This IP address has been reported a total of
15
times from
6 distinct
sources.
5.157.52.30 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 4
reports;
United States of America
with 3
reports;
Czechia
with 1
report.
Over the same time period, 5.157.52.30 has changed
country of origin 2 times.
The most common categories in these recent reports were:
Hacking
5
times;
Web App Attack
5
times;
Bad Web Bot
4
times;
Exploited Host
2
times;
DDoS Attack
2
times;
Other
2
times.
Old Reports
The most recent abuse report for this IP address is from
. It is possible that this IP is no
longer involved in abusive activities.
Blocked abusive HTTP application-layer DoS / botnet traffic from 5.157.52.30: traffic from this addr ...
show moreBlocked abusive HTTP application-layer DoS / botnet traffic from 5.157.52.30: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
This address sends abusive requests to WordPress sites we host: user enumeration through the REST AP ...
show moreThis address sends abusive requests to WordPress sites we host: user enumeration through the REST API, xmlrpc.php calls the site refuses, endpoints the site does not serve. These are the reconnaissance and attack calls of automated WordPress attack tools, blocked on sight. Please check the machine behind it. | method: POST | path: /xmlrpc.php | 2026-09-22 04:18 UTC
show less
Blocked abusive HTTP application-layer DoS / botnet traffic from 5.157.52.30: traffic from this addr ...
show moreBlocked abusive HTTP application-layer DoS / botnet traffic from 5.157.52.30: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
Web spam bot from 5.157.52.30: automated HTTPS requests for fake pharmacy / prescription / drug SEO ...
show moreWeb spam bot from 5.157.52.30: automated HTTPS requests for fake pharmacy / prescription / drug SEO URLs (bbs and blog product-style paths). 1 hits; paths: /blogs/abhorrentonthego/Online-Pharmacy-Travel-Medications.
show less
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: ...
show moreMalicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: /xmlrpc.php | 2026-09-06 12:12 UTC
show less
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: ...
show moreMalicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: /xmlrpc.php | 2026-09-05 06:43 UTC
show less
Triggered Cloudflare WAF (firewallCustom) from SE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show moreTriggered Cloudflare WAF (firewallCustom) from SE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Triggered Cloudflare WAF (firewallCustom) from SE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show moreTriggered Cloudflare WAF (firewallCustom) from SE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /genshin-stella-mod
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 YaBrowser/22.7.0 Yowser/2.5 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
[Sat Mar 05 14:48:53.727830 2022] [proxy_fcgi:error] [pid 27907:tid 140245060261632] [client 5.157.5 ...
show more[Sat Mar 05 14:48:53.727830 2022] [proxy_fcgi:error] [pid 27907:tid 140245060261632] [client 5.157.52.30:39343] AH01071: Got error 'Primary script unknown\n', referer: https://lancairtalk.net/
...
show less