This IP address has been reported a total of
34
times from
26 distinct
sources.
167.99.68.252 was first reported on
August 26th 2026 , and the most recent report was
1 month ago .
In the last 60 days, the top reporter locations were:
Germany
with 15
reports;
Netherlands
with 7
reports;
United States of America
with 3
reports.
The most common categories in these recent reports were:
Web App Attack
27
times;
Brute-Force
10
times;
Exploited Host
5
times;
Hacking
5
times;
Port Scan
3
times;
Other
7
times.
Old Reports
The most recent abuse report for this IP address is from
1 month ago . It is possible that this IP is no
longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ฌ๐ท
setupgr
2026-08-27 02:53:06
(1 month ago)
(wplogin_block) Blocked WP-Login Access Attempt 167.99.68.252 (SG/Singapore/-/Singapore (Pioneer)/-/ ...
show more
(wplogin_block) Blocked WP-Login Access Attempt 167.99.68.252 (SG/Singapore/-/Singapore (Pioneer)/-/[AS14061 DIGITALOCEAN-ASN]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 167.99.68.252 - - [27/Aug/2026:05:39:44 +0300] "GET /wp-login.php HTTP/1.1" 301 280 "https://www.google.com/search?q=wordpress" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1; rv:119.0) Gecko/20100101 Firefox/119.0"
show less
Port Scan
๐ฆ๐บ
paulshipley.com.au
2026-08-27 02:24:38
(1 month ago)
valueaddedpromotions.com.au:443 167.99.68.252 - - [27/Aug/2026:12:24:36 +1000] "GET /?author=1 HTTP/ ...
show more
valueaddedpromotions.com.au:443 167.99.68.252 - - [27/Aug/2026:12:24:36 +1000] "GET /?author=1 HTTP/1.1" 404 347961 "https://www.bing.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 19:50:14
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 167.99.68.252 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 167.99.68.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 15:50:06.914452 2026] [security2:error] [pid 19630:tid 19630] [client 167.99.68.252:53087] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.test.artfranz.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.test.artfranz.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao9Dbp00VoxxqM-TyZAcQQAAABM"], referer: https://www.google.com/search?q=wordpress
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-26 19:40:52
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
Showing 31 to
34
of 34 reports