AbuseIPDB » 188.172.111.85
188.172.111.85 was found in our database!
This IP was reported 3 times. Confidence of
Abuse
is 4% : ?
ISP
Vodafone Albania Mobile
Usage Type
Mobile ISP
ASN
AS50973
Domain Name
vodafone.com
Country
๐ฆ๐ฑ
Albania
City
Tirana, Tirana
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 188.172.111.85 :
This IP address has been reported a total of
3
times from
2 distinct
sources.
188.172.111.85 was first reported on
November 16th 2025 , and the most recent report was
2 days ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐บ๐ธ
TPI-Abuse
2026-09-28 20:31:48
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 188.172.111.85 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 188.172.111.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 16:31:42.058676 2026] [security2:error] [pid 26373:tid 26373] [client 188.172.111.85:42198] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||circleinthesquare.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "circleinthesquare.org"] [uri "/"] [unique_id "arrOrmbRIra2sAnq4z0tewAAAAU"], referer: https://stlouisgalleryguide.blogspot.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 09:46:13
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 188.172.111.85 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 188.172.111.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 05:46:09.354382 2026] [security2:error] [pid 10776:tid 10776] [client 188.172.111.85:40431] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||refreshmc.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "refreshmc.com"] [uri "/"] [unique_id "aro3YQhD-4hxv-2eRyyMjwAAAA4"], referer: https://bulkbacklinkanalysis.website/dir/competitive-seo-backlinks-174179
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-16 11:23:54
(10 months ago)
scanning http requests from known botnet
Web App Attack
Showing 1 to
3
of 3 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: