Log in to view charts and search reports for this IP.
Log In
No reports in the last 60 days
161.118.228.80 has been reported 223
times. The most recent report is from
.
The full history is preserved below and remains searchable. A
0% score reflects the absence of recent activity, but
this is not a guarantee that earlier reports were invalid. Abuse confidence score decays,
naturally, over time, when the abusive activity stops.
This IP address has been reported a total of
223
times from
79 distinct
sources.
161.118.228.80 was first reported on
, and the most recent report was
.
ketovoila.pl web app/PHP backdoor scan: hits=16; unique_paths=15; sample_paths=/wp-content/plugins/h ...
show moreketovoila.pl web app/PHP backdoor scan: hits=16; unique_paths=15; sample_paths=/wp-content/plugins/hello.php,/wp-includes/class-wp.php,/wp-includes/option.php; UA="Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1 Safari/605.1.15"; window=2026-05-30T17:57:42Z..2026-05-30T17:57:43Z
show less
caddy probes: wordpress: GET /wp-admin/(DROP), GET /wp-admin/admin-ajax.php(DROP), GET /wp-admin/loa ...
show morecaddy probes: wordpress: GET /wp-admin/(DROP), GET /wp-admin/admin-ajax.php(DROP), GET /wp-admin/load-scripts.php(DROP), GET /wp-admin/load-styles.php(DROP), GET /wp-content/plugins/(DROP), GET /wp-content/themes/(DROP), GET /wp-content/themes/twentytwenty/(DROP), GET /wp-content/uploads/(DROP), GET /wp-includes/class-wp.php(DROP), GET /wp-includes/css/dashicons.css(DROP), GET /wp-includes/functions.php(DROP), GET /wp-includes/js/jquery/jquery.js(DROP), GET /wp-includes/option.php(DROP), GET /wp-includes/post.php(DROP), GET /wp-includes/user.php(DROP), GET /wp-includes/version.php(DROP), GET /wp-json/(DROP), GET /wp-json/oembed/1.0/embed(DROP), GET /wp-json/wp/v2/(DROP), GET /wp-json/wp/v2/categories(DROP), GET /wp-json/wp/v2/media(DROP), GET /wp-json/wp/v2/pages(DROP), GET /wp-json/wp/v2/posts(DROP), GET /wp-json/wp/v2/tags(DROP), GET /wp-login.php(DROP)
show less
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show moreTriggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1 Safari/605.1.15
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less