This IP address has been reported a total of
22
times from
19 distinct
sources.
149.22.84.135 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Credential stuffing attack observed. Multiple malicious login attempts using usernames/passwords ass ...
show moreCredential stuffing attack observed. Multiple malicious login attempts using usernames/passwords associated with known data breaches. 3 attempts recorded.
show less
Malicious IP detected by WAF with anomaly score 11.0. Attack types: Timestamp deviates by 2.0 hours, ...
show moreMalicious IP detected by WAF with anomaly score 11.0. Attack types: Timestamp deviates by 2.0 hours, Timestamp deviates by 1.6 hours, Timestamp deviates by 3.2 hours (+8 more). Activity: 9825 requests to 50 URLs. Period: 2025-08-08 11:01:14 - 2025-08-08 11:01:14 (America/Bogota). Origin: US. Source: Automated WAF log analysis.
show less
Triggered Cloudflare WAF (firewallCustom) from US.
ASN: 212238 (CDNEXT)
Protocol: HTTP/3 (GET method ...
show moreTriggered Cloudflare WAF (firewallCustom) from US.
ASN: 212238 (CDNEXT)
Protocol: HTTP/3 (GET method)
UA: Mozilla/5.0 (iPhone; CPU iPhone OS 18_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.5 Mobile/15E148 Safari/604.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.07.29 is noted in report tim ...
show moreAttempted brute force login to web vpn 2 time(s); last attempt for 2025.07.29 is noted in report timestamp
show less
(mod_security) mod_security (id:210492) triggered by 149.22.84.135 (unn-149-22-84-135.datapacket.com ...
show more(mod_security) mod_security (id:210492) triggered by 149.22.84.135 (unn-149-22-84-135.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 27 22:44:44.102852 2025] [security2:error] [pid 18666:tid 18666] [client 149.22.84.135:42218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sieder.com.ar"] [uri "/.git/config"] [unique_id "aIbkHCf0Lcb0JI-EOmGFvQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.06.06 is noted in report tim ...
show moreAttempted brute force login to web vpn 1 time(s); last attempt for 2025.06.06 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.05.29 is noted in report tim ...
show moreAttempted brute force login to web vpn 2 time(s); last attempt for 2025.05.29 is noted in report timestamp
show less