๐บ๐ธ
TPI-Abuse
2026-10-02 03:42:08
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 186.22.245.213 (cpe-186-22-245-213.telecentro-r ...
show more
(mod_security) mod_security (id:210350) triggered by 186.22.245.213 (cpe-186-22-245-213.telecentro-reversos.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 23:42:04.469303 2026] [security2:error] [pid 19719:tid 19719] [client 186.22.245.213:13264] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||mohsep-eg.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "mohsep-eg.com"] [uri "/"] [unique_id "ar8oDCE5ipsf9MqoIy4GCgAAAAY"], referer: https://backlinksearch.website/dir/organic-visibility-backlinks-139077
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 14:56:58
(4 days ago)
(mod_security) mod_security (id:210350) triggered by 186.22.245.213 (cpe-186-22-245-213.telecentro-r ...
show more
(mod_security) mod_security (id:210350) triggered by 186.22.245.213 (cpe-186-22-245-213.telecentro-reversos.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 10:56:53.866361 2026] [security2:error] [pid 10302:tid 10302] [client 186.22.245.213:25091] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||ramseycountycorruption.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ramseycountycorruption.com"] [uri "/"] [unique_id "arvRtdtiQ8A0Y7_4XVL_8QAAAAU"], referer: https://bestfreeseochecker.site/dir/seo-link-building-experts-171986
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 22:00:56
(4 days ago)
(mod_security) mod_security (id:210350) triggered by 186.22.245.213 (cpe-186-22-245-213.telecentro-r ...
show more
(mod_security) mod_security (id:210350) triggered by 186.22.245.213 (cpe-186-22-245-213.telecentro-reversos.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 18:00:48.507811 2026] [security2:error] [pid 20689:tid 20689] [client 186.22.245.213:29914] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||danharrisphotoart.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "danharrisphotoart.com"] [uri "/"] [unique_id "arrjkE5T8XAJROdl6HeZhwAAAB4"], referer: https://drew-harris.blogspot.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 14:55:31
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 186.22.245.213 (cpe-186-22-245-213.telecentro-r ...
show more
(mod_security) mod_security (id:210350) triggered by 186.22.245.213 (cpe-186-22-245-213.telecentro-reversos.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 10:55:25.189316 2026] [security2:error] [pid 23474:tid 23474] [client 186.22.245.213:29862] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||travelsupersonic.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "travelsupersonic.com"] [uri "/"] [unique_id "arfc3YCver3TXwHIrRDBeQAAAAg"], referer: https://dapachecker.store/dir/relevant-seo-backlinks-217135
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
security.rdmc.fr
2026-09-17 10:12:18
(2 weeks ago)
Port Scan Attack proto:TCP src:62715 dst:23
Port Scan
๐บ๐ธ
technojoe99
2026-09-17 09:21:39
(2 weeks ago)
Attempted SSH connection from 186.22.245.213 port 63933 asn outside arin; no valid users in that asn
Port Scan
SSH
๐ซ๐ท
Hiigara
2026-09-17 07:01:09
(2 weeks ago)
connection attempt : 186.22.245.213 on port : tcp/23 (Telnet)
Port Scan
๐บ๐ธ
xmission.com
2026-09-16 00:33:05
(2 weeks ago)
Blocked by UFW (TCP on 23)
Source port: 60630
TTL: 44
Packet length: 60
TOS: 0x08
This report (for ...
show more
Blocked by UFW (TCP on 23)
Source port: 60630
TTL: 44
Packet length: 60
TOS: 0x08
This report (for 186.22.245.213) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Hacking
Brute-Force
๐บ๐ธ
MPL
2026-09-15 18:43:53
(2 weeks ago)
tcp ports: 23,22 (24 or more attempts)
Port Scan
๐บ๐ธ
RAP
2026-09-14 05:11:02
(2 weeks ago)
2026-09-14 05:11:02 UTC Unauthorized activity to TCP port 22. SSH
SSH
๐ฉ๐ช
_ArminS_
2026-09-14 01:25:14
(2 weeks ago)
Bad SSHAUTH 2026.09.14 03:25:14
blocked until 2026.09.17 03:25:14
by HoneyPot DE_State of Berlin01
SSH
Brute-Force
Hacking
๐ง๐ท
noconex
2026-09-13 10:41:12
(2 weeks ago)
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 186.22.245 ...
show more
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 186.22.245.213
show less
Port Scan
Brute-Force
SSH
๐ง๐ท
noconex
2026-09-10 21:36:09
(3 weeks ago)
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 186.22.245 ...
show more
Wazuh Alert | Rule ID: 100199 | Desc: Suricata: (ET SCAN Potential SSH Scan) detectado de 186.22.245.213
show less
Port Scan
Brute-Force
SSH
๐บ๐ธ
RAP
2026-09-09 09:29:13
(3 weeks ago)
2026-09-09 09:29:13 UTC Unauthorized activity to TCP port 22. SSH
SSH
๐บ๐ธ
RAP
2026-09-08 21:33:11
(3 weeks ago)
2026-09-08 21:33:11 UTC Unauthorized activity to TCP port 23. Telnet
Port Scan