This IP address has been reported a total of
21
times from
20 distinct
sources.
41.222.179.235 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show moreDistributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in thread-post.asp
show less
(wordpress) Failed wordpress login from 41.222.179.235 (TZ/Tanzania/Dar es Salaam Region/Dar es Sala ...
show more(wordpress) Failed wordpress login from 41.222.179.235 (TZ/Tanzania/Dar es Salaam Region/Dar es Salaam/-)
show less
(mod_security) mod_security (id:240335) triggered by 41.222.179.235 (-): 1 in the last 300 secs; Por ...
show more(mod_security) mod_security (id:240335) triggered by 41.222.179.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 15:21:10.419740 2026] [security2:error] [pid 411630:tid 411644] [client 41.222.179.235:53835] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.222.179.235 (+1 hits since last alert)|daraluz.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "daraluz.net"] [uri "/xmlrpc.php"] [unique_id "aon2psUGOu4k2vOOXK1nBgAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
Large-scale coordinated botnet (1.2M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a ...
show moreLarge-scale coordinated botnet (1.2M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/Shursky [yordim|LIS|MOW]); Attacker: Mikhail Smirnov (mikhail-smirnov-79830323/Aidan [MOW]) employed by Angara Technologies Group | Attack Signature Blocked: /wishlist/index/add/product/10926/form_key/HKAeUJHwJbi10Tkg/ | UA: Mozilla/5.0 (iPod; U; CPU iPhone OS 3_1 like Mac OS X; sc-IT) AppleWebKit/534.8.4 (KHTML, like Gecko) Version/3.0.5 Mobile/8B115 Safari/6534.8.4 | (Magento Site)
show less
Blocked by UFW (TCP on 60973)
Source port: 47751
TTL: 40
Packet length: 60
TOS: 0x08
This report (f ...
show moreBlocked by UFW (TCP on 60973)
Source port: 47751
TTL: 40
Packet length: 60
TOS: 0x08
This report (for 41.222.179.235) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
[Mon Jun 08 16:39:29.327281 2026] [security2:error] [pid 922275:tid 140662170183360] [client 41.222. ...
show more[Mon Jun 08 16:39:29.327281 2026] [security2:error] [pid 922275:tid 140662170183360] [client 41.222.179.235:16951] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "www.bmkg.go.id" at REQUEST_HEADERS:Referer. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "582"] [id "440068"] [msg "BAD Referer"] [data "Matched Data: www.bmkg.go.id found within REQUEST_HEADERS:Referer: https://www.bmkg.go.id/ request_line = GET /index.php/analisis-iklim/analisis-bulanan/analisis-distribusi-hujan/analisis-distribusi-curah-hujan HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/analisis-iklim/analisis-bulanan/analisis-distribusi-hujan/analisis-distribusi-curah-hujan"] [unique_id "aiaN0cvrxkCn-gcND_aOrQABBAA"], referer https://www.bmkg.go.id/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[922276] [h3tqyToSJ5w] [aiaN0cvrxkCn-gcND_aOrQABBAA] keep_alive=[1] [2026-06-08 16:39:29.327286] [R:aiaN0cvr
...
show less
Email Spam
Hacking
Anonymous
Botnet-generated fake user-agent with impossible version. UA="Mozilla/5.0 (Linux; Android 6.0; Nexus ...
show moreBotnet-generated fake user-agent with impossible version. UA="Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.6855.1775 Mobile Safar"
show less
Bad Web Bot
Anonymous
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
Anonymous
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show moreDistributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in printer-friendly.asp
show less