AbuseIPDB » 102.216.117.213
102.216.117.213 was found in our database!
This IP was reported 8 times. Confidence of
Abuse
is 18%: ?
| ISP |
SAVENET NETWORKS
|
| Usage Type |
Fixed Line ISP
|
| ASN |
AS329021
|
| Domain Name |
savenet.co.ke
|
| Country |
๐ฐ๐ช
Kenya
|
| City |
Nairobi, Nairobi County
|
IP info including ISP, Usage Type, and Location provided
by IPInfo. Updated weekly.
IP Abuse Reports for 102.216.117.213:
This IP address has been reported a total of
8
times from
7 distinct
sources.
102.216.117.213 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
| Reporter |
IoA Timestamp (UTC)
|
Comment |
Categories |
|
|
๐บ๐ธ
stechusa
|
|
ELEVATED_THREAT | 31 IPs targeting /brand/satco-products-inc/satco-light-bulbs.html | Facet request ...
show more
ELEVATED_THREAT | 31 IPs targeting /brand/satco-products-inc/satco-light-bulbs.html | Facet request during elevated threat (facet_ratio=0.88, unique_ips=509) | HTTP/1.1 over TLS (elevated=True)
show less
|
Bad Web Bot
DDoS Attack
|
|
|
๐ฉ๐ช
Vegascosmetics
|
|
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after obfuscated redirect. Vegas Security
|
DDoS Attack
Hacking
Exploited Host
|
|
|
๐บ๐ธ
kosada.com
|
|
Web bot: denial-of-service flood
|
DDoS Attack
Bad Web Bot
|
|
|
๐บ๐ธ
RAP
|
|
2026-05-01 17:49:46 UTC Unauthorized activity to TCP port 23. Telnet
|
Port Scan
|
|
|
Anonymous
|
|
Unauthorized connection attempt
|
Port Scan
Hacking
Exploited Host
|
|
|
๐ฉ๐ช
EGP Abuse Dept
|
|
Scraping webshop URLs (www.awardkopen.nl), likely botnet drone
|
Bad Web Bot
Exploited Host
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 102.216.117.213 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 102.216.117.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 24 12:55:53.580469 2026] [security2:error] [pid 26445:tid 26445] [client 102.216.117.213:39646] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.austli.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.austli.com"] [uri "/norkyn.com"] [unique_id "aZ3mKSdFJIGn6hJGI5eZ-wAAAAM"], referer: http://www.austli.com/
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:218580) triggered by 102.216.117.213 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:218580) triggered by 102.216.117.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 12:12:24.556659 2026] [security2:error] [pid 4254:tid 4254] [client 102.216.117.213:51242] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:\\\\/\\\\*[!+](?:[\\\\w\\\\s=_\\\\-()]+)?\\\\*\\\\/)" at ARGS:autoplay. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "76"] [id "218580"] [rev "1"] [msg "COMODO WAF: MySQL in-line comment detected.||www.caferutadelaseda.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "www.caferutadelaseda.com"] [uri "/player"] [unique_id "aZyKeJQB94SmdvWtsQoqIwAAABA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
Showing 1 to
8
of 8 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: