This IP address has been reported a total of
61
times from
37 distinct
sources.
185.132.53.47 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
2026-09-21 18:00:15,444 fail2ban.actions [1813714]: NOTICE [tor] Ban 185.132.53.47
2026-09-2 ...
show more2026-09-21 18:00:15,444 fail2ban.actions [1813714]: NOTICE [tor] Ban 185.132.53.47
2026-09-21 21:00:15,573 fail2ban.actions [1813714]: NOTICE [tor] Ban 185.132.53.47
2026-09-22 00:00:16,985 fail2ban.actions [1813714]: NOTICE [tor] Ban 185.132.53.47
2026-09-22 03:00:36,622 fail2ban.actions [1813714]: NOTICE [tor] Ban 185.132.53.47
2026-09-22 06:01:11,266 fail2ban.actions [1813714]: NOTICE [tor] Ban 185.132.53.47
show less
This address sends abusive requests to WordPress sites we host: user enumeration through the REST AP ...
show moreThis address sends abusive requests to WordPress sites we host: user enumeration through the REST API, xmlrpc.php calls the site refuses, endpoints the site does not serve. These are the reconnaissance and attack calls of automated WordPress attack tools, blocked on sight. Please check the machine behind it. | method: POST | path: /xmlrpc.php | 2026-09-21 18:25 UTC
show less
Reported by Akarguard DDoS protection: this IP exceeded the per-IP rate limit at our reverse-proxy e ...
show moreReported by Akarguard DDoS protection: this IP exceeded the per-IP rate limit at our reverse-proxy edge (repeated HTTP 444), consistent with an automated Layer 7 flood.
show less
Active Response: IP Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). Reported by Tang ...
show moreActive Response: IP Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 185.132.53.47 (DE/Germany/lain.185. ...
show moreLF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 185.132.53.47 (DE/Germany/lain.185.132.53.47.aluy.net): 1 in the last 3600 secs
show less
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show moreMalicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-content/plugins/woocommerce/readme.txt (+3 more) | 2026-09-07 13:14 UTC
show less
Hacking
Web App Attack
Anonymous
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
| [Dangerous/Singapore] Aggressive IP 185.132.53.47 (~30 hits). Type: DoS Defender- Web server 400 e ...
show more| [Dangerous/Singapore] Aggressive IP 185.132.53.47 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
Showing 1 to
15
of 61 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ