AbuseIPDB » 157.22.44.50
157.22.44.50 was found in our database!
This IP was reported 7 times. Confidence of
Abuse
is 15% : ?
ISP
Global Transit Systems LLC
Usage Type
Data Center/Web Hosting/Transit
ASN
AS213954
Domain Name
globaltransitsystems.online
Country
πΈπͺ
Sweden
City
Marsta, Stockholm
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 157.22.44.50 :
This IP address has been reported a total of
7
times from
6 distinct
sources.
157.22.44.50 was first reported on
January 20th 2026 , and the most recent report was
6 days ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
π©πͺ
FeG Deutschland
2026-06-11 15:54:57
(6 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-13 17:40:15
(1 month ago)
(mod_security) mod_security (id:218580) triggered by 157.22.44.50 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:218580) triggered by 157.22.44.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 13:40:11.414660 2026] [security2:error] [pid 21900:tid 21900] [client 157.22.44.50:11337] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:\\\\/\\\\*[!+](?:[\\\\w\\\\s=_\\\\-()]+)?\\\\*\\\\/)" at ARGS:/category/154/start-192. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "76"] [id "218580"] [rev "1"] [msg "COMODO WAF: MySQL in-line comment detected.||www.genesis-castle.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "www.genesis-castle.com"] [uri "/gallery/index.php"] [unique_id "agS3e8_3Op61vKu8wgVDZAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π±
everkey
2026-04-20 09:23:00
(1 month ago)
157.22.44.50 20/Apr/2026:05:23:28 -0400 "GET / HTTP/1.1" 200 13660 "-" "Mozilla/5.0 (X11; CrOS x86_ ...
show more
157.22.44.50 20/Apr/2026:05:23:28 -0400 "GET / HTTP/1.1" 200 13660 "-" "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36"
157.22.44.50 20/Apr/2026:05:23:30 -0400 "GET /wp-login.php?action=register HTTP/1.1" 301 0 "https://miweb.com/" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
Hacking
π¨π΄
conexcol
2026-03-26 19:17:48
(2 months ago)
(mod_security) mod_security (id:99001) triggered by 157.22.44.50 (DE/Germany/-): 5 in the last 3600 ...
show more
(mod_security) mod_security (id:99001) triggered by 157.22.44.50 (DE/Germany/-): 5 in the last 3600 secs
show less
Brute-Force
πΊπΈ
TPI-Abuse
2026-03-22 03:08:52
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.44.50 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.44.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 23:08:45.707022 2026] [security2:error] [pid 14204:tid 14204] [client 157.22.44.50:21061] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||drumez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "drumez.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ab9dPSE3pvOTjNGipr2khgAAABk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
kjaerulff
2026-03-11 14:59:38
(3 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
Anonymous
2026-01-20 19:02:18
(4 months ago)
wordpress-trap
Web App Attack
Showing 1 to
7
of 7 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown π©
Recently Reported IPs: