AbuseIPDB » 185.55.4.210
185.55.4.210 was found in our database!
This IP was reported 5 times. Confidence of
Abuse
is 14% : ?
ISP
Segna Technologies Virginia
Usage Type
Fixed Line ISP
ASN
AS5650
Domain Name
segnatek.com
Country
๐บ๐ธ
United States of America
City
Ashburn, Virginia
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 185.55.4.210 :
This IP address has been reported a total of
5
times from
4 distinct
sources.
185.55.4.210 was first reported on
April 13th 2025 , and the most recent report was
1 day ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ณ๐ฑ
Savvii
2026-07-22 03:44:05
(1 day ago)
20 attempts against mh-misbehave-ban on pavo
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-21 23:19:03
(1 day ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-20 16:43:52
(10 months ago)
(mod_security) mod_security (id:210350) triggered by 185.55.4.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 185.55.4.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 20 12:43:45.299121 2025] [security2:error] [pid 15330:tid 15330] [client 185.55.4.210:38545] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||groupof12.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "groupof12.com"] [uri "/"] [unique_id "aM7Zwf3AKCMlT2HajC-RnQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-11 22:59:49
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 185.55.4.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 185.55.4.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 11 18:59:37.224979 2025] [security2:error] [pid 18547:tid 18547] [client 185.55.4.210:28903] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||billyclouse.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "billyclouse.com"] [uri "/mailto:[email protected] "] [unique_id "aMNUWfISPyuNfcgZZqy1lQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
wil.com
2025-04-13 18:16:59
(1 year ago)
GlobalProtect login attempts with user infouk.
VPN IP
Brute-Force
Showing 1 to
5
of 5 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: