This IP address has been reported a total of
87
times from
13 distinct
sources.
52.7.118.208 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
France
with 41
reports;
United States of America
with 36
reports;
Germany
with 3
reports.
The most common categories in these recent reports were:
Bad Web Bot
57
times;
Exploited Host
36
times;
DDoS Attack
35
times;
Web App Attack
30
times;
Hacking
2
times;
Other
2
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
HTTP application-layer DoS / botnet traffic from 52.7.118.208: repeated high-cost dynamic page and f ...
show moreHTTP application-layer DoS / botnet traffic from 52.7.118.208: repeated high-cost dynamic page and feed requests (profile/tag views, forums, tracker, RSS) at abusive rates via completed TCP/HTTPS. Likely compromised end-user host.
show less
Vulnerability scanning | method: GET | path: /spip.php | ua: Mozilla/5.0 (X11; Linux x86_64) AppleWe ...
show moreVulnerability scanning | method: GET | path: /spip.php | ua: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 | 2026-10-08 23:34 UTC
show less
Detected by Cloudflare Security Events via WordPress automation. Detection: bad_bot_scanner (Bad bot ...
show moreDetected by Cloudflare Security Events via WordPress automation. Detection: bad_bot_scanner (Bad bot / scanner behavior). Hits from same IP in last 60 minutes: 1. Unique request paths counted internally: 1. Cloudflare action: managed_challenge. Cloudflare source: botFight.
show less
Blocked abusive HTTP application-layer DoS / botnet traffic from 52.7.118.208: traffic from this add ...
show moreBlocked abusive HTTP application-layer DoS / botnet traffic from 52.7.118.208: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show moreKingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 69>=65, Abuse 68, NonEU, first-seen)
show less
Hacking
Exploited Host
Web App Attack
Anonymous
Distributed web scraper targeting /store/filtered/ on shop.grizzlyliquor.com. Residential proxy - IP ...
show moreDistributed web scraper targeting /store/filtered/ on shop.grizzlyliquor.com. Residential proxy - IP+timestamp provided for ISP DHCP log attribution.
show less
HTTP application-layer DoS / botnet traffic from 52.7.118.208: repeated high-cost dynamic page and f ...
show moreHTTP application-layer DoS / botnet traffic from 52.7.118.208: repeated high-cost dynamic page and feed requests (profile/tag views, forums, tracker, RSS) at abusive rates via completed TCP/HTTPS. Likely compromised end-user host.
show less
Blocked abusive HTTP application-layer DoS / botnet traffic from 52.7.118.208: traffic from this add ...
show moreBlocked abusive HTTP application-layer DoS / botnet traffic from 52.7.118.208: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
Detected by Cloudflare Security Events via WordPress automation. Detection: bad_bot_scanner (Bad bot ...
show moreDetected by Cloudflare Security Events via WordPress automation. Detection: bad_bot_scanner (Bad bot / scanner behavior). Hits from same IP in last 60 minutes: 1. Unique request paths counted internally: 1. Cloudflare action: managed_challenge. Cloudflare source: botFight.
show less
HTTP application-layer DoS / botnet traffic from 52.7.118.208: repeated high-cost dynamic page and f ...
show moreHTTP application-layer DoS / botnet traffic from 52.7.118.208: repeated high-cost dynamic page and feed requests (profile/tag views, forums, tracker, RSS) at abusive rates via completed TCP/HTTPS. Likely compromised end-user host.
show less