This IP address has been reported a total of
820
times from
130 distinct
sources.
220.151.9.22 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[SunJun0703:36:21.1278492026][security2:error][pid3120663:tid3120763][client220.151.9.22:0]ModSecuri ...
show more[SunJun0703:36:21.1278492026][security2:error][pid3120663:tid3120763][client220.151.9.22:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"asw-sa.com\"][uri\"/\"][unique_id\"aiTLFftuAjXDWGiLIvmuuQAAAIg\"]
show less
[FriJun0512:57:53.4825272026][security2:error][pid609867:tid609995][client220.151.9.22:0]ModSecurity ...
show more[FriJun0512:57:53.4825272026][security2:error][pid609867:tid609995][client220.151.9.22:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"federicorella.ch\"][uri\"/\"][unique_id\"aiKrsSFNyDWor8GivP56PQAAARE\"]
show less
[ThuMay2812:11:53.1444872026][security2:error][pid448360:tid448498][client220.151.9.22:0]ModSecurity ...
show more[ThuMay2812:11:53.1444872026][security2:error][pid448360:tid448498][client220.151.9.22:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"specialfood.ch\"][uri\"/\"][unique_id\"ahgU6Y3Qn2gXroSV8YclkgAAAQw\"]
show less
[fail2ban Auto Report] {"time":"2026-05-25T12:12:55.135285378-04:00","level":"INFO","source":{"funct ...
show more[fail2ban Auto Report] {"time":"2026-05-25T12:12:55.135285378-04:00","level":"INFO","source":{"function":"github.com/TecharoHQ/anubis/lib.(*Server).checkRules","file":"/Users/cadey/Code/TecharoHQ/botstopper/upstream/anubis/lib/anubis.go","line":309},"msg":"explicit deny","subsystem":"anubis","host":"cobalt.directory","method":"GET","path":"/","user_agent":"","accept_language":"","priority":"","x-forwarded-for":"220.151.9.22","x-real-ip":"220.151.9.22","host":"cobalt.directory","check_result":{"name":"bot/no-user-agent-string","rule":"DENY","weight":0}}
...
show less
[fail2ban Auto Report] {"time":"2026-05-23T12:23:39.09168789-04:00","level":"INFO","source":{"functi ...
show more[fail2ban Auto Report] {"time":"2026-05-23T12:23:39.09168789-04:00","level":"INFO","source":{"function":"github.com/TecharoHQ/anubis/lib.(*Server).checkRules","file":"/Users/cadey/Code/TecharoHQ/botstopper/upstream/anubis/lib/anubis.go","line":309},"msg":"explicit deny","subsystem":"anubis","host":"cobalt.directory","method":"GET","path":"/","user_agent":"","accept_language":"","priority":"","x-forwarded-for":"220.151.9.22","x-real-ip":"220.151.9.22","host":"cobalt.directory","check_result":{"name":"bot/no-user-agent-string","rule":"DENY","weight":0}}
...
show less
[SatMay2306:25:10.9688832026][security2:error][pid409072:tid409200][client220.151.9.22:0]ModSecurity ...
show more[SatMay2306:25:10.9688832026][security2:error][pid409072:tid409200][client220.151.9.22:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:user-agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"www.gustotondo.ch\"][uri\"/\"][unique_id\"ahEsJjLKbMPKHl8rZAL3YQAAANI\"]
show less
Requests denied due to active blacklist hits (tenant=82 method=GET path=/ ua='Mozilla/5.0 (X11; Linu ...
show moreRequests denied due to active blacklist hits (tenant=82 method=GET path=/ ua='Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36')
show less
Web App Attack
Exploited Host
Showing 1 to
15
of 820 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ