AbuseIPDB » 104.168.118.135
104.168.118.135 was found in our database!
This IP was reported 8 times. Confidence of
Abuse
is 14% : ?
ISP
HostPapa
Usage Type
Data Center/Web Hosting/Transit
ASN
AS36352
Hostname(s)
104-168-118-135-host.colocrossing.com
Domain Name
hostpapa.com
Country
πΊπΈ
United States of America
City
Buffalo, New York
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 104.168.118.135 :
This IP address has been reported a total of
8
times from
5 distinct
sources.
104.168.118.135 was first reported on
March 12th 2022 , and the most recent report was
4 weeks ago .
Old Reports:
The most recent abuse report for this IP address is from
4 weeks ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
πΊπΈ
TPI-Abuse
2026-05-28 14:59:41
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.168.118.135 (104-168-118-135-host.colocross ...
show more
(mod_security) mod_security (id:210492) triggered by 104.168.118.135 (104-168-118-135-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 10:59:38.789505 2026] [security2:error] [pid 19842:tid 19855] [client 104.168.118.135:33253] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tristatepropertymgmt.com"] [uri "/.env.local"] [unique_id "ahhYWlqs3Rf8kAtJgj31UQAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-27 23:39:10
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.168.118.135 (104-168-118-135-host.colocross ...
show more
(mod_security) mod_security (id:210492) triggered by 104.168.118.135 (104-168-118-135-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 19:39:02.816335 2026] [security2:error] [pid 25310:tid 25310] [client 104.168.118.135:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.pixacast.com"] [uri "/.env.save"] [unique_id "aheAloFlFM2VKFd9l2gzTwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
big-cloud.nl
2026-05-27 22:56:57
(4 weeks ago)
Try to access /.aws/credentials
Web App Attack
π³π±
homeshowdomain.nl
2026-05-27 22:00:41
(4 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-26.
show less
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-05-27 00:31:05
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.168.118.135 (104-168-118-135-host.colocross ...
show more
(mod_security) mod_security (id:210492) triggered by 104.168.118.135 (104-168-118-135-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 20:30:50.853919 2026] [security2:error] [pid 18930:tid 18930] [client 104.168.118.135:50895] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.gapanda.com"] [uri "/.env.local"] [unique_id "ahY7OhEEnMn8n6lZPlCtbgAAAA4"], referer: https://www.google.com/search?q=cpanel.gapanda.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-26 17:54:09
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.168.118.135 (104-168-118-135-host.colocross ...
show more
(mod_security) mod_security (id:210492) triggered by 104.168.118.135 (104-168-118-135-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 13:53:45.917479 2026] [security2:error] [pid 19566:tid 19566] [client 104.168.118.135:40981] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.old" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "krugmans.net"] [uri "/wp-config.old"] [unique_id "ahXeKaPKadnUU6HEkqwX_wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Sklurk
2025-10-15 09:25:11
(8 months ago)
Web App Attack
Web App Attack
πΊπΈ
SiliSoftware
2022-03-12 01:33:56
(4 years ago)
manyexponentdetails=%D0%A0%D1%97%D0%A0%D1%95%D0%A0%D1%94%D0%A1%D1%93%D0%A0%D1%97%D0%A0%D1%94%D0%A0%C ...
show more
manyexponentdetails=%D0%A0%D1%97%D0%A0%D1%95%D0%A0%D1%94%D0%A1%D1%93%D0%A0%D1%97%D0%A0%D1%94%D0%A0%C2%B0%3B%D0%A1%D0%83%D0%A0%D1%91%D0%A0%D1%96%D0%A0%C2%B0%D0%A1%D0%82%D0%A0%C2%B5%D0%A1%E2%80%9A%3B%D0%A0%D1%95%D0%A0%D1%97%D0%A1%E2%80%9A%D0%A0%D1%95%D0%A0%D1%98%3Bhttp%3A%2F%2Fg9.www6.cn%2Findex.asp%3Fuser%3Dadmin&factordetails=&exponentdetails=&json=
show less
Web App Attack
Showing 1 to
8
of 8 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown π©
Recently Reported IPs: