AbuseIPDB » 217.216.103.27
217.216.103.27 was found in our database!
This IP was reported 7 times. Confidence of
Abuse
is 18% : ?
ISP
Packethub S.A.
Usage Type
Data Center/Web Hosting/Transit
ASN
AS136787
Domain Name
packethub.net
Country
๐ธ๐ฌ
Singapore
City
Singapore
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 217.216.103.27 :
This IP address has been reported a total of
7
times from
6 distinct
sources.
217.216.103.27 was first reported on
February 18th 2026 , and the most recent report was
1 month ago .
Old Reports:
The most recent abuse report for this IP address is from
1 month ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐บ๐ธ
kosada.com
2026-07-25 14:34:53
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ฎ๐น
CoreTech srl
2026-07-15 23:23:58
(1 month ago)
cloudlinux2 fail2ban: 2026-07-16 01:18:56,293 fail2ban.filter [1812]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-07-16 01:18:56,293 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 173.239.214.203 - 2026-07-16 01:18:54cloudlinux2 fail2ban: 2026-07-16 01:18:56,297 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 173.239.214.232 - 2026-07-16 01:18:54cloudlinux2 fail2ban: 2026-07-16 01:18:59,671 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 173.239.214.203 - 2026-07-16 01:18:58cloudlinux2 fail2ban: 2026-07-16 01:19:25,343 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 208.76.40.156 - 2026-07-16 01:19:24cloudlinux2 fail2ban: 2026-07-16 01:19:49,697 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 193.37.33.130 - 2026-07-16 01:19:48cloudlinux2 fail2ban: 2026-07-16 01:20:35,693 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 193.19.109.118 - 2026-07-16 01:20:35cloudlinux2 fail2ban: 2026-07-16 01:20:31,344 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 193.19.109.118 - 2026-07-16 01:20:31c
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-15 22:32:33
(1 month ago)
(mod_security) mod_security (id:211190) triggered by 217.216.103.27 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 217.216.103.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 18:32:27.510225 2026] [security2:error] [pid 18822:tid 18822] [client 217.216.103.27:25220] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||fattoria-rendena.it|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fattoria-rendena.it"] [uri "/"] [unique_id "algKe--465_p5dp9NRaBWgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-15 21:30:07
(1 month ago)
(mod_security) mod_security (id:211190) triggered by 217.216.103.27 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 217.216.103.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 17:30:00.636273 2026] [security2:error] [pid 5324:tid 5324] [client 217.216.103.27:2468] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||cybersoftware.org|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cybersoftware.org"] [uri "/"] [unique_id "alf72BfbTURUZg3mDxWXhgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ut-addicted.com
2026-07-15 21:26:39
(1 month ago)
\[Wed Jul 15 23:26:37.633132 2026\] \[:error\] \[pid 9318:tid 139785758783232\] \[client 217.216.103 ...
show more
\[Wed Jul 15 23:26:37.633132 2026\] \[:error\] \[pid 9318:tid 139785758783232\] \[client 217.216.103.27:56210\] \[client 217.216.103.27\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 25\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "crx.it"\] \[uri "/"\] \[unique_id "alf7DT4JQXqZ9O@JBinqVAAAAM4"\]
show less
Brute-Force
Web App Attack
๐ฉ๐ช
4server
2026-07-15 18:43:47
(1 month ago)
[WedJul1520:43:45.7739232026][security2:error][pid3836981:tid3837061][client217.216.103.27:0]ModSecu ...
show more
[WedJul1520:43:45.7739232026][security2:error][pid3836981:tid3837061][client217.216.103.27:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"/etc/passwd\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"141\"][id\"347009\"][rev\"1\"][msg\"Atomicorp.comWAFRules:ProtectedFileaccessdenied\"][severity\"CRITICAL\"][hostname\"allegraravizza.it\"][uri\"/\"][unique_id\"alfU4RR2BKdxTw33zdhT8gAAAkA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ต๐ฑ
launch.joomla.org
2026-02-18 17:48:00
(6 months ago)
Phishing
Fraud Orders
Phishing
VPN IP
Showing 1 to
7
of 7 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: