This IP address has been reported a total of
17
times from
11 distinct
sources.
206.84.81.158 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 7
reports;
France
with 2
reports;
Germany
with 1
report.
The most common categories in these recent reports were:
Bad Web Bot
9
times;
Web App Attack
6
times;
Brute-Force
5
times;
DDoS Attack
3
times;
Exploited Host
2
times;
Other
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
(mod_security) mod_security (id:210350) triggered by 206.84.81.158 (Dinamic-Somos-206-84-81-158.somo ...
show more(mod_security) mod_security (id:210350) triggered by 206.84.81.158 (Dinamic-Somos-206-84-81-158.somosinternet.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 12:30:03.964556 2026] [security2:error] [pid 14995:tid 14995] [client 206.84.81.158:60894] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||tortoisehosting.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "tortoisehosting.com"] [uri "/"] [unique_id "aq1nCwW-VBVYeFyWieDhvwAAAAI"], referer: https://dacheckerinbulk.store/dir/contextual-seo-backlinks-215817
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
Large-scale coordinated botnet (5M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/S ...
show moreLarge-scale coordinated botnet (5M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/Shursky [yordim|LIS|MOW]): Retaliation after theft; Attacker: Mikhail Smirnov (mikhail-smirnov-79830323/Aidan [MOW]): Employed by Angara Technologies Group | Catalog Search Abuse Blocked: /catalogsearch/result/?dir=desc&order=relevance+&product_vc_mcu=104%2C105&q=Bosch+FCS | UA: Mozilla/5.0 (compatible; MSIE 6.0; Windows NT 5.0; Trident/5.1) | (Magento Site)
show less
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -97.707 (Bad < -10 / Very Bad < -20 ...
show moreBot/Spam/Scrapper attack detected on www.handytreff.de - Score: -97.707 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Saf
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
show less
UDP flood (DDoS) vs AS215599: 7883 pkts / 11.27 MB to UDP 80/8443 across 490 dst IP(s), 2026-08-19 2 ...
show moreUDP flood (DDoS) vs AS215599: 7883 pkts / 11.27 MB to UDP 80/8443 across 490 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
UDP flood (DDoS) vs AS215599: 7883 pkts / 11.27 MB to UDP 80/8443 across 490 dst IP(s), 2026-08-19 2 ...
show moreUDP flood (DDoS) vs AS215599: 7883 pkts / 11.27 MB to UDP 80/8443 across 490 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
[Askari] | Behavior: HTTP/1.1 over TLS, Slow-read attack, Outdated browser, Targeting specific pages ...
show more[Askari] | Behavior: HTTP/1.1 over TLS, Slow-read attack, Outdated browser, Targeting specific pages, URL template abuse
show less
Suspicious WooCommerce query combination detected. Not default available on websites. Matched combi ...
show moreSuspicious WooCommerce query combination detected. Not default available on websites. Matched combi patterns: filter_, add-to-cart=, orderby=, product_count=. Activity is consistent with high-volume request abuse.
show less