This IP address has been reported a total of
15
times from
8 distinct
sources.
178.253.99.209 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
Bot / scanning and/or hacking attempts: GET /.env.old HTTP/1.1, GET /wp-config.php.orig HTTP/1.1, GE ...
show moreBot / scanning and/or hacking attempts: GET /.env.old HTTP/1.1, GET /wp-config.php.orig HTTP/1.1, GET /wp-config.php.bak HTTP/1.1
show less
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show moreAsking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-12 09:23 UTC
show less
(mod_security) mod_security (id:210492) triggered by 178.253.99.209 (lumiai-agency.com): 1 in the la ...
show more(mod_security) mod_security (id:210492) triggered by 178.253.99.209 (lumiai-agency.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 17:14:15.104072 2026] [security2:error] [pid 2017:tid 2017] [client 178.253.99.209:46296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mardensmith.com"] [uri "/wp-config.php.orig"] [unique_id "ap8pJ2kfZLhHCP1jueIykgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
[ns41.kdns.gr] httpd-config-scan: sites=www.koukas-machines.com; logs=/var/log/httpd/domains/koukas- ...
show more[ns41.kdns.gr] httpd-config-scan: sites=www.koukas-machines.com; logs=/var/log/httpd/domains/koukas-machines.com.log; samples=/wp-config.php~ | /wp-config.php.orig
show less
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 178.253.99.209 (SY/Syria/lumiai-age ...
show moreLF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 178.253.99.209 (SY/Syria/lumiai-agency.com): 1 in the last 3600 secs
show less
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 178.253.99.209 (SY/Syria/lumiai-agenc ...
show more(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 178.253.99.209 (SY/Syria/lumiai-agency.com): 1 in the last 3600 secs (0-196)
show less
Hacking
Showing 1 to
15
of 15 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ