AbuseIPDB » 104.164.118.18
104.164.118.18 was found in our database!
This IP was reported 8 times. Confidence of
Abuse
is 42% : ?
ISP
EGIHosting
Usage Type
Data Center/Web Hosting/Transit
ASN
AS212238
Domain Name
egihosting.com
Country
π«π·
France
City
Marseille, Provence-Alpes-Cote d'Azur
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 104.164.118.18 :
This IP address has been reported a total of
8
times from
8 distinct
sources.
104.164.118.18 was first reported on
August 5th 2026 , and the most recent report was
2 days ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
π¦πΊ
FireGuard Server
2026-08-26 15:45:09
(2 days ago)
Blocked by os-abuseipdb; 4 hits, proto=tcp, ports=443
Port Scan
Hacking
π©πͺ
bancix
2026-08-22 18:33:49
(6 days ago)
Heimdall NIDS: Automatic ban triggered. Reason: RST_LIMIT_EXCEEDED (5/5)
Port Scan
π«π·
COMAITE
2026-08-17 13:10:25
(1 week ago)
SQL injection attempt from 104.164.118.18.
Web App Attack
π³π±
DrLex0
2026-08-16 00:48:22
(1 week ago)
BnL006: Obvious dumb distributed botnet crawler stepping into honeypot trap, violating robots.txt an ...
show more
BnL006: Obvious dumb distributed botnet crawler stepping into honeypot trap, violating robots.txt and meta directives
104.164.118.18 443 - [16/Aug/2026:00:48:22 +0000] "GET [redacted] HTTP/1.1" 200 7074 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36"
show less
Bad Web Bot
Exploited Host
π«π·
saythe.name
2026-08-13 08:05:59
(2 weeks ago)
Auto-Ban [2026-08-13 08:05:59]: CRITICAL: bot trap (soft) | route=/api/trap/internal/reviews-sync | ...
show more
Auto-Ban [2026-08-13 08:05:59]: CRITICAL: bot trap (soft) | route=/api/trap/internal/reviews-sync | hits=1 | ua=Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like
show less
Hacking
Web App Attack
Anonymous
2026-08-12 21:09:02
(2 weeks ago)
Malicious activity detected
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-12 05:19:32
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 104.164.118.18 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.164.118.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 01:19:23.480541 2026] [security2:error] [pid 4112304:tid 4112304] [client 104.164.118.18:60032] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||anbruswebdesign.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "anbruswebdesign.com"] [uri "/[email protected] "] [unique_id "anwCW2Fzu7yKuaGQxP7bQAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
backslash
2026-08-05 14:18:00
(3 weeks ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
Showing 1 to
8
of 8 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown π©
Recently Reported IPs: