This IP address has been reported a total of
9
times from
7 distinct
sources.
109.252.161.9 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[MonAug2404:10:24.5085382026][security2:error][pid1503390:tid1503687][client109.252.161.9:0]ModSecur ...
show more[MonAug2404:10:24.5085382026][security2:error][pid1503390:tid1503687][client109.252.161.9:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"ticinoscout.ch\"][uri\"/templates/gridbox/library/icons/material/material.css\"][unique_id\"aouoEPLQaKM6IFPPZAum2QAAAUM\"]
show less
[SunAug2320:56:57.6632582026][security2:error][pid6068:tid6099][client109.252.161.9:0]ModSecurity:Ac ...
show more[SunAug2320:56:57.6632582026][security2:error][pid6068:tid6099][client109.252.161.9:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"domoticaswiss.ch\"][uri\"/media/sourcerer/js/popup.js\"][unique_id\"aotCebtIMJUk8yip8h99ywAAABQ\"]
show less
(mod_security) mod_security (id:210730) triggered by 109.252.161.9 (109-252-161-9.dynamic.spd-mgts.r ...
show more(mod_security) mod_security (id:210730) triggered by 109.252.161.9 (109-252-161-9.dynamic.spd-mgts.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 02:50:51.231986 2026] [security2:error] [pid 9684:tid 9700] [client 109.252.161.9:2213] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ureseal.com|F|2"] [data ".pkg_sourcerer.sys.ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ureseal.com"] [uri "/language/en-GB/en-GB.pkg_sourcerer.sys.ini"] [unique_id "aolGy6gLj_S5uCGfSHrriQAAAY4"], referer: https://ureseal.com/administrator/manifests/packages/pkg_sourcerer.xml
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
| [Dangerous/Russia] Aggressive IP 109.252.161.9 (~30 hits). Type: DoS Defender- Web server 400 erro ...
show more| [Dangerous/Russia] Aggressive IP 109.252.161.9 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
Showing 1 to
9
of 9 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ