AbuseIPDB » 39.109.99.172
39.109.99.172 was found in our database!
This IP was reported 6 times. Confidence of
Abuse
is 23% : ?
ISP
TENGSHENG TECH LIMITED
Usage Type
Data Center/Web Hosting/Transit
ASN
AS152179
Domain Name
tengshengtech.net
Country
ππ°
Hong Kong
City
Hong Kong
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 39.109.99.172 :
This IP address has been reported a total of
6
times from
3 distinct
sources.
39.109.99.172 was first reported on
September 5th 2026 , and the most recent report was
17 hours ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
π«π·
Sklurk
2026-09-17 09:25:52
(17 hours ago)
Web App Attack
Web App Attack
π«π·
Sklurk
2026-09-16 03:34:02
(1 day ago)
Web App Attack
Web App Attack
π«π·
Sklurk
2026-09-14 03:19:57
(3 days ago)
Web App Attack
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-12 19:37:15
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 39.109.99.172 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 39.109.99.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 15:37:09.173621 2026] [security2:error] [pid 18795:tid 18795] [client 39.109.99.172:55403] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.barbaraehill.com|F|2"] [data ".barbaraehill.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.barbaraehill.com"] [uri "/blog/https:/www.barbaraehill.com"] [unique_id "aqWp5TThvmO_lGaQOI-a3AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-06 11:37:31
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 39.109.99.172 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 39.109.99.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 07:37:27.147226 2026] [security2:error] [pid 1593:tid 1593] [client 39.109.99.172:40037] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||benjaminshaw.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "benjaminshaw.com"] [uri "/baggywrinkle/WS_FTP.LOG"] [unique_id "ap1Qd8Znf7EenPEXZCdzkgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
gui-ying233
2026-09-05 21:43:12
(1 week ago)
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0. ...
show more
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36
show less
Bad Web Bot
Showing 1 to
6
of 6 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown π©
Recently Reported IPs: