AbuseIPDB » 158.181.42.59
158.181.42.59 was found in our database!
This IP was reported 8 times. Confidence of
Abuse
is 14% : ?
ISP
Aztelekom LLC
Usage Type
Fixed Line ISP
ASN
AS8814
Domain Name
aztelekom.az
Country
π¦πΏ
Azerbaijan
City
Ganja, GΗncΗ
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 158.181.42.59 :
This IP address has been reported a total of
8
times from
5 distinct
sources.
158.181.42.59 was first reported on
November 21st 2025 , and the most recent report was
2 days ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
π―π΅
jay hung
2026-07-25 07:16:22
(2 days ago)
2026-07-25T07:16:21.165228+00:00 quarktech kernel: [3608444.038696] [UFW BLOCK] IN=eth0 OUT= MAC=22: ...
show more
2026-07-25T07:16:21.165228+00:00 quarktech kernel: [3608444.038696] [UFW BLOCK] IN=eth0 OUT= MAC=22:00:92:2e:84:93:fe:ff:ff:ff:ff:ff:08:00 SRC=158.181.42.59 DST=172.237.20.248 LEN=60 TOS=0x00 PREC=0x00 TTL=32 ID=40993 DF PROTO=TCP SPT=9363 DPT=53 WINDOW=65535 RES=0x00 SYN URGP=0
...
show less
Port Scan
π¨π
backslash
2026-07-22 18:57:01
(5 days ago)
block ruleset 39D9DF3582BC0B50B0A9559A2D05D44391E672DC
Bad Web Bot
π©πͺ
SMARTNET
2026-05-27 06:03:53
(2 months ago)
Aisuru(Mirai variant) DDoS | Incident ID: 22ada211-5b5c-463a-b46f-60fd11dc639d
DDoS Attack
π¨π
backslash
2026-02-09 06:35:11
(5 months ago)
block ruleset 6B63410D189E6343B910F7440B8499558BEC52EB
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-01-28 17:03:59
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 158.181.42.59 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 158.181.42.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 28 12:03:53.140954 2026] [security2:error] [pid 25005:tid 25005] [client 158.181.42.59:19218] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.leothecolorman.com|F|2"] [data ".grovewood.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.leothecolorman.com"] [uri "/tag/rosinante/www.grovewood.com"] [unique_id "aXpBebHOXnry_btsBkJqEAAAAAw"], referer: https://www.leothecolorman.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-10 14:52:11
(7 months ago)
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized ac ...
show more
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized access"
show less
DDoS Attack
SQL Injection
Exploited Host
Anonymous
2025-11-25 16:51:32
(8 months ago)
scanning http requests from known botnet
Web App Attack
Anonymous
2025-11-21 16:28:24
(8 months ago)
scanning http requests from known botnet
Web App Attack
Showing 1 to
8
of 8 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown π©
Recently Reported IPs: