This IP address has been reported a total of
61
times from
41 distinct
sources.
195.182.22.229 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 13
reports;
Germany
with 3
reports;
Poland
with 2
reports.
The most common categories in these recent reports were:
Bad Web Bot
10
times;
Port Scan
8
times;
Brute-Force
6
times;
DDoS Attack
6
times;
Web App Attack
5
times;
Other
8
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
(mod_security) mod_security (id:210350) triggered by 195.182.22.229 (-): 1 in the last 300 secs; Por ...
show more(mod_security) mod_security (id:210350) triggered by 195.182.22.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:09:05.488077 2026] [security2:error] [pid 26271:tid 26271] [client 195.182.22.229:43142] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||keepaustinnuts.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "keepaustinnuts.com"] [uri "/"] [unique_id "ar6TsQjJhizynjvryqdUDgAAAAg"], referer: https://thelinkbuilding.store/dir/high-da-backlinks-112368
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-25T16:45:27.835936+00:00 HongKong1 sshd-session[689956]: Connection closed by 195.182.22.229 ...
show more2026-09-25T16:45:27.835936+00:00 HongKong1 sshd-session[689956]: Connection closed by 195.182.22.229 port 53912 [preauth]
2026-09-25T16:45:28.214138+00:00 HongKong1 sshd-session[689964]: Connection closed by 195.182.22.229 port 53960 [preauth]
...
show less
Blocked by UFW (TCP on 23)
Source port: 46046
TTL: 48
Packet length: 60
TOS: 0x00
This report (for ...
show moreBlocked by UFW (TCP on 23)
Source port: 46046
TTL: 48
Packet length: 60
TOS: 0x00
This report (for 195.182.22.229) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
show less
Botnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18: ...
show moreBotnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18:00 and 19:30 local time (+04:00). This source sent UDP to port 47472 of 185.143.177.x at more than 800 packets/sec. Nothing listens on that port - repeated full packet captures of all traffic reaching this machine recorded its services on other UDP ports and never a single packet to 47472 - so this cannot be a client of anything; it is flood by definition, independent of any rate measurement. One of 2743 sources in 1270 networks and 136 countries in the same wave. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. The host is almost certainly compromised and part of a botnet. Evidence: [email protected].
show less
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0. ...
show moreMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
show less