AbuseIPDB » 102.221.237.6
102.221.237.6 was found in our database!
This IP was reported 10 times. Confidence of
Abuse
is 38% : ?
ISP
Ciudad Infrastructure Limited
Usage Type
Fixed Line ISP
ASN
AS328722
Domain Name
ciudad.ng
Country
π³π¬
Nigeria
City
Lagos, Lagos
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 102.221.237.6 :
This IP address has been reported a total of
10
times from
7 distinct
sources.
102.221.237.6 was first reported on
October 1st 2025 , and the most recent report was
1 day ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
πΊπΈ
TPI-Abuse
2026-06-16 00:53:41
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 102.221.237.6 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 102.221.237.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 20:53:37.248308 2026] [security2:error] [pid 14453:tid 14453] [client 102.221.237.6:50213] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.221.237.6 (+1 hits since last alert)|americanureport.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "americanureport.com"] [uri "/xmlrpc.php"] [unique_id "ajCekYOJQmLVB3rrNGH_SQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
screwlooseit.com.au
2026-06-14 23:58:58
(2 days ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
-
Web App Attack
π«π·
Kenshin869
2026-06-12 00:09:26
(5 days ago)
Wordpress unauthorized access attempt
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-10 20:29:43
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 102.221.237.6 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 102.221.237.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 16:29:39.353678 2026] [security2:error] [pid 3725:tid 3725] [client 102.221.237.6:57096] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.221.237.6 (+1 hits since last alert)|chatgptfrance.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "chatgptfrance.net"] [uri "/xmlrpc.php"] [unique_id "ainJM0bkgQjFdhFEA7OaggAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
WeekendWeb
2026-06-08 23:41:18
(1 week ago)
Wordpress Vunerability attack
Web App Attack
π«π·
masterguru
2026-06-05 01:03:29
(1 week ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
π©πͺ
rh24
2026-06-01 17:27:57
(2 weeks ago)
(wordpress) Failed wordpress login from 102.221.237.6 (NG/Nigeria/-): (CF_ENABLE)
Brute-Force
π«π·
masterguru
2026-06-01 03:20:46
(2 weeks ago)
(xmlrpc) Apache: Failed xmlrpc access from 102.221.237.6 (NG/Nigeria/-): 10 in the last 3600 secs (0 ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 102.221.237.6 (NG/Nigeria/-): 10 in the last 3600 secs (0-201)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-05-28 23:49:35
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 102.221.237.6 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 102.221.237.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 19:49:30.194232 2026] [security2:error] [pid 24499:tid 24524] [client 102.221.237.6:57835] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.221.237.6 (+1 hits since last alert)|41bravo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "41bravo.com"] [uri "/xmlrpc.php"] [unique_id "ahjUivb9IMIpFCuI-iNo-QAAANY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
exxos
2025-10-01 11:05:32
(8 months ago)
Attacks with Bad user agents
Hacking
Showing 1 to
10
of 10 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown π©
Recently Reported IPs: