This IP address has been reported a total of
8
times from
6 distinct
sources.
179.238.29.166 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 4
reports;
Switzerland
with 1
report;
Italy
with 1
report.
The most common categories in these recent reports were:
Web App Attack
7
times;
Hacking
4
times;
Brute-Force
2
times;
Port Scan
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
WordPress attack-tool calls | method: POST | path: /xmlrpc.php | ua: Mozilla/5.0 (Macintosh; Intel M ...
show moreWordPress attack-tool calls | method: POST | path: /xmlrpc.php | ua: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/87.0.0.0 Safari/537.36 | 2026-09-29 18:54 UTC
show less
[TueSep2920:35:56.5660902026][security2:error][pid1132598:tid1132724][client179.238.29.166:0]ModSecu ...
show more[TueSep2920:35:56.5660902026][security2:error][pid1132598:tid1132724][client179.238.29.166:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"714\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"support-ticino.ch\"][uri\"/xmlrpc.php\"][unique_id\"arwFDFo4syX7YQYAlkCjEwAAAJQ\"]
show less
Unauthorized automated scanning and reconnaissance against Solantex resources. No crawl, scan or tes ...
show moreUnauthorized automated scanning and reconnaissance against Solantex resources. No crawl, scan or test permission has been granted to this source.
show less
WordPress attack-tool calls | method: POST | path: /xmlrpc.php | ua: Mozilla/5.0 (Windows NT 6.2; ar ...
show moreWordPress attack-tool calls | method: POST | path: /xmlrpc.php | ua: Mozilla/5.0 (Windows NT 6.2; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/90.0.0.0 Safari/537.36
show less
[TueSep2911:11:12.2680112026][security2:error][pid2065139:tid2065190][client179.238.29.166:0]ModSecu ...
show more[TueSep2911:11:12.2680112026][security2:error][pid2065139:tid2065190][client179.238.29.166:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"globalhorizon.ch\"][uri\"/xmlrpc.php\"][unique_id\"aruAsA0xOJDDvEjuNHaqXwAAAEs\"]
show less
Port Scan
Brute-Force
Web App Attack
Showing 1 to
8
of 8 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown 🚩