Ban Hackers

Back in the day, hackers were unemployed or unemployable programmers or teenagers with nothing to do.
Now days, it's criminal organizations and Programmers (with a capital P) with masters degrees hired by foreign (and not so foreign) governments to hack into every server they can find. They even try to scan every possible IP address for web servers. When they find one, somebody later tries to hack it.
So, I set up a website for them to visit. It says Coming Soon.
Then, it records their IP Address and bans it from the server with iptables. It also adds their IP Address and User Agent string to the database.

Here are the IP addresses I've banned over the last week:
BannedID IP User Agent String Date Hacked Banned Reason
69917177.52.119.44Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.710/19/2025 03:36:07 AMTried to access http ip directly.
6991635.203.210.224Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity10/19/2025 01:25:47 AMTried to access http ip directly.
6991523.180.120.244ip9max/1.010/19/2025 01:24:21 AMTried to access http ip directly.
6991420.163.60.90Mozilla/5.0 zgrab/0.x10/19/2025 12:45:59 AMUser Agent Mozilla/5.0 zgrab/0.x
69913152.42.255.50Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);10/18/2025 11:52:12 PMEvil 404 .env (AWS vulnerability)
69912144.172.103.124Mozilla/5.0 (X11; Linux x86_64; rv:140.0) Gecko/20100101 Firefox/140.010/18/2025 11:03:36 PMTried to access http ip directly.
69911194.26.29.44masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)10/18/2025 08:55:52 PMTried to access http ip directly.
699103.83.41.233Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.3610/18/2025 08:52:20 PMTried to access http ip directly.
69909157.20.32.213Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.3610/18/2025 07:42:41 PMEvil 404 .env (AWS vulnerability)
69908195.178.110.68Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.010/18/2025 07:14:46 PMEvil 404 .env (AWS vulnerability)
6990774.235.4.85python-requests/2.32.310/18/2025 06:28:53 PMTried to access http ip directly.
69906188.212.159.1110/18/2025 06:03:23 PMTried to log in as root with no password.
69905176.65.148.93Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:77.0) Gecko/20100101 Firefox/77.010/18/2025 05:32:31 PMEvil 404 /boaform/admin/formTracert
69904135.119.88.100Mozilla/5.0 zgrab/0.x10/18/2025 03:21:14 PMTried to access http ip directly.
699035.39.58.236Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.3610/18/2025 02:47:07 PMTried to access http ip directly.
69902167.172.47.74Mozilla/5.0 zgrab/0.x10/18/2025 11:20:27 AMTried to access http ip directly.
6990151.68.46.249python-requests/2.25.110/18/2025 11:15:46 AMUser Agent python-requests/2.25.1
69900170.62.100.230Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.3610/18/2025 10:07:29 AMTried to access http ip directly.
6989934.77.161.183python-requests/2.32.510/18/2025 08:27:39 AMTried to access http ip directly.
6989820.98.165.154Mozilla/5.0 zgrab/0.x10/18/2025 08:24:57 AMUser Agent Mozilla/5.0 zgrab/0.x
69897212.42.199.187Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/18/2025 08:24:46 AMEvil 404 /wp-login.php.bak
6989684.33.243.56Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/18/2025 08:24:45 AMTried to access http ip directly.
69895191.96.173.189Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/18/2025 08:24:08 AMTried to access http ip directly.
6989420.51.201.52python-requests/2.32.510/18/2025 08:23:58 AMTried to access http ip directly.
6989382.24.235.229Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/18/2025 08:21:38 AMEvil 404 /wp-login.php.bak
69892104.250.201.116Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/18/2025 08:21:35 AMTried to access http ip directly.
69891156.243.186.74Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/18/2025 08:21:02 AMTried to access http ip directly.
69890172.174.203.87python-requests/2.32.510/18/2025 08:20:51 AMTried to access http ip directly.
6988945.142.193.27Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.4610/18/2025 08:07:59 AMTried to access http ip directly.
69888113.116.156.3710/18/2025 05:44:32 AMTried to log in as root with no password.
6988735.216.159.22210/18/2025 05:32:57 AMTried to log in as root with no password.
69886185.48.52.4Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/18/2025 01:47:01 AMEvil 404 .env (AWS vulnerability)
69885172.206.225.82Mozilla/5.0 zgrab/0.x10/18/2025 01:46:59 AMUser Agent Mozilla/5.0 zgrab/0.x
6988431.59.10.207Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/18/2025 01:46:50 AMEvil 404 /admin/logs/errors.log
69883145.223.62.9Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/18/2025 01:46:47 AMEvil 404 /admin/logs/error.log
69882107.172.156.114Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/18/2025 01:46:40 AMEvil 404 /admin/errors.log
69881154.6.128.79Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/18/2025 01:46:37 AMEvil 404 /admin/error.log
69880194.39.33.231Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/18/2025 01:46:31 AMEvil 404 .env (AWS vulnerability)
6987920.55.102.4python-requests/2.32.510/18/2025 01:46:24 AMTried to access http ip directly.
6987845.41.177.242Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/18/2025 01:39:27 AMEvil 404 .env (AWS vulnerability)
6987745.43.95.91Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/18/2025 01:39:18 AMEvil 404 /admin/logs/errors.log
69876154.29.25.63Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/18/2025 01:39:15 AMEvil 404 /admin/logs/error.log
6987545.43.64.198Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/18/2025 01:39:12 AMEvil 404 /admin/log/error.log
69874206.206.124.46Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/18/2025 01:39:10 AMEvil 404 /admin/errors.log
69873216.173.105.171Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/18/2025 01:39:05 AMEvil 404 /admin/error.log
6987282.22.220.159Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/18/2025 01:38:56 AMEvil 404 .env (AWS vulnerability)
6987120.55.24.42python-requests/2.32.510/18/2025 01:38:52 AMTried to access http ip directly.
69870167.99.148.211Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);10/18/2025 12:02:49 AMEvil 404 .env (AWS vulnerability)
69869134.209.107.2Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.3610/17/2025 11:18:21 PMEvil 404 /wp-includes/ID3/license.txt
6986816.171.4.29python-httpx/0.24.110/17/2025 10:01:12 PMUser Agent python-httpx/0.24.1
6986765.49.1.108Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:141.0) Gecko/20100101 Firefox/141.010/17/2025 10:01:07 PMTried to access http ip directly.
69866144.172.89.99Mozilla/5.0 (X11; Linux x86_64; rv:140.0) Gecko/20100101 Firefox/140.010/17/2025 09:16:21 PMTried to access http ip directly.
69865147.185.132.112Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity10/17/2025 07:15:05 PMTried to access http ip directly.
6986413.212.13.233python-httpx/0.24.110/17/2025 06:21:59 PMUser Agent python-httpx/0.24.1
6986320.64.105.126Mozilla/5.0 zgrab/0.x10/17/2025 05:50:01 PMUser Agent Mozilla/5.0 zgrab/0.x
6986245.231.31.60Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.3010/17/2025 05:47:36 PMEvil 404 .env (AWS vulnerability)
6986120.118.202.209Mozilla/5.0 zgrab/0.x10/17/2025 05:19:34 PMUser Agent Mozilla/5.0 zgrab/0.x
69860107.155.50.87Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.3610/17/2025 04:06:25 PMTried to access http ip directly.
698593.136.108.196Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.010/17/2025 02:36:06 PMEvil 404 .env (AWS vulnerability)
69858165.154.125.19Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.3610/17/2025 12:16:03 PMTried to access http ip directly.
69857165.22.209.253Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);10/17/2025 12:01:15 PMEvil 404 .env (AWS vulnerability)
6985620.55.3.202Mozilla/5.0 zgrab/0.x10/17/2025 09:36:53 AMTried to access http ip directly.
69855185.247.137.242Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)10/17/2025 08:41:02 AMTried to access http ip directly.
6985487.120.191.93Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.3610/17/2025 08:12:22 AMTried to access http ip directly.
69853172.236.8.84Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.010/17/2025 07:15:19 AMTried to access http ip directly.
69852143.110.218.4Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.3610/17/2025 06:19:23 AMTried to access http ip directly.
6985165.111.14.97python-requests/2.32.510/17/2025 05:41:38 AMUser Agent python-requests/2.32.5
69850216.26.255.79python-requests/2.32.510/17/2025 05:41:37 AMUser Agent python-requests/2.32.5
69849101.36.127.24Mozilla/5.0 (Windows NT 7_1_2; Win64; x64) AppleWebKit/595.43 (KHTML, like Gecko) Chrome/82.0.2971 Safari/537.3610/17/2025 05:34:16 AMTried to access http ip directly.
69848146.190.153.29Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.3610/17/2025 04:23:18 AMEvil 404 /wp-includes/wlwmanifest.xml
69847146.190.167.150Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.3610/17/2025 03:52:32 AMEvil 404 /wp-includes/wlwmanifest.xml
69846162.216.150.93Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity10/17/2025 03:47:23 AMTried to access http ip directly.
6984578.189.78.2110/17/2025 02:32:01 AMTried to log in as root with no password.
69844176.123.248.108Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.3610/17/2025 01:07:07 AMTried to access http ip directly.
69843195.184.76.15Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.010/17/2025 12:11:53 AMTried to access http ip directly.
6984234.38.19.235python-requests/2.32.510/16/2025 11:47:34 PMTried to access http ip directly.
69840165.232.46.56Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);10/16/2025 11:38:54 PMEvil 404 .env (AWS vulnerability)
69841196.251.66.5810/16/2025 11:32:47 PMTried to log in as root with no password.
69839143.198.239.191Linux Gnu (cow)10/16/2025 11:24:21 PMTried to access http ip directly.
6983820.65.217.91Mozilla/5.0 zgrab/0.x10/16/2025 11:00:14 PMUser Agent Mozilla/5.0 zgrab/0.x
69837124.198.131.83Mozilla/5.0 (bang2012@tutanota.de)10/16/2025 10:47:19 PMEvil 404 /cgi-bin/luci/;stok=/locale?form=country&operation
6983654.221.190.180Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.3610/16/2025 10:31:11 PMTried to access http ip directly.
6983543.248.108.188Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.3610/16/2025 07:49:45 PMTried to access http ip directly.
69834134.199.175.156Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.3610/16/2025 07:31:03 PMTried to access http ip directly.
69833209.50.164.200Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.3610/16/2025 04:53:23 PMEvil 404 /wp-includes/ID3/license.txt
69832103.99.33.204Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/16/2025 04:05:44 PMTried to access http ip directly.
6983192.113.7.59Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/16/2025 04:05:43 PMTried to access http ip directly.
69830104.253.41.68Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/16/2025 04:05:43 PMTried to access http ip directly.
6982964.137.94.42Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/16/2025 04:05:42 PMTried to access http ip directly.
6982845.38.78.143Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/16/2025 04:05:41 PMTried to access http ip directly.
69827156.243.187.175Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/16/2025 04:05:41 PMTried to access http ip directly.
69826168.199.209.4Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/16/2025 04:05:39 PMTried to access http ip directly.
698252.57.31.141Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/16/2025 04:05:38 PMTried to access http ip directly.
6982482.27.247.39Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/16/2025 04:05:38 PMTried to access http ip directly.
6982382.22.232.236Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/16/2025 04:05:37 PMTried to access http ip directly.
6982245.43.189.52Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/16/2025 04:05:36 PMTried to access http ip directly.
6982194.46.206.119Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/16/2025 04:05:35 PMTried to access http ip directly.
6982092.112.200.107Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/16/2025 04:05:34 PMEvil 404 /cgi-bin/printenv.pl
69819142.147.129.197Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.3610/16/2025 04:05:33 PMTried to access http ip directly.
69818172.203.249.110python-requests/2.32.510/16/2025 04:05:28 PMTried to access http ip directly.
6981745.156.129.66Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.3610/16/2025 03:31:13 PMTried to access http ip directly.
69816192.250.230.2python-requests/2.31.010/16/2025 03:06:57 PMUser Agent python-requests/2.31.0
69815167.71.129.121Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.3610/16/2025 02:40:55 PMTried to access http ip directly.
6981443.131.32.36Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.110/16/2025 01:49:13 PMTried to access http ip directly.
69813159.65.14.87Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.3610/16/2025 01:48:38 PMEvil 404 /wp-includes/wlwmanifest.xml
6981235.233.95.0python-requests/2.32.510/16/2025 12:59:46 PMTried to access http ip directly.
6981140.124.180.92Mozilla/5.0 zgrab/0.x10/16/2025 12:08:37 PMTried to access http ip directly.
6981080.191.171.13Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.3610/16/2025 12:08:04 PMTried to access http ip directly.
69809159.89.162.182Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);10/16/2025 11:37:08 AMEvil 404 .env (AWS vulnerability)
6980845.94.31.31Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.3610/16/2025 09:23:50 AMEvil 404 /wp-includes/wlwmanifest.xml
6980744.249.3.119python-httpx/0.28.110/16/2025 09:07:56 AMUser Agent python-httpx/0.28.1
6980687.120.191.92Hello World10/16/2025 07:51:54 AMTried to access http ip directly.
69805101.36.123.67Mozilla/5.0 (Windows NT 7_1_1; Win64; x64) AppleWebKit/557.53 (KHTML, like Gecko) Chrome/68.0.1128 Safari/537.3610/16/2025 07:40:07 AMTried to access http ip directly.
6980435.223.251.1Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.3610/16/2025 06:11:25 AMEvil 404 /wp-includes/js/jquery/jquery.js
6980391.231.89.2Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.010/16/2025 05:49:10 AMTried to access http ip directly.
69802185.73.23.159Mozilla/5.0 zgrab/0.x10/16/2025 05:36:19 AMTried to access http ip directly.
6980120.64.105.221Mozilla/5.0 zgrab/0.x10/16/2025 04:41:47 AMUser Agent Mozilla/5.0 zgrab/0.x
6980013.86.113.74Mozilla/5.0 zgrab/0.x10/16/2025 04:04:32 AMUser Agent Mozilla/5.0 zgrab/0.x
69799194.187.176.133Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.010/16/2025 03:53:30 AMTried to access http ip directly.
6979818.212.162.71Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.3610/16/2025 02:59:47 AMTried to access http ip directly.
6979766.132.153.132Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)10/16/2025 02:43:49 AMTried to access http ip directly.
69796185.195.24.69Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.3610/16/2025 01:51:35 AMEvil 404 /admin/
6979591.217.80.200Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 YaBrowser/25.2.0.0 Safari/537.3610/16/2025 01:51:33 AMEvil 404 /admin/
69794216.180.246.62'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)'10/16/2025 01:22:01 AMTried to access http ip directly.
69793195.96.129.4Mozilla/5.010/16/2025 12:27:10 AMTried to access http ip directly.
69792167.172.100.49Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.3610/16/2025 12:25:36 AMTried to access http ip directly.
69791143.110.243.86Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);10/15/2025 11:29:51 PMEvil 404 .env (AWS vulnerability)
69790147.185.133.250Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity10/15/2025 11:14:42 PMTried to access http ip directly.
69789218.147.23.15810/15/2025 09:44:08 PMTried to log in as root with no password.
69788104.248.122.29Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.3610/15/2025 04:45:19 PMTried to access http ip directly.
6978752.188.82.204Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.3610/15/2025 03:08:09 PMTried to access http ip directly.
69786183.57.179.136Mozilla/5.0(WindowsNT10.0;Win64;x64)AppleWebKit/537.36(KHTML,likeGecko)Chrome/86.0.4240.111Safari/537.3610/15/2025 01:20:59 PMTried to access http ip directly.
69785161.189.90.122Python-urllib/2.710/15/2025 11:48:59 AMTried to access http ip directly.
69784137.184.237.73Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);10/15/2025 11:46:14 AMEvil 404 .env (AWS vulnerability)
69783165.154.236.169Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.3610/15/2025 11:03:35 AMTried to access http ip directly.
69782152.42.167.31Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.3610/15/2025 10:29:06 AMEvil 404 /wp-includes/wlwmanifest.xml
6978134.59.175.189libredtail-http10/15/2025 08:59:39 AMTried to access http ip directly.
69780195.178.110.201Go-http-client/1.110/15/2025 07:20:11 AMTried to access http ip directly.
69779159.192.99.97Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.3610/15/2025 06:34:27 AMTried to access http ip directly.
69778185.78.119.211Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.3610/15/2025 06:22:08 AMTried to access http ip directly.
69777135.237.127.87Mozilla/5.0 zgrab/0.x10/15/2025 05:31:11 AMTried to access http ip directly.
6977618.205.246.105Python-urllib/2.710/15/2025 01:57:20 AMUser Agent Python-urllib/2.7
6977545.148.10.159Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.010/15/2025 01:31:49 AMEvil 404 .env (AWS vulnerability)
69774137.184.109.156Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.3610/15/2025 12:06:23 AMTried to access http ip directly.
69773165.22.56.38Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);10/14/2025 11:47:21 PMEvil 404 .env (AWS vulnerability)
6977280.75.218.30Python-urllib/2.710/14/2025 11:33:40 PMUser Agent Python-urllib/2.7
69771162.216.150.69Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity10/14/2025 10:37:36 PMTried to access http ip directly.
6977050.17.32.22Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.3610/14/2025 09:29:15 PMTried to access http ip directly.
69769199.45.154.148Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)10/14/2025 09:22:56 PMTried to access http ip directly.
6976861.140.47.98Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Firefox/45.010/14/2025 08:19:54 PMEvil 404 /wp-login.php
69767185.247.137.253Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)10/14/2025 07:45:29 PMTried to access http ip directly.
69766185.253.45.26Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.3610/14/2025 07:00:20 PMEvil 404 .env (AWS vulnerability)
6976545.153.34.54Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.010/14/2025 05:38:18 PMTried to access http ip directly.
69764118.193.57.218curl/7.29.010/14/2025 04:36:34 PMTried to access http ip directly.
69763199.45.155.67Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)10/14/2025 01:05:46 PMTried to access http ip directly.
69762216.180.246.120'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)'10/14/2025 12:09:34 PMTried to access http ip directly.
69761143.198.150.119Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.3610/14/2025 11:50:02 AMEvil 404 /wp-includes/wlwmanifest.xml
69760139.59.90.151Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);10/14/2025 11:41:49 AMEvil 404 .env (AWS vulnerability)
69759151.238.31.67Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.3610/14/2025 10:50:00 AMTried to access http ip directly.
6975894.156.14.32Python-urllib/3.1310/14/2025 09:56:48 AMUser Agent Python-urllib/3.13
6975782.102.18.124python-requests/2.32.510/14/2025 09:56:12 AMUser Agent python-requests/2.32.5
6975643.130.141.193Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.110/14/2025 09:47:48 AMTried to access http ip directly.
6975593.123.109.163Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.3610/14/2025 09:16:14 AMTried to access http ip directly.
69754187.202.214.37Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.710/14/2025 08:14:25 AMTried to access http ip directly.
6975393.123.109.60Python/3.10 aiohttp/3.12.1510/14/2025 08:14:11 AMUser Agent Python/3.10 aiohttp/3.12.15
6975245.130.203.190Python-urllib/3.1010/14/2025 04:22:44 AMUser Agent Python-urllib/3.10
6975135.197.102.13Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.3610/14/2025 03:25:00 AMEvil 404 /wp-includes/wlwmanifest.xml
69750216.26.243.183Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.3610/14/2025 02:50:34 AMEvil 404 /wp-includes/ID3/license.txt
69749136.117.141.2Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.3610/14/2025 02:47:35 AMEvil 404 /wp-includes/wlwmanifest.xml
69748165.154.206.35Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.3610/13/2025 11:27:33 PMTried to access http ip directly.
69747104.248.12.66Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);10/13/2025 11:27:27 PMEvil 404 .env (AWS vulnerability)
6974634.201.39.46Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.3610/13/2025 09:23:50 PMTried to access http ip directly.
697453.107.166.183Mozilla/5.0 (Linux x86_64; X11) AppleWebKit/537.29 (KHTML, like Gecko) Chrome/25.0.1537.68 Safari/535.610/13/2025 08:53:15 PMEvil 404 .env (AWS vulnerability)
69744159.203.47.158Mozilla/5.0 (X11; Linux x86_64; rv:139.0) Gecko/20100101 Firefox/139.010/13/2025 08:52:58 PMTried to access http ip directly.
6974334.52.176.247python-requests/2.32.510/13/2025 08:43:26 PMTried to access http ip directly.
6974261.245.156.89Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.3610/13/2025 08:31:30 PMTried to access http ip directly.
69741162.216.150.182Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity10/13/2025 08:28:29 PMTried to access http ip directly.
69740134.209.97.30Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.3610/13/2025 08:00:19 PMEvil 404 /wp-includes/wlwmanifest.xml
69739212.11.64.31shodanscanprint(chr(49).chr(55).chr(73).chr(53).chr(51).chr(48).chr(86).chr(65).chr(117).chr(52))10/13/2025 07:48:27 PMTried to access http ip directly.
6973866.175.215.176Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.3610/13/2025 06:54:39 PMTried to access http ip directly.
69737142.93.51.97Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.3610/13/2025 06:54:23 PMTried to access http ip directly.
69736142.93.84.213Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.3610/13/2025 06:54:21 PMTried to access http ip directly.
69735104.248.179.222Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.3610/13/2025 06:54:21 PMTried to access http ip directly.
6973443.135.164.228Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.110/13/2025 06:17:05 PMTried to access http ip directly.
69733194.163.129.51xfa110/13/2025 05:59:32 PMEvil 404 /admin/config.php
69732194.195.215.27Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.3610/13/2025 02:28:26 PMTried to access http ip directly.
6973123.92.30.48Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.3610/13/2025 02:28:16 PMTried to access http ip directly.
6972945.56.126.58Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.3610/13/2025 02:28:14 PMTried to access http ip directly.
69730173.255.247.94Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.3610/13/2025 02:28:14 PMTried to access http ip directly.
69728151.240.205.199Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.3610/13/2025 01:47:05 PMEvil 404 /wp-includes/ID3/license.txt
69727149.40.62.27python-requests/2.32.510/13/2025 01:13:07 PMUser Agent python-requests/2.32.5
69726143.198.29.77Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);10/13/2025 11:36:21 AMEvil 404 .env (AWS vulnerability)
6972520.118.202.126Mozilla/5.0 zgrab/0.x10/13/2025 10:46:05 AMUser Agent Mozilla/5.0 zgrab/0.x
6972445.130.203.236Python-urllib/3.1010/13/2025 10:22:58 AMUser Agent Python-urllib/3.10
6972345.3.39.109Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.3610/13/2025 09:59:51 AMEvil 404 /wp-includes/ID3/license.txt
69722207.154.254.128Mozilla/5.0 (compatible; Odin; https://docs.getodin.com/)10/13/2025 09:59:33 AMTried to access http ip directly.
69720178.128.205.142Go-http-client/1.110/13/2025 09:59:33 AMEvil 404 /cgi-bin/authLogin.cgi
69721167.99.253.24Go-http-client/1.110/13/2025 09:59:33 AMEvil 404 /solr/admin/info/system
6971945.250.231.225Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.710/13/2025 09:08:18 AMTried to access http ip directly.
69718169.150.196.149python-requests/2.32.510/13/2025 07:56:29 AMUser Agent python-requests/2.32.5
69717169.150.196.149python-requests/2.32.510/13/2025 07:56:29 AMUser Agent python-requests/2.32.5
6971680.234.46.166Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.710/13/2025 06:23:47 AMTried to access http ip directly.
69715216.180.246.71'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)'10/13/2025 04:39:32 AMTried to access http ip directly.
6971465.111.9.183Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.3610/13/2025 01:49:49 AMEvil 404 /wp-includes/ID3/license.txt
69713144.172.106.240Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.3610/13/2025 01:20:54 AMTried to access http ip directly.
69712176.65.148.164Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.010/13/2025 12:31:19 AMEvil 404 /boaform/admin/formLogin
69711162.243.3.53Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);10/12/2025 11:31:35 PMEvil 404 .env (AWS vulnerability)
69710196.251.86.13ALittle Client10/12/2025 10:49:09 PMEvil 404 /admin/plugins/fileupload/index.php
69709114.55.179.101Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.84 Safari/537.3610/12/2025 10:10:27 PMTried to access http ip directly.
6970835.88.198.174Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.3610/12/2025 09:06:54 PMTried to access http ip directly.
6970747.236.42.190curl/7.64.110/12/2025 09:03:32 PMTried to access http ip directly.
6970634.48.202.234Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.3610/12/2025 08:13:06 PMEvil 404 /wp-includes/wlwmanifest.xml
6970534.48.50.53Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.3610/12/2025 07:59:58 PMEvil 404 /wp-includes/wlwmanifest.xml
69704162.216.150.82Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity10/12/2025 07:49:25 PMTried to access http ip directly.
69703194.26.192.110Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.3610/12/2025 06:34:27 PMEvil 404 .env (AWS vulnerability)
69702135.237.125.174Mozilla/5.0 zgrab/0.x10/12/2025 06:24:34 PMTried to access http ip directly.
69701109.105.209.5Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.3610/12/2025 05:48:09 PMTried to access http ip directly.
69700175.4.8.54Go-http-client/1.110/12/2025 02:49:19 PMEvil 404 /wp-login.php
6969966.132.153.112Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)10/12/2025 02:20:01 PMTried to access http ip directly.
69698196.251.70.47Mozilla/5.0 (Kubuntu; Linux i686; rv:128.0) Gecko/20100101 Firefox/128.010/12/2025 02:15:36 PMEvil 404 .env (AWS vulnerability)
69697161.35.191.193Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);10/12/2025 11:10:44 AMEvil 404 .env (AWS vulnerability)
69696200.53.24.207Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.3610/12/2025 10:06:59 AMTried to access http ip directly.
6969534.34.144.227python-requests/2.32.510/12/2025 09:19:29 AMTried to access http ip directly.
6969413.86.117.6Mozilla/5.0 zgrab/0.x10/12/2025 08:39:52 AMUser Agent Mozilla/5.0 zgrab/0.x
69693148.135.200.30Mozilla/5.010/12/2025 07:52:17 AMEvil 404 /wp-login.php
69692152.32.183.231curl/7.29.010/12/2025 07:37:52 AMTried to access http ip directly.
6969150.117.3.87Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Firefox/45.010/12/2025 05:15:01 AMEvil 404 /wp-login.php