AbuseIPDB » 49.51.134.84
49.51.134.84 was found in our database!
This IP was reported 7 times. Confidence of
Abuse
is 0% : ?
ISP
Tencent cloud computing (Beijing) Co., Ltd.
Usage Type
Data Center/Web Hosting/Transit
ASN
AS132203
Domain Name
tencent.com
Country
๐ฉ๐ช
Germany
City
Frankfurt am Main, Hesse
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 49.51.134.84 :
This IP address has been reported a total of
7
times from
7 distinct
sources.
49.51.134.84 was first reported on
August 28th 2025 , and the most recent report was
1 month ago .
Old Reports:
The most recent abuse report for this IP address is from
1 month ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐บ๐ธ
Yawning Angel
2026-07-16 18:35:00
(1 month ago)
Fake invoice banking/credit phishing and vishing scam.
From: Grisela Dimino <nicol.caraballo@castil ...
show more
Fake invoice banking/credit phishing and vishing scam.
From: Grisela Dimino <[email protected] >
Subject: Download and keep your invoice file (Token) to retain a backup
Message Body: info, we have received your payment. Invoice is included. 17 July 2026-Service Hotline: +1(656) 556-2208
Attachment: Download and keep your invoice file _Token_ to retain a backup.pdf 23.1 KB
show less
Fraud Orders
Email Spam
Phishing
๐จ๐ญ
backslash
2025-09-28 07:19:10
(10 months ago)
Bad Web Bot
๐ฎ๐ฉ
hermawan
2025-09-11 02:46:21
(11 months ago)
[Thu Sep 11 09:45:13.177222 2025] [security2:error] [pid 860510:tid 139797180950208] [client 49.51.1 ...
show more
[Thu Sep 11 09:45:13.177222 2025] [security2:error] [pid 860510:tid 139797180950208] [client 49.51.134.84:36747] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/fax:+62341464827" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "69"] [id "448101"] [msg "BAD REQUEST FILENAME - Detected and Blocked"] [data "Matched Data: /fax:+62341464827 found within REQUEST_FILENAME: /index.php/fax:+62341464827 request_line = GET /index.php/fax:+62341464827 HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/fax:+62341464827"] [unique_id "aMI3uV3qEIAgWlD4teszfAACiAQ"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[860515] [iTvAhr1DIT0] [aMI3uV3qEIAgWlD4teszfAACiAQ] keep_alive=[1] [2025-09-11 09:45:13.177228] [R:aMI3uV3qEIAgWlD4teszfAACiAQ] UA:'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36' Host:'staklim-ja
...
show less
Hacking
Web App Attack
๐ฌ๐ง
threewalls.co.uk
2025-09-08 09:46:11
(11 months ago)
Triggered bot honeypot on gclproducts.co.uk
Fraud Orders
FTP Brute-Force
Brute-Force
Exploited Host
๐บ๐ธ
TPI-Abuse
2025-09-04 12:11:37
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 49.51.134.84 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 49.51.134.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 04 08:11:29.796926 2025] [security2:error] [pid 29266:tid 29266] [client 49.51.134.84:41613] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.williamfitzsimmons.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.williamfitzsimmons.com"] [uri "/leifvollebekk.com"] [unique_id "aLmB8Qklz5E3B-FVnRYWQwAAAAU"], referer: http://www.williamfitzsimmons.com/leifvollebekk.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-08-29 17:48:22
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ณ๐ฑ
exxos
2025-08-28 23:03:01
(11 months ago)
Attacks with Bad user agents
Hacking
Showing 1 to
7
of 7 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: