Recent Activity
This IP has received recent abuse reports, which causes the score to increase.
Tor Exit Node
This address is a Tor exit node. Neither the
owner nor the provider are directly behind the offending action.
Log in to view charts and search reports for this IP.
Log In
Reports Activity
Example preview
Report Categories (Last 60 Days)
Example preview
Top Reporter Countries (Last 60 Days)
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 185.132.53.58
This IP address has been reported a total of
201
times from
95 distinct
sources.
185.132.53.58 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 11
reports;
United States of America
with 4
reports;
Turkey
with 3
reports.
The most common categories in these recent reports were:
Web App Attack
16
times;
Brute-Force
8
times;
Hacking
6
times;
Port Scan
5
times;
Exploited Host
2
times;
Other
8
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reported by Akarguard DDoS protection: this IP exceeded the per-IP rate limit at our reverse-proxy e ...
show moreReported by Akarguard DDoS protection: this IP exceeded the per-IP rate limit at our reverse-proxy edge (repeated HTTP 444), consistent with an automated Layer 7 flood.
show less
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show moreAsking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: /accueil-entreprises/entreprises-contactez-nous | 2026-09-10 09:36 UTC
show less
[SQL UNION SELECT] f2b match %{+Q}r for ^.*haproxy\[[0-9]+\]: <HOST>:.* (GET |POST ).*\?.*(UNION%20| ...
show more[SQL UNION SELECT] f2b match %{+Q}r for ^.*haproxy\[[0-9]+\]: <HOST>:.* (GET |POST ).*\?.*(UNION%20|union%20|SELECT%20|select%20).* HTTP/1.1$
show less
Web vulnerability scanning / probing from 185.132.53.58: automated requests for CMS admin paths, log ...
show moreWeb vulnerability scanning / probing from 185.132.53.58: automated requests for CMS admin paths, login endpoints, xmlrpc, and common scanner fingerprints over HTTPS. 1 hits; paths: /tracker.
show less
Port Scan
Hacking
Web App Attack
Anonymous
2026-08-28 03:00:14,870 fail2ban.actions [242592]: NOTICE [tor] Ban 185.132.53.58
2026-08-28 ...
show more2026-08-28 03:00:14,870 fail2ban.actions [242592]: NOTICE [tor] Ban 185.132.53.58
2026-08-28 06:00:28,433 fail2ban.actions [242592]: NOTICE [tor] Ban 185.132.53.58
2026-08-28 09:00:12,588 fail2ban.actions [242592]: NOTICE [tor] Ban 185.132.53.58
2026-08-28 10:01:48,499 fail2ban.actions [242592]: NOTICE [tor] Ban 185.132.53.58
2026-08-28 10:03:32,631 fail2ban.actions [242592]: NOTICE [tor] Ban 185.132.53.58
show less
[FriAug2808:02:50.6048362026][security2:error][pid2232716:tid2232810][client185.132.53.58:0]ModSecur ...
show more[FriAug2808:02:50.6048362026][security2:error][pid2232716:tid2232810][client185.132.53.58:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"gmint.ch\"][uri\"/xmlrpc.php\"][unique_id\"apEkiio6Ixk_LN0R5rREZwAAAIA\"]
show less