This IP address has been reported a total of
13
times from
11 distinct
sources.
41.210.142.72 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 7
reports;
Italy
with 2
reports;
Georgia
with 1
report.
The most common categories in these recent reports were:
Port Scan
6
times;
Brute-Force
5
times;
Web App Attack
5
times;
Hacking
3
times;
Exploited Host
2
times;
Other
3
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[SatOct0302:47:20.3719432026][security2:error][pid3038990:tid3039334][client41.210.142.72:0]ModSecur ...
show more[SatOct0302:47:20.3719432026][security2:error][pid3038990:tid3039334][client41.210.142.72:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"giftech.ch\"][uri\"/xmlrpc.php\"][unique_id\"asBQmBV4w3K7273KAfaW9gAAARE\"]
show less
[ThuOct0110:26:27.5733362026][security2:error][pid688655:tid688820][client41.210.142.72:0]ModSecurit ...
show more[ThuOct0110:26:27.5733362026][security2:error][pid688655:tid688820][client41.210.142.72:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"morandi-trasporti.ch\"][uri\"/xmlrpc.php\"][unique_id\"ar4ZM8tuH8dgMkLXrhdUHwAAAJU\"]
show less
Botnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:27004/udp in AS203136 (LLC Ord ...
show moreBotnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:27004/udp in AS203136 (LLC Ordunet), Georgia. This source sustained more than 150 packets/sec toward that single UDP port and was one of 3229 distinct sources from 1488 autonomous systems in 139 countries taking part in a coordinated flood on 2026-09-03/04. Our border router discarded 184 million packets (149 GB) of this attack traffic in 24 hours. Detected on a MikroTik RouterOS router by per-source rate accounting in the raw/prerouting chain (dst-limit 150,50,src-address/10s); the timestamp is the moment this source crossed the threshold, timezone +04:00. This is not a port scan and not a brute-force attempt - it is a packet flood, so the host is almost certainly compromised and part of a botnet. Full packet-level evidence available on request to [email protected].
show less
DDoS Attack
Exploited Host
Anonymous
denied traffic to a honeypot network. destination port 30351.
Port Scan
Hacking
Anonymous
denied traffic to a honeypot network. destination port 44772.