Log in to view charts and search reports for this IP.
Log In
No reports in the last 60 days
52.138.205.172 has been reported 61
times. The most recent report is from
.
The full history is preserved below and remains searchable. A
0% score reflects the absence of recent activity, but
this is not a guarantee that earlier reports were invalid. Abuse confidence score decays,
naturally, over time, when the abusive activity stops.
IP Abuse Reports for 52.138.205.172:
This IP address has been reported a total of
61
times from
45 distinct
sources.
52.138.205.172 was first reported on
, and the most recent report was
.
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrp ...
show moreFail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrpc_attack, wp-login brute force, excessive crawling/scraping
show less
2024/04/19 14:43:39 [error] 3364684#3364684: *528749 FastCGI sent in stderr: "PHP message: BOT WARNI ...
show more2024/04/19 14:43:39 [error] 3364684#3364684: *528749 FastCGI sent in stderr: "PHP message: BOT WARNING: visitor used the honeypot: 52.138.205.172, you should ban it for long time (honeypot form function-abuseipdb)" while reading response header from upstream, client: 52.138.205.172, server: www.elivecd.org, request: "POST / HTTP/1.1", upstream: "fastcgi://unix:/run/php/php8.2-fpm-elivewp.sock:", host: "78.141.243.157"
...
show less
(mod_security) mod_security (id:949110) triggered by 52.138.205.172 (-): 3 in the last 3600 secs; Po ...
show more(mod_security) mod_security (id:949110) triggered by 52.138.205.172 (-): 3 in the last 3600 secs; Ports: *; Direction: 0; Trigger: LF_MODSEC;
show less