AbuseIPDB » 45.70.85.8
45.70.85.8 was found in our database!
This IP was reported 10 times. Confidence of
Abuse
is 0% : ?
ISP
TELLIUS & ALLNET TELECOMUNICAÇÕES DAS AMÉRICAS
Usage Type
Fixed Line ISP
ASN
AS267593
Domain Name
tellius.com.br
Country
🇧🇷
Brazil
City
Aracatuba, Sao Paulo
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 45.70.85.8 :
This IP address has been reported a total of
10
times from
4 distinct
sources.
45.70.85.8 was first reported on
November 12th 2023 , and the most recent report was
1 year ago .
Old Reports:
The most recent abuse report for this IP address is from
1 year ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
🇺🇸
TPI-Abuse
2024-10-09 09:51:07
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 45.70.85.8 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 45.70.85.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 09 05:51:02.651490 2024] [security2:error] [pid 16859:tid 16859] [client 45.70.85.8:52050] [client 45.70.85.8] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 141.98.102.227 (0+1 hits since last alert)|tttns.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tttns.com"] [uri "/xmlrpc.php"] [unique_id "ZwZSBgFCLL6ywivNKmMNwgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
bittiguru.fi
2024-10-08 05:23:25
(1 year ago)
45.70.85.8 - [08/Oct/2024:08:23:22 +0300] "POST /xmlrpc.php HTTP/1.1" 200 257 "-" "Mozilla/5.0 (X11; ...
show more
45.70.85.8 - [08/Oct/2024:08:23:22 +0300] "POST /xmlrpc.php HTTP/1.1" 200 257 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.138 Safari/537.36" "1.85"
45.70.85.8 - [08/Oct/2024:08:23:24 +0300] "POST /xmlrpc.php HTTP/1.1" 200 257 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.138 Safari/537.36" "1.85"
...
show less
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2024-10-07 15:32:14
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 45.70.85.8 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 45.70.85.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 07 11:32:09.717019 2024] [security2:error] [pid 21217:tid 21227] [client 45.70.85.8:58233] [client 45.70.85.8] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.70.85.8 (+1 hits since last alert)|www.jimpepperfest.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.jimpepperfest.net"] [uri "/xmlrpc.php"] [unique_id "ZwP--fYJVCHec0LzvBwk4gAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇷
gbetsis
2024-03-15 15:25:27
(2 years ago)
TCP Port Scanning
Port Scan
Exploited Host
🇬🇷
gbetsis
2024-03-01 21:14:07
(2 years ago)
TCP Port Scanning
Port Scan
Exploited Host
🇬🇷
gbetsis
2023-12-19 12:20:56
(2 years ago)
TCP Port Scanning
Port Scan
Exploited Host
🇬🇷
gbetsis
2023-12-08 12:55:22
(2 years ago)
TCP Port Scanning
Port Scan
Exploited Host
🇬🇷
gbetsis
2023-12-03 09:10:17
(2 years ago)
TCP Port Scanning
Port Scan
Exploited Host
🇩🇪
Pingger Shikkoken
2023-11-13 05:25:24
(2 years ago)
Participating in DDoS Amplification Attack! Sending 15 requests over 29223s asking for ?0? of cisco. ...
show more
Participating in DDoS Amplification Attack! Sending 15 requests over 29223s asking for ?0? of cisco.com, atlassian.com, apple.com
show less
DNS Poisoning
DDoS Attack
Hacking
Brute-Force
Exploited Host
🇩🇪
Pingger Shikkoken
2023-11-12 16:10:38
(2 years ago)
Participating in DDoS Amplification Attack! Sending 16 requests over 49837s asking for ?0? of atlass ...
show more
Participating in DDoS Amplification Attack! Sending 16 requests over 49837s asking for ?0? of atlassian.com, apple.com, cisco.com
show less
DNS Poisoning
DDoS Attack
Hacking
Brute-Force
Exploited Host
Showing 1 to
10
of 10 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown 🚩
Recently Reported IPs: