Report for IP: 165.22.115.137

Threat LevelMEDIUM45/1003 rule types across 3 attack categories
3 incidents on record · 3 rule types · confirmed on global blocklist · persistent 12-day campaign · last seen 16d ago
PTR N/A
Org / ASN DigitalOcean, LLC
Country 🇬🇧 United Kingdom
City Slough, England
Timezone Europe/London

Attack Analysis

Backup & Database File Probe
This IP requested common backup file paths (.bak, .sql, .zip, wp-config.bak), hunting for database dumps or config files containing plaintext credentials. A single exposed wp-config.bak can hand an attacker full database access. This attack is automated and deliberate.
Geo-Blocked Country
This IP was blocked purely based on its country of origin — the site owner has restricted access from this IP's geographic location due to a pattern of unwanted traffic from that region. This does not necessarily mean the specific IP itself has attacked anything; it reflects a blanket country-level policy.
Listed on 1 threat-intelligence blocklist
  • FireHOL level2 — FireHOL level2 lists addresses seen attacking in the last 48 hours across many sensors. It is large and volatile: addresses enter and leave quickly, so on its own this is weaker, recent-activity evidence.
Only short-lived or context lists match, so this is weak evidence on its own.

Reports (3)

Date Severity Description
14 Sep 2026 - 03:34 low FireHOL level2 (48h recent-attacker feed, large & volatile)
13 Sep 2026 - 11:35 low Geo Blocker — Country Match
2 Sep 2026 - 02:10 high Web: Backup/database file probe