AbuseIPDB » 172.121.164.242
172.121.164.242 was found in our database!
This IP was reported 5 times. Confidence of
Abuse
is 24% : ?
ISP
EGIHosting
Usage Type
Data Center/Web Hosting/Transit
ASN
AS3257
Domain Name
egihosting.com
Country
๐บ๐ธ
United States of America
City
Dallas, Texas
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 172.121.164.242 :
This IP address has been reported a total of
5
times from
4 distinct
sources.
172.121.164.242 was first reported on
October 18th 2024 , and the most recent report was
1 week ago .
Old Reports:
The most recent abuse report for this IP address is from
1 week ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ฉ๐ช
bescared
2026-08-24 06:11:00
(1 week ago)
WAF (2) - Malicious activity detected: URL probing.
Bad Web Bot
Web App Attack
Hacking
๐ฎ๐น
A000Z
2026-08-24 00:35:56
(1 week ago)
Fail2Ban: 172.121.164.242 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/ ...
show more
Fail2Ban: 172.121.164.242 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-12 05:08:18
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 172.121.164.242 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 172.121.164.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 01:08:11.879513 2026] [security2:error] [pid 7268:tid 7268] [client 172.121.164.242:21810] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.rimworld.com|F|2"] [data ".marsasystems.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.rimworld.com"] [uri "/www.marsasystems.com"] [unique_id "anv_u48vK4Tt1KX-DoOdIQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-08-02 02:42:02
(4 weeks ago)
block ruleset 798ECF92F12ADC636D3520C2890AF17ADEFDE3BE
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-10-18 12:06:58
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 172.121.164.242 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 172.121.164.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 18 08:06:51.458486 2024] [security2:error] [pid 1287916:tid 1287916] [client 172.121.164.242:8768] [client 172.121.164.242] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Steelcase/pics/Siento/Thumbs.db"] [unique_id "ZxJPW-pNEr2a6nm4Lz_XhgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Showing 1 to
5
of 5 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: