Log in to view charts and search reports for this IP.
Log In
No reports in the last 60 days
72.11.157.52 has been reported 28
times. The most recent report is from
.
The full history is preserved below and remains searchable. A
0% score reflects the absence of recent activity, but
this is not a guarantee that earlier reports were invalid. Abuse confidence score decays,
naturally, over time, when the abusive activity stops.
IP Abuse Reports for 72.11.157.52:
This IP address has been reported a total of
28
times from
21 distinct
sources.
72.11.157.52 was first reported on
, and the most recent report was
.
(mod_security) mod_security (id:210492) triggered by 72.11.157.52 (72.11.157.52.static.quadranet.com ...
show more(mod_security) mod_security (id:210492) triggered by 72.11.157.52 (72.11.157.52.static.quadranet.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 15 20:05:31.996970 2024] [security2:error] [pid 9347] [client 72.11.157.52:47319] [client 72.11.157.52] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "skinnywheels.xyz"] [uri "/wp-content/themes/arrival/down.php"] [unique_id "Zc602-VG4k1QylM3hmH--wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
Bot / scanning and/or hacking attempts: GET /wp-config.php2 HTTP/1.1, GET /wp-config.phpd HTTP/1.1, ...
show moreBot / scanning and/or hacking attempts: GET /wp-config.php2 HTTP/1.1, GET /wp-config.phpd HTTP/1.1, GET /wp-config.php.original HTTP/1.1, GET //wp-config.php~ HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /wp-config.php.bk HTTP/1.1, GET /wp-config.php_bk HTTP/1.1, GET /wp-content/plugins/cherry-plugin/admin/import-export/downl, GET /wp-config.php_copy HTTP/1.1, done, streams: 0/1/1/0/0 (open/recv/resp/push/rst), GET /wp-config.php-bak HTTP/1.1
show less
(mod_security) mod_security (id:210492) triggered by 72.11.157.52 (NL/The Netherlands/72.11.157.52.s ...
show more(mod_security) mod_security (id:210492) triggered by 72.11.157.52 (NL/The Netherlands/72.11.157.52.static.quadranet.com): 5 in the last 300 secs
show less
(mod_security) mod_security (id:210492) triggered by 72.11.157.52 (NL/The Netherlands/North Holland/ ...
show more(mod_security) mod_security (id:210492) triggered by 72.11.157.52 (NL/The Netherlands/North Holland/Amsterdam/72.11.157.52.static.quadranet.com/[AS207083 HostSlim B.V.]): 5 in the last 3600 secs (CF_ENABLE)
show less
(mod_security) mod_security (id:210492) triggered by 72.11.157.52 (72.11.157.52.static.quadranet.com ...
show more(mod_security) mod_security (id:210492) triggered by 72.11.157.52 (72.11.157.52.static.quadranet.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 15 08:33:30.624810 2024] [security2:error] [pid 21967] [client 72.11.157.52:42375] [client 72.11.157.52] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sirio-b.com"] [uri "/main/wp-content/themes/twentythirteen/down.php"] [unique_id "Zc4SqiHljOBhn9uefTgN1QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
suspicious behavior
Brute-Force
Web App Attack
Anonymous
(mod_security) mod_security triggered on hostname [redacted] 72.11.157.52 (NL/Netherlands/72.11.157. ...
show more(mod_security) mod_security triggered on hostname [redacted] 72.11.157.52 (NL/Netherlands/72.11.157.52.static.quadranet.com)
show less