This IP address has been reported a total of
14
times from
9 distinct
sources.
148.253.212.211 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show moreMalicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-09-01 01:41 UTC
show less
(mod_security) mod_security (id:225170) triggered by 148.253.212.211 (ip148-253-212-211.ptr.my-vm.wo ...
show more(mod_security) mod_security (id:225170) triggered by 148.253.212.211 (ip148-253-212-211.ptr.my-vm.work): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 01:30:00.027158 2026] [security2:error] [pid 9129:tid 9129] [client 148.253.212.211:50666] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.timetemple.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.timetemple.org"] [uri "/wp-json/wp/v2/users"] [unique_id "apURWOnp1uIhy6RmP8aY5gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
Bot / scanning and/or hacking attempts: GET /wp-admin/media-new.php HTTP/1.1, GET /wp-login.php?acti ...
show moreBot / scanning and/or hacking attempts: GET /wp-admin/media-new.php HTTP/1.1, GET /wp-login.php?action=lostpassword&error=invalidkey HTTP/1.1, POST /wp-admin/admin-ajax.php HTTP/1.1, GET /wp-login.php?login=marevista&key=Qx6BqDmFgJ6uhvxuS7Bj&acti, GET /wp-admin/theme-editor.php HTTP/1.1
show less
(wordpress) Failed wordpress login from 148.253.212.211 (PL/Poland/ip148-253-212-211.ptr.my-vm.work) ...
show more(wordpress) Failed wordpress login from 148.253.212.211 (PL/Poland/ip148-253-212-211.ptr.my-vm.work): (CF_ENABLE)
show less
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show moreMalicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-08-30 00:55 UTC
show less
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show moreMalicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-08-29 16:07 UTC
show less
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show moreMalicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-08-29 13:44 UTC
show less
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show moreMalicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: / | query: author=1 | 2026-08-29 08:15 UTC
show less
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show moreMalicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-08-29 01:02 UTC
show less