AbuseIPDB » 64.49.38.217
64.49.38.217 was found in our database!
This IP was reported 8 times. Confidence of
Abuse
is 17%: ?
| ISP |
Hostaly LLC
|
| Usage Type |
Data Center/Web Hosting/Transit
|
| ASN |
AS26548
|
| Domain Name |
hostaly.io
|
| Country |
๐บ๐ธ
United States of America
|
| City |
Seattle, Washington
|
IP info including ISP, Usage Type, and Location provided
by IPInfo. Updated weekly.
IP Abuse Reports for 64.49.38.217:
This IP address has been reported a total of
8
times from
5 distinct
sources.
64.49.38.217 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
| Reporter |
IoA Timestamp (UTC)
|
Comment |
Categories |
|
|
๐บ๐ธ
mnsf
|
|
Scanning/Probing (34)
|
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 64.49.38.217 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.49.38.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 14:16:57.000298 2026] [security2:error] [pid 24113:tid 24113] [client 64.49.38.217:34437] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wild-goose.net"] [uri "/wp-config.php.old"] [unique_id "ag36mL1CVkzqfKCCqkXc6AAAABU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 64.49.38.217 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 64.49.38.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 08:44:22.488221 2026] [security2:error] [pid 16147:tid 16147] [client 64.49.38.217:35457] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ceren.kircali.net|F|2"] [data ".inc"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ceren.kircali.net"] [uri "/wp-config.inc"] [unique_id "ag2spvll6L6bMw71eqgOCgAAAA4"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
NicoID
|
|
64.49.38.217 - - [01/May/2026:00:33:39 -0600] "GET /wp-login.php?redirect_to=https%3A%2F%2Fnicohd.co ...
show more
64.49.38.217 - - [01/May/2026:00:33:39 -0600] "GET /wp-login.php?redirect_to=https%3A%2F%2Fnicohd.com%2Fwp-admin%2Fadmin.php%3Fpage%3Dgraphiql-ide&reauth=1 HTTP/1.1" 200 7839 "https://nicohd.com/wp-admin/admin.php?page=graphiql-ide" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
|
Brute-Force
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 64.49.38.217 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 64.49.38.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 05 07:34:19.238574 2026] [security2:error] [pid 28032:tid 28032] [client 64.49.38.217:65141] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||magacine.tv|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "magacine.tv"] [uri "/wp-json/wp/v2/users"] [unique_id "aYSOS4IrQv3QnHArrUvUvwAAABA"], referer: https://www.google.com
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 64.49.38.217 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 64.49.38.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 03 17:33:43.068737 2026] [security2:error] [pid 2650681:tid 2650701] [client 64.49.38.217:32321] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gotogps.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gotogps.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aYJ3x7b5O8QtFB-1kKCEEwAAANE"], referer: https://www.google.com
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
Web App Attack
|
Brute-Force
Web App Attack
|
|
|
๐ฉ๐ช
f2_IT
|
|
SSLVPN Login attempt (blocked type h) from 64.49.38.217
|
Brute-Force
|
|
Showing 1 to
8
of 8 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: