This IP address has been reported a total of
9
times from
7 distinct
sources.
217.216.65.127 was first reported on
September 29th 2026 , and the most recent report was
6 hours ago .
In the last 60 days, the top reporter locations were:
United States of America
with 4
reports;
Germany
with 3
reports;
Belgium
with 1
report.
The most common categories in these recent reports were:
Web App Attack
7
times;
Bad Web Bot
5
times;
Brute-Force
4
times;
Hacking
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
π©πͺ
webko.si
2026-10-08 19:25:22
(6 hours ago)
JZKK: Bruteforce web app access, URI detail: '/.vscode/sftp.json'.
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 09:25:04
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 217.216.65.127 (vmi3617733.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 217.216.65.127 (vmi3617733.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 05:24:59.876365 2026] [security2:error] [pid 375:tid 375] [client 217.216.65.127:50408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dinsbach.net"] [uri "/sftp-config.json"] [unique_id "ar4m68lyBuOY_V57pdWHkQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
openstrike.co.uk
2026-09-30 05:14:14
(1 week ago)
138 attacks on password/key grabbing URLs:
GET /.vscode/sftp.json HTTP/1.1
Hacking
π§πͺ
cmbplf
2026-09-30 00:36:09
(1 week ago)
157 requests with url.path *sftp.json
Brute-Force
Bad Web Bot
πΊπΈ
nyt
2026-09-29 23:38:11
(1 week ago)
Deploy Config Probe
Web App Attack
π©πͺ
paissangroup
2026-09-29 21:16:47
(1 week ago)
Multiple WAF Violations
Web App Attack
π©πͺ
findlab
2026-09-29 12:35:02
(1 week ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 10:48:06
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 217.216.65.127 (vmi3617733.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 217.216.65.127 (vmi3617733.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 06:47:59.013575 2026] [security2:error] [pid 12526:tid 12526] [client 217.216.65.127:59834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "giganticmediallc.com"] [uri "/sftp-config.json"] [unique_id "aruXX8E3IPEeaOgqZHfKzAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 10:18:40
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 217.216.65.127 (vmi3617733.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 217.216.65.127 (vmi3617733.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 06:18:34.945358 2026] [security2:error] [pid 11566:tid 11566] [client 217.216.65.127:37318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "youssefwakim.com"] [uri "/sftp-config.json"] [unique_id "aruQei7mbH0WUHX0mlbeDwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Showing 1 to
9
of 9 reports