This IP address has been reported a total of
9
times from
7 distinct
sources.
157.22.125.252 was first reported on
May 18th 2026 , and the most recent report was
5 days ago .
In the last 60 days, the top reporter locations were:
Czechia
with 2
reports;
Switzerland
with 1
report;
Finland
with 1
report.
The most common categories in these recent reports were:
Brute-Force
5
times;
Hacking
4
times;
Web App Attack
2
times;
VPN IP
2
times;
Bad Web Bot
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ณ๐ฑ
Alt255
2026-09-24 03:55:37
(5 days ago)
[ti-01sc] WordPress XML-RPC abuse: 3 suspicious requests detected by fail2ban jail apache-xmlrpc. Ex ...
show more
[ti-01sc] WordPress XML-RPC abuse: 3 suspicious requests detected by fail2ban jail apache-xmlrpc. Example: 157.22.125.252 - - [24/Sep/2026:05:35:35 +0200] "POST /xmlrpc.php HTTP/2.0" 403 91 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
157.22.125.252 - - [24/Sep/2026:05:55:02 +0200] "POST /xmlrpc.php HTTP/2.0" 403 87 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Safari/605.1.15"
157.22.125.252 - - [24/Sep/2026:05:55:23 +0200] "POST /xmlrpc.php HTTP/2.0" 403 90 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
bittiguru.fi
2026-09-23 13:34:48
(5 days ago)
157.22.125.252 - [23/Sep/2026:16:33:59 +0300] "POST /xmlrpc.php HTTP/2.0" 404 12529 "-" "Mozilla/5.0 ...
show more
157.22.125.252 - [23/Sep/2026:16:33:59 +0300] "POST /xmlrpc.php HTTP/2.0" 404 12529 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0" "4.66"
157.22.125.252 - [23/Sep/2026:16:34:48 +0300] "POST /xmlrpc.php HTTP/2.0" 404 12529 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Safari/605.1.15" "4.66"
...
show less
Hacking
Brute-Force
Web App Attack
๐จ๐ฟ
Countryman
2026-09-13 00:10:01
(2 weeks ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
๐จ๐ฟ
Countryman
2026-09-12 00:10:01
(2 weeks ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
๐จ๐ญ
SOC [GOLINE SA]
2026-09-09 01:10:38
(2 weeks ago)
[RoutePulse | 2026-09-09T01:10:38Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 157.22.125. ...
show more
[RoutePulse | 2026-09-09T01:10:38Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 157.22.125.252 ยท AS213954 Global Transit Systems LLC ยท Seychelles
EVIDENCE: Shunned on the Cisco FTD VPN gateway โ Cisco VPN RA Brute force on Cisco FTDv โ distributed attack (4 attempts/15min) โ shun on the VPN gateway
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
๐บ๐ธ
nationaleventpros.com
2026-06-15 00:04:09
(3 months ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-14 08:55:02
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.125.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.125.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 04:54:55.424675 2026] [security2:error] [pid 15136:tid 15136] [client 157.22.125.252:24299] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lbee.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lbee.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai5sX2ov7OeILVP-fUSeUAAAABc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-30 14:20:03
(3 months ago)
FPROCO WEBEXPLOIT 157.22.125.252 (157.22.125.252)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-18 13:20:56
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.125.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.125.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 09:20:50.259209 2026] [security2:error] [pid 18218:tid 18218] [client 157.22.125.252:19141] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gonzalez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gonzalez.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agsSMlbwrnZeWHNM-b5-vAAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Showing 1 to
9
of 9 reports