IP info including ISP, Usage Type, and Location provided
by IPInfo. Updated weekly.
Important Note: 216.180.246.220 is an IP address from within
our whitelist belonging to the subnet
216.180.246.0/24,
which we identify as: "Deepfield Genome".
Whitelisted netblocks are typically owned by trusted entities, such as Google
or Microsoft who may use them for search engine spiders. However, these same entities
sometimes also provide cloud servers and mail services which are easily abused. Pay special
attention when trusting or distrusting these IPs.
This IP address has been reported a total of
791
times from
241 distinct
sources.
216.180.246.220 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Honeypot [nx-infrastructure]: Empty payload (likely service probe); 3007 [2] TCP
Reported by: Justin ...
show moreHoneypot [nx-infrastructure]: Empty payload (likely service probe); 3007 [2] TCP
Reported by: Justin F.
show less
Port Scan
Anonymous
2026-06-21 07:43:23 216.180.246.220:21303 WARNING: Bad encapsulated packet length from peer (5635), ...
show more2026-06-21 07:43:23 216.180.246.220:21303 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1768 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]
2026-06-21 07:44:52 216.180.246.220:21303 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1768 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]
2026-06-21 07:46:09 216.180.246.220:17696 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1768 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]
...
show less
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 216.180.246.220 (US/United States/c ...
show moreLF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 216.180.246.220 (US/United States/crawler220.deepfield.net): 2 in the last 3600 secs
show less
Blocked by UFW (TCP on 443)
Source port: 21631
TTL: 59
Packet length: 44
TOS: 0x00
This report (for ...
show moreBlocked by UFW (TCP on 443)
Source port: 21631
TTL: 59
Packet length: 44
TOS: 0x00
This report (for 216.180.246.220) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less