This IP address has been reported a total of
56
times from
40 distinct
sources.
18.118.26.166 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
(wordpress) Failed wordpress login from 18.118.26.166 (US/United States/ec2-18-118-26-166.us-east-2. ...
show more(wordpress) Failed wordpress login from 18.118.26.166 (US/United States/ec2-18-118-26-166.us-east-2.compute.amazonaws.com): (CF_ENABLE)
show less
(mod_security) mod_security (id:210410) triggered by 18.118.26.166 (US/United States/ec2-18-118-26-1 ...
show more(mod_security) mod_security (id:210410) triggered by 18.118.26.166 (US/United States/ec2-18-118-26-166.us-east-2.compute.amazonaws.com): 5 in the last 300 secs (CF_ENABLE)
show less
[SunJun1404:40:01.4592492026][security2:error][pid1792:tid2019][client18.118.26.166:0]ModSecurity:Ac ...
show more[SunJun1404:40:01.4592492026][security2:error][pid1792:tid2019][client18.118.26.166:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"368\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"cadvending.ch\"][uri\"/xmlrpc.php\"][unique_id\"ai4UgUPIg4ImD_5U-fd0dwAAAQE\"]
show less
(mod_security) mod_security (id:225170) triggered by 18.118.26.166 (ec2-18-118-26-166.us-east-2.comp ...
show more(mod_security) mod_security (id:225170) triggered by 18.118.26.166 (ec2-18-118-26-166.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 22:36:04.783349 2026] [security2:error] [pid 27366:tid 27366] [client 18.118.26.166:60172] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||campnecon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "campnecon.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ai4TlF5WIQ82xX30hbpwdgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
(wordpress) Failed wordpress login from 18.118.26.166 (US/United States/ec2-18-118-26-166.us-east-2. ...
show more(wordpress) Failed wordpress login from 18.118.26.166 (US/United States/ec2-18-118-26-166.us-east-2.compute.amazonaws.com)
show less
(mod_security) mod_security (id:225170) triggered by 18.118.26.166 (ec2-18-118-26-166.us-east-2.comp ...
show more(mod_security) mod_security (id:225170) triggered by 18.118.26.166 (ec2-18-118-26-166.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 22:17:23.718511 2026] [security2:error] [pid 18908:tid 18908] [client 18.118.26.166:51520] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.londongroup.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.londongroup.info"] [uri "/wp-json/wp/v2/users/"] [unique_id "ai4PM2_zorxme59yrkzZFgAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
(wordpress) Failed wordpress login from 18.118.26.166 (US/United States/Ohio/Columbus/ec2-18-118-26- ...
show more(wordpress) Failed wordpress login from 18.118.26.166 (US/United States/Ohio/Columbus/ec2-18-118-26-166.us-east-2.compute.amazonaws.com/[redacted])
show less
[SunJun1404:04:48.2396192026][security2:error][pid2004027:tid2004132][client18.118.26.166:0]ModSecur ...
show more[SunJun1404:04:48.2396192026][security2:error][pid2004027:tid2004132][client18.118.26.166:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"studio-portale.ch\"][uri\"/xmlrpc.php\"][unique_id\"ai4MQI_hyaERasGkonGexQAAAMg\"]
show less