port: Simple Mail Transfer 25 Found in one or more Blacklists Date: 27/08/2019
2019-08-26 17:15 abuse Email SpamBrute-Force AbuseIPDB proto=tcp . spt=58636 . dpt=25 . (listed on Blocklist de Aug 26) (171)
2019-08-25 17:33 attacks Brute-Force AbuseIPDB Unauthorized connection attempt from IP address 197.254.38.250 on Port 25(SMTP)
2019-08-25 02:05 abuse Email Spam AbuseIPDB Aug 25 05:04:44 mail postfix/postscreen[47360]: PREGREET 36 after 1 from [197.254.38.250]:52336: EHLO 197.254.38.250.acesskenya.net\r\n
2019-08-23 16:02 abuse Email Spam AbuseIPDB Sent mail to target address hacked/leaked from abandonia in 2016
2019-08-22 15:15 abuse Email SpamBrute-Force AbuseIPDB proto=tcp . spt=49007 . dpt=25 . (listed on Blocklist de Aug 22) (82)
2019-08-22 10:32 abuse Email Spam AbuseIPDB  
2019-08-15 07:23 attacks DDoS AttackEmail SpamBrute-Force AbuseIPDB Autoban 197.254.38.250 AUTH/CONNECT
2019-08-14 03:55 abuse Email Spam AbuseIPDB Mail sent to address harvested from public web site
2019-08-07 06:37 attacks DDoS AttackEmail SpamBrute-Force AbuseIPDB Autoban 197.254.38.250 AUTH/CONNECT
2019-08-07 03:04 abuse Email SpamExploited Host AbuseIPDB [ER hit] Tried to deliver spam. Already well known.
2019-08-05 13:12 abuse Email Spam AbuseIPDB Spam to target mail address hacked/leaked/bought from Kachingle
2019-08-03 18:31 attacks Brute-Force AbuseIPDB Unauthorized connection attempt from IP address 197.254.38.250 on Port 25(SMTP)
2019-08-03 14:14 abuse Email SpamBrute-Force AbuseIPDB proto=tcp . spt=44655 . dpt=25 . (listed on Blocklist de Aug 03) (9)
2019-07-25 07:17 abuse Email SpamExploited Host AbuseIPDB [ER hit] Tried to deliver spam. Already well known.
2019-07-22 11:01 abuse Bad Web BotWeb App Attack AbuseIPDB Unauthorized access detected from banned ip
2019-07-22 06:39 abuse Email SpamBrute-Force AbuseIPDB 2019-07-21 13:18:25 H=(197.254.38.250.acesskenya.net) [197.254.38.250]:51404 I=[192.147.25.65]:25 F=<[email protected]> rejected RCPT <[
2019-07-17 12:13 abuse Email SpamBrute-Force AbuseIPDB proto=tcp . spt=48054 . dpt=25 . (listed on Blocklist de Jul 17) (735)
2019-07-13 12:42 attacks Brute-ForceExploited Host AbuseIPDB Brute force attempt
2019-07-11 03:01 abuse Email Spam AbuseIPDB SpamReport
2019-05-22 23:49 attacks SQL Injection AbuseIPDB 197.254.38.250 - - [23/May/2019:04:49:25 -0400] "GET /?page=&manufacturerID=..%2f..%2fetc%2fpasswd&collectionID= HTTP/1.1" 200 16462
2019-05-15 21:04 abuse Email SpamBrute-Force AbuseIPDB SMTP/25/465/587 Probe, Reject, BadAuth, SPAM -
2019-04-30 05:28 attacks Fraud OrdersEmail Spam AbuseIPDB SMTP Fraud Orders
2019-04-13 18:50 abuse Email SpamBrute-Force AbuseIPDB SMTP/25/465/587 Probe, Reject, BadAuth, SPAM -
2019-03-31 14:24 abuse Email SpamBrute-Force AbuseIPDB SMTP/25/465/587 Probe, Reject, BadAuth, SPAM -
2019-03-19 23:20 abuse Email SpamBrute-Force AbuseIPDB SMTP/25/465/587 Probe, Reject, BadAuth, SPAM -
2019-03-03 17:20 abuse Email SpamBrute-Force AbuseIPDB SMTP/25/465/587 Probe, Reject, BadAuth, SPAM -
2019-03-01 20:11 abuse Web Spam AbuseIPDB POST /index.php HTTP/1.1 500 - index.php?productID=207-discuss=yesMozilla/4.0 (Compatible; MSIE 5.5; Windows NT 4.0; QXW03002)
2019-02-21 23:50 abuse Email SpamBrute-Force AbuseIPDB SMTP/25/465/587 Probe, Reject, BadAuth, SPAM -
2019-03-29 18:22 abuse Bad Web BotWeb SpamBlog Spam cleantalk_30d CleanTalk  
2019-03-29 18:23 abuse Bad Web BotWeb SpamBlog Spam cleantalk_updated_30d CleanTalk  
2019-03-29 18:27 abuse firehol_abusers_30d FireHOL  
2019-03-29 18:28 attacks firehol_level4 FireHOL  
2019-03-29 18:34 anonymizers Open Proxy firehol_proxies FireHOL  
2019-03-29 18:35 attacks SSH haley_ssh Charles Haley  
2019-03-29 18:40 spam lashback_ubl  
2019-03-29 18:41 spam Email Spam nixspam  
2019-03-29 18:42 abuse Web SpamBad Web BotBlog SpamForum Spam sblam sblam.com  
2019-03-29 18:43 anonymizers Open Proxy sslproxies_30d Free Proxy List  
2019-03-29 18:45 abuse Web SpamForum Spam stopforumspam StopForumSpam.com  
2019-03-29 18:47 abuse Web SpamForum Spam stopforumspam_180d StopForumSpam.com  
2019-03-29 18:51 abuse Web SpamForum Spam stopforumspam_365d StopForumSpam.com  
2019-03-29 18:52 abuse Web SpamForum Spam stopforumspam_90d StopForumSpam.com  
2019-05-28 23:28 abuse firehol_abusers_1d FireHOL  
2019-05-28 23:34 abuse gpf_comics GPF Comics  
2019-05-28 23:40 anonymizers Open Proxy socks_proxy_30d Free Proxy List  
2019-05-28 23:40 anonymizers Open Proxy socks_proxy_7d Free Proxy List  
2019-05-28 23:40 anonymizers Open Proxy sslproxies_7d Free Proxy List  
2019-05-28 23:42 abuse Web SpamForum Spam stopforumspam_1d StopForumSpam.com  
2019-05-28 23:43 abuse Web SpamForum Spam stopforumspam_30d StopForumSpam.com  
2019-05-28 23:44 abuse Web SpamForum Spam stopforumspam_7d StopForumSpam.com  
2019-06-04 22:30 anonymizers Open Proxy socks_proxy_1d Free Proxy List  
2019-06-18 08:28 attacks bi_any_0_1d BadIPs.com  
2019-06-18 08:28 attacks bi_any_1_7d BadIPs.com  
2019-06-18 08:28 attacks bi_any_2_1d BadIPs.com  
2019-06-18 08:29 attacks bi_any_2_30d BadIPs.com  
2019-06-18 08:29 attacks bi_any_2_7d BadIPs.com  
2019-06-18 08:29 attacks Brute-ForceMailserver Attack bi_mail_0_1d BadIPs.com  
2019-06-18 08:29 attacks Brute-ForceMailserver Attack bi_mail_1_7d BadIPs.com  
2019-06-18 08:29 attacks Brute-ForceMailserver Attack bi_mail_2_30d BadIPs.com  
2019-06-18 08:29 attacks Brute-ForceMailserver Attack bi_postfix_0_1d BadIPs.com  
2019-06-18 08:29 attacks Brute-ForceMailserver Attack bi_postfix_1_7d BadIPs.com  
2019-06-18 08:29 attacks Brute-ForceMailserver Attack bi_postfix_2_30d BadIPs.com  
2019-06-19 07:33 attacks blocklist_de Blocklist.de  
2019-06-19 07:34 attacks Brute-ForceMailserver Attack blocklist_de_mail Blocklist.de  
2019-06-19 07:39 attacks firehol_level2 FireHOL  
2019-06-25 01:47 anonymizers Open Proxy proxylists_1d ProxyLists.net  
2019-06-25 01:47 anonymizers Open Proxy proxylists_30d ProxyLists.net  
2019-06-25 01:47 anonymizers Open Proxy proxylists_7d ProxyLists.net  
2019-06-25 01:47 anonymizers Open Proxy proxyrss_1d ProxyRSS.com  
2019-06-25 01:47 anonymizers Open Proxy proxyrss_30d ProxyRSS.com  
2019-06-25 01:47 anonymizers Open Proxy proxyrss_7d ProxyRSS.com  
2019-06-28 22:52 anonymizers Open Proxy proxyrss ProxyRSS.com  
2019-07-04 15:53 anonymizers Open Proxy proxylists ProxyLists.net  
2019-07-05 14:45 anonymizers Open Proxy proxz_1d ProxZ.com  
2019-07-05 14:45 anonymizers Open Proxy proxz_30d ProxZ.com  
2019-07-05 14:45 anonymizers Open Proxy proxz_7d ProxZ.com  
2019-07-09 10:38 attacks Email Spam bi_spam_0_1d BadIPs.com  
2019-07-09 10:38 attacks Email Spam bi_spam_1_7d BadIPs.com  
2019-07-31 18:14 spam php_dictionary  
2019-07-31 18:14 spam php_dictionary_1d  
2019-07-31 18:14 spam php_dictionary_30d  
2019-07-31 18:14 spam php_dictionary_7d  
2019-07-31 18:15 anonymizers Open Proxy sslproxies_1d Free Proxy List  
2019-08-20 17:18 abuse Email Spam blocklist_net_ua blocklist.net.ua  
2019-08-23 14:23 attacks Web App AttackCMS Attack bi_cms_0_1d BadIPs.com  
2019-08-23 14:23 attacks bi_http_0_1d BadIPs.com  
2019-08-23 14:25 attacks Brute-ForceWindows RDP Attack bi_wordpress_0_1d BadIPs.com  
2019-09-08 21:57 anonymizers Open Proxy sslproxies Free Proxy List  
2019-09-10 19:36 attacks darklist_de darklist.de  
only last 50 and first 10 AbuseIPDB logs are shown

Threats Categories :

abuse
IPs used to spam forum, boards, blogs or smtp servers, automated web scripts or scrappers (bad bots)
anonymizer
Onion Router IP addresses. TOR network IPs, TOR exit points, socks or ssl proxy.
attacks
bruteforce ssh/ftp/system account, IPs that have been detected by fail2ban, ports scan, vulnerabilities scan, DDoS.
malware
Addresses that have been identified distributing malware, form-grabber and stealer, Viruses, Worms, Trojans, Ransomware, Adware, Spyware

Whois

inetnum: 197.254.0.0 - 197.254.127.255
netname: KE-COMMSOL
descr: Access Kenya Group Ltd
country: KE
org: ORG-CSL1-AFRINIC
admin-c: MR48-AFRINIC
admin-c: KH4-AFRINIC
admin-c: NPS2007-AFRINIC
tech-c: MR48-AFRINIC
tech-c: NPS2007-AFRINIC
status: ALLOCATED PA
mnt-by: AFRINIC-HM-MNT
mnt-lower: ACCESSKENYA-MNT
source: AFRINIC # Filtered
parent: 197.0.0.0 - 197.255.255.255

organisation: ORG-CSL1-AFRINIC
org-name: AccessKenya Group Ltd
org-type: LIR
country: KE
remarks: data has been transferred from RIPE Whois Database 20050221
address: Access Kenya Group Ltd
address: 4th Floor, Purshottam Place
address: Westlands Road
address: P O Box 43588
address: Nairobi 0100
phone: tel:+254-20-3742107
phone: tel:+254-20-3600000
phone: tel:+254-20-3600200
admin-c: MR48-AFRINIC
admin-c: KH4-AFRINIC
admin-c: NPS2007-AFRINIC
tech-c: MR48-AFRINIC
tech-c: NPS2007-AFRINIC
mnt-ref: AFRINIC-HM-MNT
mnt-ref: ACCESSKENYA-MNT
mnt-by: AFRINIC-HM-MNT
source: AFRINIC # Filtered

person: Kaveer Harie
address: The Campus
address: 57 Sloane Street
address: Bryanston
address: Johannesburg
address: South Africa
phone: tel:+27-11-575-0211
fax-no: tel:+27-11-576-6927
nic-hdl: KH4-AFRINIC
mnt-by: GENERATED-YKGODFMFNDNTIDPAJHP0XIXOBKCH1EYH-MNT
source: AFRINIC # Filtered

person: MARTIN RATEMO
address: Access Kenya Group Ltd, 4th Floor, Purushottam Place, Westlands Road, P O Box 43588, Nairobi, Kenya
phone: tel:+254-732-136532
nic-hdl: MR48-AFRINIC
mnt-by: GENERATED-RCTQLV05H0BRBNCDMBK5FJWXHZIPOOL3-MNT
source: AFRINIC # Filtered

person: AccessKenya IP Administrators
address: 4th Floor,
address: Purshottam Place
address: Westlands Road
address: Nairobi
address: Kenya
phone: tel:+254-20-3600000
nic-hdl: NPS2007-AFRINIC
mnt-by: GENERATED-NYGCRCHF7U9QZPQGT1HYFPDJ4LAL09IB-MNT
source: AFRINIC # Filtered

route: 197.254.80.0/20
descr: ACCESSKENYA - 197.254.80.0/20
origin: AS15808
mnt-by: ACCESSKENYA-MNT
source: AFRINIC # Filtered
most specific ip range is highlighted
Updated : 2019-07-25