AbuseIPDB » 2800:6c0:3::199c
2800:6c0:3::199c was found in our database!
This IP was reported 8 times. Confidence of
Abuse
is 0% : ?
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
ISP
Dattatec.com
Usage Type
Data Center/Web Hosting/Transit
ASN
AS27823
Hostname(s)
vps-3123330-x.dattaweb.com
Domain Name
donweb.com
Country
๐ฆ๐ท
Argentina
City
Rosario, Santa Fe
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 2800:6c0:3::199c :
This IP address has been reported a total of
8
times from
3 distinct
sources.
2800:6c0:3::199c was first reported on
May 31st 2024 , and the most recent report was
2 years ago .
Old Reports:
The most recent abuse report for this IP address is from
2 years ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐บ๐ธ
TPI-Abuse
2024-07-08 13:41:39
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2800:6c0:3::199c (vps-3123330-x.dattaweb.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 2800:6c0:3::199c (vps-3123330-x.dattaweb.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 08 09:41:30.996652 2024] [security2:error] [pid 25115] [client 2800:6c0:3::199c:57718] [client 2800:6c0:3::199c] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mcthorpe.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mcthorpe.com"] [uri "/blog.bak"] [unique_id "ZovsihGnCu15cNf21h78WgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-07-02 07:07:41
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2800:6c0:3::199c (vps-3123330-x.dattaweb.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 2800:6c0:3::199c (vps-3123330-x.dattaweb.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 02 03:07:25.475704 2024] [security2:error] [pid 26610] [client 2800:6c0:3::199c:47338] [client 2800:6c0:3::199c] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||glaswood.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "glaswood.com"] [uri "/wp.bak"] [unique_id "ZoOnLRtbkAG0hnG8XQCX7QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
preissler.co.uk
2024-06-25 18:39:35
(2 years ago)
Web scanning
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-20 11:53:34
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 2800:6c0:3::199c (vps-3123330-x.dattaweb.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 2800:6c0:3::199c (vps-3123330-x.dattaweb.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 20 07:53:24.135889 2024] [security2:error] [pid 6525] [client 2800:6c0:3::199c:33034] [client 2800:6c0:3::199c] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kavahawaii.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kavahawaii.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZnQYND3Fb_yXtUekjWNUGgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-09 12:43:27
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2800:6c0:3::199c (vps-3123330-x.dattaweb.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 2800:6c0:3::199c (vps-3123330-x.dattaweb.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 09 08:43:20.319521 2024] [security2:error] [pid 24938] [client 2800:6c0:3::199c:53434] [client 2800:6c0:3::199c] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||britishfolk.org|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "britishfolk.org"] [uri "/code.bak"] [unique_id "ZmWjaIbi0U_2v46NqehedgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-08 14:09:32
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2800:6c0:3::199c (vps-3123330-x.dattaweb.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 2800:6c0:3::199c (vps-3123330-x.dattaweb.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 08 10:09:22.169832 2024] [security2:error] [pid 8975] [client 2800:6c0:3::199c:35048] [client 2800:6c0:3::199c] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||30daysout.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "30daysout.com"] [uri "/a.bak"] [unique_id "ZmRmEi5FYsIvisl-N3VO-QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-05 01:20:17
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2800:6c0:3::199c (vps-3123330-x.dattaweb.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 2800:6c0:3::199c (vps-3123330-x.dattaweb.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 04 21:20:12.660913 2024] [security2:error] [pid 8946] [client 2800:6c0:3::199c:54430] [client 2800:6c0:3::199c] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||anenglishcottage.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "anenglishcottage.com"] [uri "/master.bak"] [unique_id "Zl-9TDUCXrPoXqGCqLzBmAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2024-05-31 21:53:55
(2 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
Showing 1 to
8
of 8 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: