AbuseIPDB » 216.225.200.198
216.225.200.198 was found in our database!
This IP was reported 5 times. Confidence of
Abuse
is 23% : ?
ISP
IONOS Inc.
Usage Type
Data Center/Web Hosting/Transit
ASN
AS8560
Hostname(s)
ip216-225-200-198.pbiaas.com
Domain Name
ionos.com
Country
๐บ๐ธ
United States of America
City
New York City, New York
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 216.225.200.198 :
This IP address has been reported a total of
5
times from
4 distinct
sources.
216.225.200.198 was first reported on
August 18th 2026 , and the most recent report was
5 days ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ฉ๐ช
milcraft.nl
2026-08-28 21:14:42
(5 days ago)
Honeypot / Fake URL Access: Access to hidden and / or intentionally fake URLs designed to detect aut ...
show more
Honeypot / Fake URL Access: Access to hidden and / or intentionally fake URLs designed to detect automated scanners or malicious bots. .env, .env.local, .env.production, .htpasswd Activity is consistent with web application abuse.
show less
Hacking
๐ฎ๐ฉ
Chasserr
2026-08-28 04:20:20
(5 days ago)
Port Scan
SSH
IoT Targeted
๐บ๐ธ
TPI-Abuse
2026-08-18 21:51:42
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 216.225.200.198 (ip216-225-200-198.pbiaas.com): ...
show more
(mod_security) mod_security (id:210492) triggered by 216.225.200.198 (ip216-225-200-198.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 17:51:37.833366 2026] [security2:error] [pid 14040:tid 14040] [client 216.225.200.198:64711] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tracdynamics.com"] [uri "/.env"] [unique_id "aoTT6cu7nXnpsv6BiTTpdwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-08-18 16:04:06
(2 weeks ago)
[Wed Aug 19 02:04:05.690968 2026] [security2:error] [pid 250546] [client 216.225.200.198:61510] [cli ...
show more
[Wed Aug 19 02:04:05.690968 2026] [security2:error] [pid 250546] [client 216.225.200.198:61510] [client 216.225.200.198] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dlcarterauthor.com"] [uri "/.env"] [unique_id "aoSCdWT0iCp61d_ujSWtJQAAAAk"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 14:51:22
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 216.225.200.198 (ip216-225-200-198.pbiaas.com): ...
show more
(mod_security) mod_security (id:210492) triggered by 216.225.200.198 (ip216-225-200-198.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 10:51:14.577399 2026] [security2:error] [pid 31214:tid 31214] [client 216.225.200.198:52372] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "colvani.com"] [uri "/.env"] [unique_id "aoRxYuFgtljraqw1JPxk0wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Showing 1 to
5
of 5 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: