AbuseIPDB » 27.65.116.139
27.65.116.139 was found in our database!
This IP was reported 4 times. Confidence of
Abuse
is 0% : ?
ISP
Viettel Group
Usage Type
Fixed Line ISP
ASN
AS7552
Hostname(s)
localhost
Domain Name
viettel.com.vn
Country
π»π³
Viet Nam
City
Ho Chi Minh City, Ho Chi Minh City (HCMC)
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 27.65.116.139 :
This IP address has been reported a total of
4
times from
3 distinct
sources.
27.65.116.139 was first reported on
February 7th 2024 , and the most recent report was
2 years ago .
Old Reports:
The most recent abuse report for this IP address is from
2 years ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
πΊπΈ
TPI-Abuse
2024-02-10 20:35:00
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 27.65.116.139 (localhost): 1 in the last 300 se ...
show more
(mod_security) mod_security (id:210730) triggered by 27.65.116.139 (localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 10 15:34:54.887800 2024] [security2:error] [pid 13305] [client 27.65.116.139:58301] [client 27.65.116.139] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thevillageartcenter.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thevillageartcenter.com"] [uri "/mailto:[email protected] "] [unique_id "Zcfd7kOVh8uviU1BBtRb2gAAAAw"], referer: http://thevillageartcenter.com/contact.html
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
dwmp
2024-02-09 23:16:45
(2 years ago)
Feb 10 00:16:41 plesk postfix/smtpd[392844]: lost connection after CONNECT from unknown[27.65.116.13 ...
show more
Feb 10 00:16:41 plesk postfix/smtpd[392844]: lost connection after CONNECT from unknown[27.65.116.139]
Feb 10 00:16:42 plesk postfix/smtpd[392844]: lost connection after CONNECT from unknown[27.65.116.139]
Feb 10 00:16:44 plesk postfix/smtpd[392844]: lost connection after CONNECT from unknown[27.65.116.139]
...
show less
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2024-02-08 06:18:45
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 27.65.116.139 (localhost): 1 in the last 300 se ...
show more
(mod_security) mod_security (id:210730) triggered by 27.65.116.139 (localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 08 01:18:39.672940 2024] [security2:error] [pid 1150] [client 27.65.116.139:49303] [client 27.65.116.139] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ronniescedarinn.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ronniescedarinn.com"] [uri "/mailto:[email protected] "] [unique_id "ZcRyPyQpgo6MDhFJvc15_AAAAAw"], referer: http://ronniescedarinn.com/contact_us.htm
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
brocococonut
2024-02-07 13:00:42
(2 years ago)
2024-02-07 19:22:51 dovecot_plain authenticator failed for ([127.0.0.1]) [27.65.116.139]: 535 Incorr ...
show more
2024-02-07 19:22:51 dovecot_plain authenticator failed for ([127.0.0.1]) [27.65.116.139]: 535 Incorrect authentication data ([email protected] )
2024-02-07 19:22:51 dovecot_plain authenticator failed for ([127.0.0.1]) [27.65.116.139]: 535 Incorrect authentication data ([email protected] )
2024-02-07 19:22:58 dovecot_login authenticator failed for ([127.0.0.1]) [27.65.116.139]: 535 Incorrect authentication data ([email protected] )
2024-02-07 19:22:58 dovecot_login authenticator failed for ([127.0.0.1]) [27.65.116.139]: 535 Incorrect authentication data ([email protected] )
2024-02-07 19:22:51 dovecot_plain authenticator failed for ([127.0.0.1]) [27.65.116.139]: 535 Incorrect authentication data ([email protected] )
...
show less
Brute-Force
Showing 1 to
4
of 4 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown π©
Recently Reported IPs: