AbuseIPDB » 107.172.116.119
107.172.116.119 was found in our database!
This IP was reported 8 times. Confidence of
Abuse
is 4% : ?
ISP
RackNerd LLC
Usage Type
Data Center/Web Hosting/Transit
ASN
AS36352
Hostname(s)
107-172-116-119-host.colocrossing.com
Domain Name
racknerd.com
Country
๐บ๐ธ
United States of America
City
Buffalo, New York
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 107.172.116.119 :
This IP address has been reported a total of
8
times from
4 distinct
sources.
107.172.116.119 was first reported on
July 29th 2025 , and the most recent report was
6 hours ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ซ๐ท
bigorre.org
2026-07-21 16:47:29
(6 hours ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
๐ซ๐ท
bigorre.org
2026-07-20 10:23:57
(1 day ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-01-17 15:21:19
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 107.172.116.119 (107-172-116-119-host.colocross ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.116.119 (107-172-116-119-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 10:21:14.238339 2026] [security2:error] [pid 8673:tid 8673] [client 107.172.116.119:35133] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/wp-content/plugins/jsmol2wp/php/jsmol.php"] [unique_id "aWuo6mYbQ4qY69Hi4rsfagAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 19:40:03
(6 months ago)
(mod_security) mod_security (id:210381) triggered by 107.172.116.119 (107-172-116-119-host.colocross ...
show more
(mod_security) mod_security (id:210381) triggered by 107.172.116.119 (107-172-116-119-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 14:39:55.611760 2025] [security2:error] [pid 22840:tid 22949] [client 107.172.116.119:38265] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||www.kettlehill.net|F|4"] [data "REQUEST_URI=/assets/built%2F..%2F..%2F%E0%A4%A/package.json"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.kettlehill.net"] [uri "/assets/built%2F..%2F..%2F%E0%A4%A/package.json"] [unique_id "aVLZC_USdzJ-gbjPWKhfvgAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-04 01:31:44
(7 months ago)
(mod_security) mod_security (id:221260) triggered by 107.172.116.119 (107-172-116-119-host.colocross ...
show more
(mod_security) mod_security (id:221260) triggered by 107.172.116.119 (107-172-116-119-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 03 20:31:40.345625 2025] [security2:error] [pid 26756:tid 26756] [client 107.172.116.119:42165] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||cpcalendars.farmers123.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.farmers123.com"] [uri "/debug.cgi"] [unique_id "aTDkfCnXM1t2jqk8G747xAAAACw"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-17 11:14:18
(8 months ago)
| Shellshock attack detected
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 10:23:55
(8 months ago)
(mod_security) mod_security (id:211190) triggered by 107.172.116.119 (107-172-116-119-host.colocross ...
show more
(mod_security) mod_security (id:211190) triggered by 107.172.116.119 (107-172-116-119-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 05:23:46.494142 2025] [security2:error] [pid 29316:tid 29316] [client 107.172.116.119:37855] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||ftp.nbcnewsradio.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /maint/modules/home/index.php?lang=english|cat%20/etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.nbcnewsradio.com"] [uri "/maint/modules/home/index.php"] [unique_id "aRWxshigc5_66ZesECfTIAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2025-07-29 04:00:02
(11 months ago)
IP was involved in L7 DDoS attack.
DDoS Attack
Showing 1 to
8
of 8 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: