Ban Hackers

Back in the day, hackers were unemployed or unemployable programmers or teenagers with nothing to do.
Now days, it's criminal organizations and Programmers (with a capital P) with masters degrees hired by foreign (and not so foreign) governments to hack into every server they can find. They even try to scan every possible IP address for web servers. When they find one, somebody later tries to hack it.
So, I set up a website for them to visit. It says Coming Soon.
Then, it records their IP Address and bans it from the server with iptables. It also adds their IP Address and User Agent string to the database.

Here are the IP addresses I've banned over the last week:
BannedID IP User Agent String Date Hacked Banned Reason
7136544.212.53.44Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.3612/18/2025 01:47:24 PMTried to access http ip directly.
7136420.214.243.12Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.112/18/2025 12:54:48 PMEvil 404 /wp-content/admin-header.php
71363170.64.207.120Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.3612/18/2025 12:30:49 PMEvil 404 .env (AWS vulnerability)
71362104.215.29.182Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.3612/18/2025 11:08:58 AMEvil 404 /wp-admin/css/colors/blue
7136191.230.168.213Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.012/18/2025 10:52:20 AMTried to access http ip directly.
7136091.230.168.91Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.012/18/2025 10:22:41 AMTried to access http ip directly.
71359128.203.200.175Mozilla/5.0 zgrab/0.x12/18/2025 08:31:01 AMUser Agent Mozilla/5.0 zgrab/0.x
7135837.46.115.27Mozilla/5.0 (X11; Linux x86_64; WanscannerBot/1.2; +https://abuse.pend.re) Gecko/20100101 Firefox/10.012/18/2025 06:30:15 AMTried to access http ip directly.
7135740.124.116.246Mozilla/5.0 zgrab/0.x12/18/2025 06:28:14 AMUser Agent Mozilla/5.0 zgrab/0.x
7135672.146.234.81Mozilla/5.0 (X11; Linux x86_64; rv:101.0) Gecko/20100101 Firefox/101.012/18/2025 05:48:18 AMEvil 404 /cgi-bin/luci/;stok=/locale?form=country
7135534.75.255.111Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.3612/18/2025 05:19:12 AMEvil 404 /wp-includes/wlwmanifest.xml
7135413.89.124.214Mozilla/5.0 zgrab/0.x12/18/2025 03:00:39 AMUser Agent Mozilla/5.0 zgrab/0.x
71353109.105.210.97Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.3612/18/2025 02:24:39 AMTried to access http ip directly.
71352172.174.244.189Mozilla/5.0 zgrab/0.x12/17/2025 10:37:21 PMTried to access http ip directly.
71351216.180.246.28'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)'12/17/2025 07:24:03 PMTried to access http ip directly.
7135035.234.83.229Mozilla/5.0 (X11; Linux x86_64)12/17/2025 07:23:19 PMEvil 404 .env (AWS vulnerability)
7134935.234.83.229Mozilla/5.0 (X11; Linux x86_64)12/17/2025 07:23:19 PMEvil 404 .env (AWS vulnerability)
7134835.234.83.229Mozilla/5.0 (X11; Linux x86_64)12/17/2025 07:23:19 PMEvil 404 .env (AWS vulnerability)
7134752.163.124.79Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.112/17/2025 06:51:31 PMEvil 404 /cgi-bin/file.php
71346167.99.223.58Mozilla/5.0 (X11; Linux x86_64; rv:142.0) Gecko/20100101 Firefox/142.012/17/2025 06:20:31 PMTried to access http ip directly.
71345101.36.108.9Mozilla/5.0 (Windows NT 9_2_1; Win64; x64) AppleWebKit/602.43 (KHTML, like Gecko) Chrome/86.0.634 Safari/537.3612/17/2025 04:50:50 PMTried to access http ip directly.
71344152.32.188.207curl/7.29.012/17/2025 04:49:49 PMTried to access http ip directly.
713434.213.179.32Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.3612/17/2025 03:13:06 PMEvil 404 /cgi-bin/file.php
7134245.8.19.150python-requests/2.26.012/17/2025 03:10:48 PMUser Agent python-requests/2.26.0
7134136.250.221.177Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.3612/17/2025 01:20:58 PMTried to access http ip directly.
71340116.197.130.59Mozilla/5.0 (X11; Linux x86_64)12/17/2025 11:59:22 AMEvil 404 .env (AWS vulnerability)
7133934.205.74.42Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.3612/17/2025 11:11:10 AMTried to access http ip directly.
71338107.170.63.43Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);12/17/2025 10:47:17 AMEvil 404 .env (AWS vulnerability)
7133791.224.92.184Mozilla/5.0 (X11; Linux x86_64) Gecko/20100101 Firefox/117.012/17/2025 09:39:24 AMEvil 404 /wp-login.php
71336172.236.228.198Mozilla/5.0 (Macintosh; Intel Mac OS X 13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.3612/17/2025 06:45:02 AMTried to access http ip directly.
7133564.62.156.132Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.3612/17/2025 06:23:42 AMTried to access http ip directly.
7133423.94.26.208libredtail-http12/17/2025 05:47:01 AMTried to access http ip directly.
71333178.128.87.57nvdorz12/17/2025 05:19:24 AMEvil 404 /admin/config.php
7133240.119.41.94Mozilla/5.0 zgrab/0.x12/17/2025 04:35:13 AMUser Agent Mozilla/5.0 zgrab/0.x
71331177.84.40.51Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.3612/17/2025 03:54:27 AMTried to access http ip directly.
71330211.145.47.70python-requests/2.22.012/16/2025 09:30:47 PMTried to access http ip directly.
71329213.209.143.116python-requests/2.22.012/16/2025 07:31:49 PMUser Agent python-requests/2.22.0
71328199.45.155.91Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)12/16/2025 07:05:51 PMTried to access http ip directly.
71327147.185.132.38Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity12/16/2025 06:33:08 PMTried to access http ip directly.
71326193.24.123.42Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.6 Safari/605.1.1512/16/2025 05:30:45 PMTried to access http ip directly.
71325134.122.23.171Mozilla/5.012/16/2025 05:28:25 PMEvil 404 /wp-login.php
71324194.180.49.168python-httpx/0.28.112/16/2025 03:45:12 PMUser Agent python-httpx/0.28.1
71323157.230.178.245Mozilla/5.0 zgrab/0.x12/16/2025 03:04:27 PMTried to access http ip directly.
7132254.210.130.186Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.3612/16/2025 11:25:20 AMTried to access http ip directly.
71321129.212.234.114Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.3612/16/2025 10:13:57 AMEvil 404 /wp-includes/ID3/license.txt
7132085.217.149.20Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)12/16/2025 09:45:58 AMTried to access http ip directly.
7131993.123.109.28Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.3612/16/2025 09:12:52 AMTried to access http ip directly.
7131834.145.198.77Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.3612/16/2025 04:44:44 AMEvil 404 /wp-includes/wlwmanifest.xml
7131793.183.226.62Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.3612/16/2025 04:15:50 AMTried to access http ip directly.
71316167.71.151.192Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);12/16/2025 03:41:51 AMEvil 404 .env (AWS vulnerability)
7131520.65.193.234Mozilla/5.0 zgrab/0.x12/16/2025 03:12:49 AMTried to access http ip directly.
71314209.38.88.92Mozilla/5.012/16/2025 02:42:25 AMTried to access http ip directly.
71313191.96.150.131Mozilla/5.0 (X11; Linux x86_64; WanscannerBot/1.2; +https://abuse.pend.re) Gecko/20100101 Firefox/10.012/16/2025 02:23:16 AMTried to access http ip directly.
71312209.38.28.227Mozilla/5.012/16/2025 01:23:02 AMTried to access http ip directly.
7131174.50.65.135xfa1,nvdorz,nvd0rz12/15/2025 11:12:24 PMEvil 404 /admin/config.php
7131064.226.73.132Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.3612/15/2025 11:00:53 PMTried to access http ip directly.
7130989.42.231.244Mozilla/5.0 (Windows NT 10.0; Win64; x64) Assetnote/1.0.012/15/2025 10:34:15 PMTried to access http ip directly.
71308109.171.30.19Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.3612/15/2025 08:21:33 PMTried to access http ip directly.
71307207.180.196.218xfa1,nvdorz,nvd0rz12/15/2025 07:58:14 PMEvil 404 /admin/config.php
7130695.214.55.71python-requests/2.31.012/15/2025 07:42:18 PMTried to access http ip directly.
7130540.124.175.58Mozilla/5.0 zgrab/0.x12/15/2025 07:10:50 PMUser Agent Mozilla/5.0 zgrab/0.x
71304165.22.198.197Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.3612/15/2025 06:49:43 PMTried to access http ip directly.
71303169.150.203.197Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.3612/15/2025 06:19:10 PMEvil 404 /wp-includes/wlwmanifest.xml
7130287.121.84.177Go-http-client/1.112/15/2025 05:24:07 PMTried to access http ip directly.
7130174.63.235.247Mozilla/5.012/15/2025 04:45:56 PMEvil 404 /wp-login.php
71300109.105.210.104Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.3612/15/2025 03:54:35 PMTried to access http ip directly.
71299170.64.183.109Mozilla/5.012/15/2025 02:29:35 PMTried to access http ip directly.
71298212.41.8.97Shodan-Pull/1.012/15/2025 02:28:06 PMTried to access http ip directly.
712974.197.92.55Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.5 Mobile/15E148 Safari/604.112/15/2025 02:20:37 PMEvil 404 /cgi-bin/file.php
7129646.151.178.49Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.3612/15/2025 12:31:02 PMTried to access http ip directly.
7129520.40.209.173Mozilla/5.0 zgrab/0.x12/15/2025 11:41:35 AMUser Agent Mozilla/5.0 zgrab/0.x
7129420.214.242.147Mozilla/5.0 (Linux; Android 11; CPH2251) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.3612/15/2025 11:28:23 AMEvil 404 /cgi-bin/file.php
712933.82.130.45Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.3612/15/2025 11:27:20 AMTried to access http ip directly.
7129245.156.131.25Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.3612/15/2025 10:46:41 AMTried to access http ip directly.
71291170.64.226.123Mozilla/5.012/15/2025 10:30:18 AMTried to access http ip directly.
71290195.24.237.174Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.3612/15/2025 10:11:00 AMEvil 404 .env (AWS vulnerability)
7128938.248.90.23Mozilla/5.012/15/2025 07:50:49 AMEvil 404 /wp-login.php
7128845.33.80.243Mozilla/5.0 (Macintosh; Intel Mac OS X 13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.3612/15/2025 07:09:51 AMTried to access http ip directly.
71287135.237.125.195Mozilla/5.0 zgrab/0.x12/15/2025 06:38:33 AMUser Agent Mozilla/5.0 zgrab/0.x
71286144.31.4.188Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.3612/15/2025 06:21:51 AMEvil 404 /wp-admin/install.php
7128540.67.161.175Mozilla/5.0 zgrab/0.x12/15/2025 05:46:36 AMTried to access http ip directly.
71284157.245.209.233xfa1,nvdorz,nvd0rz12/15/2025 05:46:24 AMEvil 404 /admin/config.php
71283109.123.111.89libredtail-http12/15/2025 02:49:05 AMTried to access http ip directly.
7128251.81.52.135libredtail-http12/14/2025 11:11:15 PMTried to access http ip directly.
7128191.206.169.59Go-http-client/1.112/14/2025 08:34:51 PMEvil 404 /wp-content/txets.php
7128062.60.135.189Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.312/14/2025 07:38:30 PMTried to access http ip directly.
712794.230.0.145Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.112/14/2025 07:30:13 PMEvil 404 /wp-content/admin-header.php
71278206.81.13.89Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);12/14/2025 07:27:38 PMEvil 404 .env (AWS vulnerability)
7127774.7.227.178Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)12/14/2025 06:18:37 PMTried to access http ip directly.
71276182.10.225.208Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.3612/14/2025 05:56:45 PMTried to access http ip directly.
7127564.225.14.40Mozilla/5.012/14/2025 05:26:44 PMEvil 404 /wp-login.php
71274120.48.109.87libredtail-http12/14/2025 04:31:58 PMTried to access http ip directly.
7127320.89.217.198Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.112/14/2025 04:26:02 PMEvil 404 /wp-admin/css/colors/blue
7127293.186.215.227Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.3612/14/2025 02:45:42 PMTried to access http ip directly.
71271102.22.20.125xfa1,nvdorz,nvd0rz12/14/2025 02:41:52 PMEvil 404 /admin/config.php
71270183.82.115.127Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.012/14/2025 12:49:33 PMTried to access http ip directly.
71269212.73.148.21Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)12/14/2025 12:39:55 PMTried to access http ip directly.
7126820.78.177.7Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.3612/14/2025 12:16:13 PMEvil 404 /wp-content/admin-header.php
71267169.197.85.172python-requests/2.32.312/14/2025 11:49:58 AMTried to access http ip directly.
71266170.64.178.22Mozilla/5.012/14/2025 11:47:20 AMTried to access http ip directly.
7126520.65.169.214Mozilla/5.0 zgrab/0.x12/14/2025 11:42:02 AMUser Agent Mozilla/5.0 zgrab/0.x
71264204.76.203.27hi from sparixx and silverpath12/14/2025 11:26:01 AMEvil 404 /cgi-bin/luci/;stok=/locale?form=country
7126334.207.182.99Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.3612/14/2025 11:24:49 AMTried to access http ip directly.
7126284.21.171.145Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.5615.137 Safari/537.3612/14/2025 11:22:12 AMEvil 404 .env (AWS vulnerability)
712614.194.76.130Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.3612/14/2025 11:10:21 AMEvil 404 /wp-admin/css/colors/blue
71260194.180.49.171python-httpx/0.28.112/14/2025 10:57:31 AMUser Agent python-httpx/0.28.1
71259144.172.114.121Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:109.0) Gecko/20100101 Firefox/115.012/14/2025 10:47:59 AMTried to access http ip directly.
71258103.224.243.145libredtail-http12/14/2025 10:34:39 AMTried to access http ip directly.
7125735.162.5.34python-httpx/0.28.112/14/2025 09:54:22 AMUser Agent python-httpx/0.28.1
71256135.119.89.68Mozilla/5.0 zgrab/0.x12/14/2025 09:29:19 AMTried to access http ip directly.
71255209.38.31.222Mozilla/5.012/14/2025 08:11:12 AMTried to access http ip directly.
71254104.199.46.221python-requests/2.32.512/14/2025 06:51:49 AMTried to access http ip directly.
71253142.111.146.31Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.3612/14/2025 05:23:37 AMEvil 404 .env (AWS vulnerability)
7125235.203.210.208Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity12/14/2025 05:18:46 AMTried to access http ip directly.
71251208.84.102.151Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.3612/14/2025 05:15:47 AMEvil 404 /wp-includes/wlwmanifest.xml
7125085.215.117.38Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.3612/14/2025 04:32:59 AMEvil 404 /wp-login.php
71249187.110.175.195xfa1,nvdorz,nvd0rz12/14/2025 03:19:37 AMEvil 404 /admin/config.php
7124820.64.105.19Mozilla/5.0 zgrab/0.x12/14/2025 01:55:11 AMUser Agent Mozilla/5.0 zgrab/0.x
71247104.28.240.86Mozilla/5.012/14/2025 12:41:31 AMEvil 404 /wp-login.php
7124620.196.91.230Mozilla/5.0 (iPhone; CPU iPhone OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.112/14/2025 12:34:34 AMEvil 404 /wp-content/admin-header.php
7124545.59.163.167xfa1,nvdorz,nvd0rz12/14/2025 12:26:19 AMEvil 404 /admin/config.php
71244157.245.117.239Mozilla/5.012/13/2025 10:45:35 PMEvil 404 /wp-login.php
7124334.170.25.29Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.3612/13/2025 09:42:51 PMEvil 404 /wp-includes/wlwmanifest.xml
71242138.68.183.19Mozilla/5.012/13/2025 09:39:52 PMEvil 404 /wp-login.php
712414.241.241.191Mozilla/5.0 (Linux; Android 11; 21081111RG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.3612/13/2025 08:54:19 PMEvil 404 /wp-content/admin-header.php
71240167.172.80.128Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.3612/13/2025 08:44:45 PMTried to access http ip directly.
71239137.184.7.209Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.3612/13/2025 07:56:20 PMTried to access http ip directly.
71238144.31.4.112Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.3612/13/2025 07:36:12 PMEvil 404 /wp-admin/install.php
71237216.180.246.148'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)'12/13/2025 07:08:24 PMTried to access http ip directly.
71236208.84.101.251Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.3612/13/2025 06:44:30 PMEvil 404 /wp-includes/wlwmanifest.xml
712354.197.248.250Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.112/13/2025 05:58:59 PMEvil 404 /wp-admin/css/colors/blue
712345.187.35.156Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.4612/13/2025 05:36:34 PMTried to access http ip directly.
7123313.71.30.28Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.3612/13/2025 05:13:41 PMEvil 404 /wp-admin/css/colors/blue
71232165.154.41.152curl/7.29.012/13/2025 05:12:40 PMTried to access http ip directly.
7123152.230.92.201Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.112/13/2025 03:39:09 PMEvil 404 /wp-admin/css/colors/blue
7123020.64.104.78Mozilla/5.0 zgrab/0.x12/13/2025 03:03:05 PMTried to access http ip directly.
7122920.37.217.241Mozilla/5.0 (iPad; CPU OS 16_7_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.112/13/2025 02:58:09 PMEvil 404 /wp-content/admin-header.php
7122820.188.106.95Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.3612/13/2025 01:35:13 PMEvil 404 /wp-content/admin-header.php
7122752.180.136.250Mozilla/5.0 zgrab/0.x12/13/2025 01:34:39 PMUser Agent Mozilla/5.0 zgrab/0.x
71226194.163.172.10Mozilla/5.012/13/2025 10:48:24 AMTried to access http ip directly.
71225143.198.43.101Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);12/13/2025 09:56:27 AMEvil 404 .env (AWS vulnerability)
7122487.110.104.6Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.3612/13/2025 07:55:27 AMTried to access http ip directly.
71223130.180.33.226ntopng 5.6.240304/amd64/FreeBSD 14.012/13/2025 07:27:04 AMTried to access http ip directly.
71222192.3.138.26Mozilla/5.0 (compatible; LumeWebScan/2.0; +https://lumeweaver.com/)12/13/2025 06:19:47 AMTried to access http ip directly.
7122118.246.62.107Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.3612/13/2025 05:34:55 AMTried to access http ip directly.
71220216.180.246.54'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)'12/13/2025 05:23:04 AMTried to access http ip directly.
7121994.251.19.230Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.3612/13/2025 04:49:52 AMTried to access http ip directly.
71218152.42.183.90Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.3612/13/2025 04:00:36 AMEvil 404 /wp-includes/ID3/license.txt
71217173.212.203.116libredtail-http12/13/2025 02:25:51 AMTried to access http ip directly.
7121652.186.182.60Mozilla/5.0 zgrab/0.x12/13/2025 01:25:11 AMUser Agent Mozilla/5.0 zgrab/0.x
7121580.72.18.211Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.3612/12/2025 11:02:46 PMTried to access http ip directly.
7121489.117.148.254libredtail-http12/12/2025 10:49:21 PMTried to access http ip directly.
71213167.71.90.72Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.3612/12/2025 08:51:20 PMTried to access http ip directly.
71212152.42.163.164Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.3612/12/2025 08:20:28 PMTried to access http ip directly.
7121134.141.136.63python-requests/2.32.312/12/2025 07:18:50 PMUser Agent python-requests/2.32.3
7121046.101.111.185Mozilla/5.0 (l9scan/2.0.63e2232323e2238313e22373; +https://leakix.net)12/12/2025 07:18:37 PMEvil 404 .env (AWS vulnerability)
71209143.110.217.244Mozilla/5.0 (l9scan/2.0.63e2232323e2238313e22373; +https://leakix.net)12/12/2025 07:18:36 PMEvil 404 .env (AWS vulnerability)
71208206.189.95.232Mozilla/5.0 (l9scan/2.0.63e2232323e2238313e22373; +https://leakix.net)12/12/2025 07:16:04 PMEvil 404 .env (AWS vulnerability)
71207164.90.208.56Mozilla/5.0 (l9scan/2.0.63e2232323e2238313e22373; +https://leakix.net)12/12/2025 07:15:58 PMEvil 404 .env (AWS vulnerability)
71206164.92.244.132Mozilla/5.0 (l9scan/2.0.63e2232323e2238313e22373; +https://leakix.net)12/12/2025 07:15:57 PMEvil 404 .env (AWS vulnerability)
7120535.203.210.189Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity12/12/2025 05:47:56 PMTried to access http ip directly.
7120485.217.149.27Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)12/12/2025 05:25:21 PMTried to access http ip directly.
7120374.235.185.122Mozilla/5.0 zgrab/0.x12/12/2025 04:36:13 PMUser Agent Mozilla/5.0 zgrab/0.x
7120214.135.74.149Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.3612/12/2025 03:26:52 PMTried to access http ip directly.
71201212.73.148.12Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)12/12/2025 02:17:03 PMTried to access http ip directly.
71200172.192.48.198Mozilla/5.0 (Linux; Android 12; 2201116SG) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.3612/12/2025 02:10:26 PMEvil 404 /wp-content/admin-header.php
7119920.196.106.26Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.112/12/2025 01:40:21 PMEvil 404 /cgi-bin/file.php
71198144.31.4.124Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.3612/12/2025 01:36:16 PMEvil 404 /wp-admin/install.php
71197184.72.127.184Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.3612/12/2025 11:24:25 AMTried to access http ip directly.
71196216.180.246.83'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)'12/12/2025 10:09:49 AMTried to access http ip directly.
71195101.36.97.80Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Edg/120.0.0.012/12/2025 09:44:37 AMTried to access http ip directly.
71194141.98.11.172Go-http-client/1.112/12/2025 09:33:22 AMEvil 404 /cgi-bin/luci/;stok=/locale?form=country&operation
7119320.163.15.225Mozilla/5.0 zgrab/0.x12/12/2025 08:08:41 AMTried to access http ip directly.
71192185.188.61.239Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.1508.111 Safari/537.3612/12/2025 06:51:50 AMEvil 404 /static/admin/js/ueditor/ueditor.config.js/x.php
7119181.12.77.13Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.712/12/2025 04:39:40 AMTried to access http ip directly.
71190207.154.210.164Go-http-client/1.112/12/2025 03:34:04 AMTried to access http ip directly.
7118964.226.77.155Mozilla/5.0 (compatible; Odin; https://docs.getodin.com/)12/12/2025 03:34:04 AMTried to access http ip directly.
71188104.248.19.191Go-http-client/1.112/12/2025 03:34:04 AMEvil 404 /solr/admin/info/system
7118768.183.122.201Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.3612/12/2025 03:24:05 AMTried to access http ip directly.
7118623.98.90.121Mozilla/5.0 (iPad; CPU OS 17_0_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Mobile/15E148 Safari/604.112/12/2025 03:18:05 AMEvil 404 /cgi-bin/file.php
711854.189.149.100Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.1512/12/2025 03:14:57 AMEvil 404 /cgi-bin/file.php
7118468.218.61.6Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.3612/12/2025 03:02:58 AMEvil 404 /cgi-bin/file.php
71183172.237.114.104Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.012/12/2025 03:01:16 AMTried to access http ip directly.
71182134.209.86.24Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.012/12/2025 02:08:35 AMTried to access http ip directly.
7118198.80.4.44Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/58.0.3099.52 Safari/537.3212/12/2025 02:02:51 AMTried to access http ip directly.
71180180.143.228.3"Mozilla/5.012/12/2025 01:40:56 AMTried to access http ip directly.
7117920.89.208.225Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.3612/12/2025 01:37:07 AMEvil 404 /cgi-bin/file.php
71178164.92.138.29Go-http-client/1.112/12/2025 01:15:09 AMTried to access http ip directly.
71177209.38.247.79Go-http-client/1.112/12/2025 01:13:46 AMEvil 404 /cgi-bin/authLogin.cgi
71175164.92.225.162Mozilla/5.0 (compatible; Odin; https://docs.getodin.com/)12/12/2025 01:13:46 AMTried to access http ip directly.
71176161.35.216.245Go-http-client/1.112/12/2025 01:13:46 AMEvil 404 /solr/admin/info/system
71174159.65.183.154Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)12/12/2025 12:49:05 AMTried to access http ip directly.
7117320.189.203.24Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.112/11/2025 11:53:01 PMEvil 404 /cgi-bin/file.php
711724.218.15.157Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/119.0.6045.109 Mobile/15E148 Safari/604.112/11/2025 10:49:02 PMEvil 404 /cgi-bin/file.php
711714.241.233.183Mozilla/5.0 (iPhone; CPU iPhone OS 16_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/118.0 Mobile/15E148 Safari/605.1.1512/11/2025 10:31:10 PMEvil 404 /wp-content/admin-header.php
71170142.93.21.253Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);12/11/2025 09:11:34 PMEvil 404 .env (AWS vulnerability)
7116991.224.92.118Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.4612/11/2025 09:09:36 PMTried to access http ip directly.
71168150.40.178.176libredtail-http12/11/2025 08:39:19 PMTried to access http ip directly.
7116720.58.146.18Mozilla/5.0 (Linux; Android 10; LM-Q720) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.3612/11/2025 08:32:48 PMEvil 404 /wp-content/admin-header.php
711664.189.122.191Mozilla/5.0 (Linux; Android 12; V2134) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.3612/11/2025 06:09:17 PMEvil 404 /cgi-bin/file.php
71165204.76.203.8Linux Gnu (cow)12/11/2025 05:21:08 PMTried to access http ip directly.
7116435.203.210.246Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity12/11/2025 04:59:30 PMTried to access http ip directly.
7116389.42.231.242Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.4612/11/2025 04:57:17 PMTried to access http ip directly.
711624.197.195.62Mozilla/5.0 (Linux; Android 13; SM-G991U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Mobile Safari/537.3612/11/2025 04:01:34 PMEvil 404 /cgi-bin/file.php
71161119.42.144.140Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.012/11/2025 03:04:15 PMTried to access http ip directly.
71160160.30.179.245Mozilla/5.0 (X11; Linux x86_64)12/11/2025 02:49:27 PMEvil 404 .env (AWS vulnerability)
71159160.30.179.245Mozilla/5.0 (X11; Linux x86_64)12/11/2025 02:49:27 PMEvil 404 .env (AWS vulnerability)
71158160.30.179.245Mozilla/5.0 (X11; Linux x86_64)12/11/2025 02:49:27 PMEvil 404 .env (AWS vulnerability)