This IP address has been reported a total of
7
times from
6 distinct
sources.
201.221.119.255 was first reported on
October 29th 2023 , and the most recent report was
19 hours ago .
In the last 60 days, the top reporter locations were:
United States of America
with 2
reports;
Germany
with 1
report;
Romania
with 1
report.
The most common categories in these recent reports were:
Bad Web Bot
3
times;
Web App Attack
2
times;
Brute-Force
1
time;
DDoS Attack
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
🇺🇸
TPI-Abuse
2026-10-03 16:32:58
(19 hours ago)
(mod_security) mod_security (id:210350) triggered by 201.221.119.255 (201.221.119.255.cidadei.com.br ...
show more
(mod_security) mod_security (id:210350) triggered by 201.221.119.255 (201.221.119.255.cidadei.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 12:32:54.651151 2026] [security2:error] [pid 18054:tid 18054] [client 201.221.119.255:4572] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||deweysearch.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "deweysearch.com"] [uri "/"] [unique_id "asEuNnHJvGs_tsV8iK3UeAAAAAo"], referer: https://thelinkbuilding.online/dir/professional-backlink-building-54054
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-08-26 04:56:05
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
🇩🇪
FD-IX
2026-08-26 01:18:52
(1 month ago)
Fail2Ban: Automated WooCommerce filter abuse from distributed botnet activity.
Bad Web Bot
🇷🇴
INTEQ
2026-08-08 06:02:19
(1 month ago)
Web attack from 201.221.119.255
Web App Attack
🇺🇸
kosada.com
2026-08-01 05:00:12
(2 months ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
🇮🇩
hermawan
2025-10-08 20:43:31
(11 months ago)
[Thu Oct 09 00:38:15.430571 2025] [security2:error] [pid 1799036:tid 140370805520064] [client 201.22 ...
show more
[Thu Oct 09 00:38:15.430571 2025] [security2:error] [pid 1799036:tid 140370805520064] [client 201.221.119.255:60761] ModSecurity: Access denied with code 403 (phase 1). Match of "ipMatch 103.166.156.58" against "REMOTE_ADDR" required. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "372"] [id "440006"] [msg "Connection Close Header"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: close found within REMOTE_ADDR: 201.221.119.255 request_line = GET /robots.txt HTTP/1.1 Request URI RAW = /robots.txt Request Basename = robots.txt"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aOahhzALsbl3f1V8Ft1CcAAAA4I"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[1799065] [kAwXJun+n+k] [aOahhzALsbl3f1V8Ft1CcAAAA4I] keep_alive=[0] [2025-10-09 00:38:15.430578] [R:aOahhzALsbl3f1V8Ft1CcAAAA4I] UA:'Mozilla/5.0 (Linux; Android 5.0; SM-G900P Build/LRX21T) AppleW
...
show less
Hacking
Web App Attack
🇩🇪
Pingger Shikkoken
2023-10-29 05:48:43
(2 years ago)
Participating in DDoS Amplification Attack
DNS Poisoning
DDoS Attack
Hacking
Brute-Force
Exploited Host
Showing 1 to
7
of 7 reports