AbuseIPDB » 94.249.2.56
94.249.2.56 was found in our database!
This IP was reported 7 times. Confidence of
Abuse
is 14% : ?
ISP
Jordan Telecom Group (Orange)
Usage Type
Fixed Line ISP
ASN
AS8376
Hostname(s)
94.249.x.56.go.com.jo
Domain Name
orange.com
Country
๐ฏ๐ด
Jordan
City
Amman, Amman
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 94.249.2.56 :
This IP address has been reported a total of
7
times from
6 distinct
sources.
94.249.2.56 was first reported on
February 12th 2022 , and the most recent report was
23 hours ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐บ๐ธ
TPI-Abuse
2026-07-22 13:14:08
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 94.249.2.56 (94.249.x.56.go.com.jo): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 94.249.2.56 (94.249.x.56.go.com.jo): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 09:14:03.405377 2026] [security2:error] [pid 17244:tid 17244] [client 94.249.2.56:49822] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.khaoula.com|F|2"] [data ".monmaghreb.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.khaoula.com"] [uri "/sante.monmaghreb.com"] [unique_id "amDCGy0sKtNEXNoHT-1EgAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-07-06 13:05:47
(2 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-06 20:52:56
(4 months ago)
(mod_security) mod_security (id:217210) triggered by 94.249.2.56 (94.249.x.56.go.com.jo): 1 in the l ...
show more
(mod_security) mod_security (id:217210) triggered by 94.249.2.56 (94.249.x.56.go.com.jo): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 06 15:52:49.429327 2026] [security2:error] [pid 4601:tid 4601] [client 94.249.2.56:39714] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||blog33center.shop|F|4"] [data "GET http://blog33center.shop HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "blog33center.shop"] [uri "/"] [unique_id "aas-obLu6QSB2rqtmahtpwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
RAP
2026-01-14 11:32:05
(6 months ago)
2026-01-14 11:32:05 UTC Unauthorized activity to TCP port 445. SMB
Port Scan
๐ช๐ธ
10dencehispahard SL
2023-01-30 04:23:13
(3 years ago)
Unauthorized login attempts [ wordpress-xmlrpc, wordpress]
Brute-Force
Web App Attack
๐ง๐ฌ
MazenHost
2022-09-07 03:47:06
(3 years ago)
1662536825 - 09/07/2022 10:47:05 Host: 94.249.2.56/94.249.2.56 Port: 445 TCP Blocked
...
Port Scan
๐บ๐ธ
etu brutus
2022-02-12 19:23:32
(4 years ago)
22/2/12@19:23:30: FAIL: Alarm-Network address from=94.249.2.56
...
Hacking
Brute-Force
SSH
Showing 1 to
7
of 7 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: