AbuseIPDB » 138.68.47.189
138.68.47.189 was found in our database!
This IP was reported 8 times. Confidence of
Abuse
is 44% : ?
ISP
DigitalOcean, LLC
Usage Type
Data Center/Web Hosting/Transit
ASN
AS14061
Domain Name
digitalocean.com
Country
๐บ๐ธ
United States of America
City
Santa Clara, California
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 138.68.47.189 :
This IP address has been reported a total of
8
times from
7 distinct
sources.
138.68.47.189 was first reported on
September 18th 2026 , and the most recent report was
1 day ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
2026-09-18 08:17:57
(1 day ago)
Attack detected: 138.68.47.189 [2026-09-18]
Categories: 18,21
--- wp-login brute force (23 hits) --- ...
show more
Attack detected: 138.68.47.189 [2026-09-18]
Categories: 18,21
--- wp-login brute force (23 hits) ---
138.68.47.189 - - [18/Sep/2026:06:49:00 +0000] "POST /wp-login.php HTTP/1.1" 200 16532 "-" "Mozilla/5.0"
138.68.47.189 - - [18/Sep/2026:07:03:31 +0000] "POST /wp-login.php HTTP/1.1" 200 16532 "-" "Mozilla/5.0"
138.68.47.189 - - [18/Sep/2026:07:18:05 +0000] "POST /wp-login.php HTTP/1.1" 200 16532 "-" "Mozilla/5.0"
138.68.47.189 - - [18/Sep/2026:07:32:50 +0000] "POST /wp-login.php HTTP/1.1" 200 16531 "-" "Mozilla/5.0"
138.68.47.189 - - [18/Sep/2026:07:47:24 +0000] "POST /wp-login.php HTTP/1.1" 200 16532 "-" "Mozilla/5.0"
--- wp2shell/batch exploit (2 hits) ---
138.68.47.189 - - [18/Sep/2026:07:19:58 +0000] "POST /wp-json/batch/v1 HTTP/1.1" 207 720 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
138.68.47.189 - - [18/Sep/2026:07:19:59 +0000] "POST /wp-json/batch/v1 HTTP/1.1" 207 1182 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Ge
show less
Brute-Force
Web App Attack
๐จ๐ญ
Origon
2026-09-18 06:46:49
(1 day ago)
http-cve-probing - IP: 138.68.47.189 - time="2026-09-18T08:46:49+02:00" level=info msg="(555f66b4f6 ...
show more
http-cve-probing - IP: 138.68.47.189 - time="2026-09-18T08:46:49+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-cve-probing by ip 138.68.47.189 (US/14061) : 4h ban on Ip 138.68.47.189" module=db
show less
Web App Attack
๐ช๐ธ
masterguru
2026-09-18 03:36:43
(1 day ago)
wp-login request blocked, no referer. Pattern match "wp-login.php" at REQUEST_URI. (5001900-122)
Web App Attack
๐ฎ๐น
VHosting
2026-09-18 03:05:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-18 03:04:24
(1 day ago)
[ti-11al] WordPress login brute-force: 4 suspicious requests detected by fail2ban jail apache-wordpr ...
show more
[ti-11al] WordPress login brute-force: 4 suspicious requests detected by fail2ban jail apache-wordpress. Example: 138.68.47.189 - - [18/Sep/2026:05:00:14 +0200] "POST /wp-login.php HTTP/1.1" 200 21381 "-" "Mozilla/5.0"
138.68.47.189 - - [18/Sep/2026:05:00:14 +0200] "POST /wp-login.php HTTP/1.1" 200 21393 "-" "Mozilla/5.0"
138.68.47.189 - - [18/Sep/2026:05:04:04 +0200] "POST /wp-login.php HTTP/1.1" 200 21381 "-" "Mozilla/5.0"
138.68.47.189 - - [18/Sep/2026:05:04:04 +0200] "POST /wp-login.php HTTP/1.1" 200 21395 "-" "Mozilla/5.0"
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-09-18 03:01:34
(1 day ago)
wp-login request blocked, no referer. Pattern match "wp-login.php" at REQUEST_URI. (88020-193)
Hacking
๐ณ๐ด
jad-abuse
2026-09-18 02:31:18
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_login. ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_login. Observed by 1 sensor(s); 2 hits.
show less
Brute-Force
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-18 01:55:51
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 138.68.47.189 (US/United States/-): ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 138.68.47.189 (US/United States/-): 2 in the last 3600 secs
show less
Web App Attack
Showing 1 to
8
of 8 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: