Ban Hackers

Back in the day, hackers were unemployed or unemployable programmers or teenagers with nothing to do.
Now days, it's criminal organizations and Programmers (with a capital P) with masters degrees hired by foreign (and not so foreign) governments to hack into every server they can find. They even try to scan every possible IP address for web servers. When they find one, somebody later tries to hack it.
So, I set up a website for them to visit. It says Coming Soon.
Then, it records their IP Address and bans it from the server with iptables. It also adds their IP Address and User Agent string to the database.

Here are the IP addresses I've banned over the last week:
BannedID IP User Agent String Date Hacked Banned Reason
70331104.248.240.71Mozilla/5.0 (Macintosh; Intel Mac OS X 11) AppleWebKit/538.41 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.3611/6/2025 10:58:06 PMTried to access http ip directly.
70330197.211.126.14xfa111/6/2025 07:57:45 PMEvil 404 /admin/config.php
7032989.117.2.171Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.3611/6/2025 06:22:01 PMEvil 404 .env (AWS vulnerability)
7032835.203.210.7Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity11/6/2025 04:49:49 PMTried to access http ip directly.
7032746.101.158.193Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);11/6/2025 04:18:10 PMEvil 404 .env (AWS vulnerability)
7032645.185.122.26Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.3611/6/2025 02:47:13 PMTried to access http ip directly.
70325199.45.155.88Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)11/6/2025 02:01:37 PMTried to access http ip directly.
7032452.49.247.138Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)11/6/2025 12:37:29 PMTried to access http ip directly.
7032352.23.239.149Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.3611/6/2025 11:27:26 AMTried to access http ip directly.
70322134.209.157.35libredtail-http11/6/2025 11:06:09 AMTried to access http ip directly.
7032134.26.143.178Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.3611/6/2025 09:29:13 AMEvil 404 /wp-includes/js/jquery/jquery.js
7032034.38.45.85python-requests/2.32.511/6/2025 09:21:01 AMTried to access http ip directly.
70319109.105.210.92Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.3611/6/2025 09:04:25 AMTried to access http ip directly.
7031882.158.88.158libredtail-http11/6/2025 09:01:35 AMTried to access http ip directly.
70317157.173.193.56Go-http-client/1.111/6/2025 07:35:28 AMEvil 404 /wp-content/style.php
7031644.246.249.232Mozilla/5.011/6/2025 07:15:05 AMEvil 404 /wp-login.php
7031520.14.73.63Mozilla/5.0 zgrab/0.x11/6/2025 06:38:44 AMUser Agent Mozilla/5.0 zgrab/0.x
70314180.247.46.36Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.711/6/2025 06:06:43 AMTried to access http ip directly.
70313122.28.56.169Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.3611/6/2025 06:04:23 AMEvil 404 /phpmyadmin2017/index.php?lang=en
70312213.242.30.104Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.3611/6/2025 04:51:11 AMTried to access http ip directly.
7031134.77.191.38python-requests/2.32.511/6/2025 04:11:49 AMTried to access http ip directly.
7031091.196.152.5Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.011/6/2025 03:27:13 AMTried to access http ip directly.
70309216.180.246.13'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)'11/6/2025 02:57:21 AMTried to access http ip directly.
7030820.64.104.93Mozilla/5.0 zgrab/0.x11/5/2025 09:31:24 PMUser Agent Mozilla/5.0 zgrab/0.x
70307174.138.6.88Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.3611/5/2025 09:19:03 PMTried to access http ip directly.
70306162.216.150.163Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity11/5/2025 08:20:12 PMTried to access http ip directly.
7030594.236.225.167Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.3611/5/2025 07:15:25 PMEvil 404 /phpmyadmin3/index.php?lang=en
7030454.79.235.27python-httpx/0.24.111/5/2025 06:41:51 PMUser Agent python-httpx/0.24.1
70303167.172.219.3Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);11/5/2025 04:13:26 PMEvil 404 .env (AWS vulnerability)
7030236.88.244.2Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.711/5/2025 03:45:31 PMTried to access http ip directly.
7030123.185.120.115Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.3611/5/2025 02:52:35 PMEvil 404 .env (AWS vulnerability)
70300154.16.10.170libredtail-http11/5/2025 02:14:18 PMTried to access http ip directly.
7029934.201.34.132Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.3611/5/2025 11:24:57 AMTried to access http ip directly.
7029843.153.115.134Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.111/5/2025 10:34:56 AMTried to access http ip directly.
7029745.142.193.171Mozilla/5.011/5/2025 10:15:58 AMTried to access http ip directly.
7029635.190.190.67Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.3611/5/2025 09:32:43 AMEvil 404 /wp-includes/js/jquery/jquery.js
70295165.154.182.53Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/566.37 (KHTML, like Gecko) Chrome/58.0.303 Safari/537.3611/5/2025 09:11:38 AMTried to access http ip directly.
7029478.135.107.199xfa111/5/2025 09:11:24 AMEvil 404 /admin/config.php
70293118.193.59.142curl/7.29.011/5/2025 09:11:16 AMTried to access http ip directly.
7029220.15.163.73Mozilla/5.0 zgrab/0.x11/5/2025 08:35:55 AMTried to access http ip directly.
7029136.255.98.88python-requests/2.26.011/5/2025 07:09:27 AMUser Agent python-requests/2.26.0
70290216.180.246.164'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)'11/5/2025 04:54:35 AMTried to access http ip directly.
70289216.24.219.141Go-http-client/1.111/5/2025 03:59:11 AMEvil 404 /wp-content/style.php
7028835.203.211.72Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity11/5/2025 12:02:55 AMTried to access http ip directly.
7028745.185.68.245xfa111/4/2025 10:49:53 PMEvil 404 /admin/config.php
7028644.220.188.201Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/55.0.3041.92 Safari/537.3211/4/2025 10:30:32 PMTried to access http ip directly.
7028551.158.54.10xfa111/4/2025 09:36:04 PMEvil 404 /admin/config.php
70284157.230.30.169Go-http-client/1.111/4/2025 07:19:21 PMTried to access http ip directly.
70283139.59.134.212Mozilla/5.0 (compatible; Odin; https://docs.getodin.com/)11/4/2025 07:19:20 PMTried to access http ip directly.
70282164.90.214.41Go-http-client/1.111/4/2025 07:19:20 PMEvil 404 /cgi-bin/authLogin.cgi
70281164.92.160.210Go-http-client/1.111/4/2025 07:19:20 PMEvil 404 /solr/admin/info/system
70280157.245.136.7Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.3611/4/2025 07:06:00 PMTried to access http ip directly.
7027945.148.10.160Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.011/4/2025 04:50:09 PMEvil 404 .env (AWS vulnerability)
70278104.248.203.50Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.3611/4/2025 04:18:29 PMTried to access http ip directly.
70277139.59.89.220Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);11/4/2025 04:08:12 PMEvil 404 .env (AWS vulnerability)
7027620.168.113.228Mozilla/5.0 zgrab/0.x11/4/2025 02:52:53 PMUser Agent Mozilla/5.0 zgrab/0.x
70275135.233.112.109Mozilla/5.0 zgrab/0.x11/4/2025 02:06:35 PMUser Agent Mozilla/5.0 zgrab/0.x
7027454.165.201.203Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.3611/4/2025 01:27:29 PMTried to access http ip directly.
70273194.50.16.73libwww-perl/6.0511/4/2025 01:18:42 PMTried to access http ip directly.
7027234.86.248.188Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.3611/4/2025 09:19:44 AMEvil 404 /wp-includes/wlwmanifest.xml
70271147.185.132.85Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity11/4/2025 07:13:44 AMTried to access http ip directly.
7027020.106.56.86Mozilla/5.0 zgrab/0.x11/4/2025 07:13:33 AMUser Agent Mozilla/5.0 zgrab/0.x
7026935.187.114.229python-requests/2.32.511/4/2025 06:38:18 AMTried to access http ip directly.
70268103.253.146.153Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.3611/4/2025 05:18:47 AMEvil 404 /wp-includes/ID3/license.txt
7026754.197.178.250python-httpx/0.28.111/4/2025 05:02:40 AMUser Agent python-httpx/0.28.1
70266162.216.149.189Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity11/4/2025 04:54:01 AMTried to access http ip directly.
70265196.251.84.213Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.3611/4/2025 04:47:15 AMEvil 404 .env (AWS vulnerability)
70264176.65.148.246Hello World11/4/2025 04:22:27 AMTried to access http ip directly.
7026382.202.180.163ivre-masscan/1.3 https://github.com/robertdavidgraham/11/4/2025 03:22:42 AMTried to access http ip directly.
70262204.76.203.25Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.311/4/2025 03:18:21 AMEvil 404 .env (AWS vulnerability)
70261172.203.245.49Mozilla/5.0 zgrab/0.x11/4/2025 01:49:47 AMTried to access http ip directly.
70260216.180.246.40'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)'11/4/2025 01:34:42 AMTried to access http ip directly.
70259176.65.149.253Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.3611/3/2025 11:41:34 PMEvil 404 .env (AWS vulnerability)
702582.133.56.194Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.3611/3/2025 07:47:50 PMTried to access http ip directly.
70257188.93.95.126libredtail-http11/3/2025 07:32:05 PMTried to access http ip directly.
70256139.59.224.88Mozilla/5.0 (X11; Linux x86_64; rv:83.0) Gecko/20100101 Firefox/83.011/3/2025 07:00:07 PMEvil 404 .env (AWS vulnerability)
70255185.180.141.9Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.3611/3/2025 05:01:52 PMTried to access http ip directly.
702542.58.113.138Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.3611/3/2025 04:55:43 PMEvil 404 /wp-login.php
70253167.172.22.235Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);11/3/2025 04:04:40 PMEvil 404 .env (AWS vulnerability)
70252157.15.40.60Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.3611/3/2025 02:44:30 PMEvil 404 .env (AWS vulnerability)
70251196.251.70.130Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.3611/3/2025 01:28:03 PMEvil 404 /wp-includes/wlwmanifest.xml
7025054.160.230.90Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.3611/3/2025 12:54:25 PMTried to access http ip directly.
70249103.101.216.218libredtail-http11/3/2025 10:45:19 AMTried to access http ip directly.
70248128.203.201.208Mozilla/5.0 zgrab/0.x11/3/2025 07:46:02 AMUser Agent Mozilla/5.0 zgrab/0.x
70247212.227.3.26libredtail-http11/3/2025 06:44:52 AMTried to access http ip directly.
70246216.180.246.69'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)'11/3/2025 04:28:56 AMTried to access http ip directly.
70245144.31.64.70libredtail-http11/3/2025 03:40:00 AMTried to access http ip directly.
7024474.235.122.210Mozilla/5.0 zgrab/0.x11/3/2025 03:26:35 AMUser Agent Mozilla/5.0 zgrab/0.x
70243196.251.71.49Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.011/3/2025 01:32:41 AMEvil 404 .env (AWS vulnerability)
7024220.14.74.238Mozilla/5.0 zgrab/0.x11/3/2025 12:40:54 AMUser Agent Mozilla/5.0 zgrab/0.x
70241137.184.236.192Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.3611/3/2025 12:22:47 AMEvil 404 /wp-includes/wlwmanifest.xml
70240157.245.105.149libredtail-http11/2/2025 11:57:00 PMTried to access http ip directly.
7023964.23.145.249Mozilla/5.011/2/2025 11:01:42 PMEvil 404 /wp-login.php
7023889.19.190.11Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.3611/2/2025 10:35:25 PMTried to access http ip directly.
7023789.121.209.61Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.3611/2/2025 07:20:57 PMTried to access http ip directly.
70236193.228.134.161Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.3611/2/2025 06:48:21 PMTried to access http ip directly.
70235161.35.18.88Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);11/2/2025 06:15:00 PMEvil 404 .env (AWS vulnerability)
7023466.154.119.223libredtail-http11/2/2025 05:51:53 PMTried to access http ip directly.
7023345.135.194.32Mozilla/5.0 (bang2013@atomicmail.io)11/2/2025 05:49:26 PMTried to access http ip directly.
7023220.171.8.157Mozilla/5.0 zgrab/0.x11/2/2025 05:30:31 PMTried to access http ip directly.
70231185.16.139.122Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.3611/2/2025 04:37:51 PMTried to access http ip directly.
70229206.174.162.8Mozilla/5.0 (Linux; arm_64; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.7204.105 YaBrowser/25.8.5.105.00 SA/3 Mobile Safari/537.3611/2/2025 04:08:17 PMTried to access http ip directly.
7023079.142.77.75Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Mobile Safari/537.3611/2/2025 04:08:17 PMTried to access http ip directly.
70228205.169.39.57Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.3611/2/2025 03:16:31 PMTried to access http ip directly.
7022734.118.12.4Mozilla/5.0 (iPhone13,2; U; CPU iPhone OS 14_0 like Mac OS X) AppleWebKit/602.1.50 (KHTML, like Gecko) Version/10.0 Mobile/15E148 Safari/602.111/2/2025 03:13:55 PMTried to access http ip directly.
70226167.71.175.236Go-http-client/1.111/2/2025 03:12:02 PMEvil 404 .env (AWS vulnerability)
70225146.190.63.248Go-http-client/1.111/2/2025 03:12:00 PMEvil 404 .env (AWS vulnerability)
7022496.41.38.202Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:139.0) Gecko/20100101 Firefox/139.011/2/2025 03:11:53 PMEvil 404 .env (AWS vulnerability)
70223176.65.148.212Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.311/2/2025 03:07:35 PMEvil 404 .env (AWS vulnerability)
70222216.24.219.90Go-http-client/1.111/2/2025 02:56:53 PMEvil 404 /wp-content/style.php
70221218.104.149.58Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.3611/2/2025 02:44:54 PMTried to access http ip directly.
70220159.223.142.50Mozilla/5.0 zgrab/0.x11/2/2025 02:42:55 PMTried to access http ip directly.
7021945.153.34.156Mozilla/5.0 (bang2013@atomicmail.io)11/2/2025 01:54:45 PMEvil 404 /cgi-bin/luci/;stok=/locale?form=country&operation
7021818.209.9.204Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.3611/2/2025 12:49:04 PMTried to access http ip directly.
70217164.68.123.140libredtail-http11/2/2025 08:20:49 AMTried to access http ip directly.
70216202.46.113.51Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.711/2/2025 07:15:22 AMTried to access http ip directly.
7021565.49.1.202Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/120.0.6099.28 Safari/537.3611/2/2025 06:12:06 AMTried to access http ip directly.
70214162.216.150.171Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity11/2/2025 04:50:31 AMTried to access http ip directly.
7021394.74.191.120Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.3611/2/2025 04:24:58 AMEvil 404 .env (AWS vulnerability)
70212185.213.154.182Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.3611/2/2025 02:40:10 AMEvil 404 .env (AWS vulnerability)
70211217.154.8.176libredtail-http11/2/2025 02:10:17 AMTried to access http ip directly.
7021013.89.125.229Mozilla/5.0 zgrab/0.x11/2/2025 02:03:17 AMUser Agent Mozilla/5.0 zgrab/0.x
7020935.241.212.143python-requests/2.32.511/2/2025 01:24:09 AMTried to access http ip directly.
7020898.142.247.134Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.3011/2/2025 01:01:07 AMEvil 404 .env (AWS vulnerability)
70207217.154.8.112libredtail-http11/2/2025 12:49:35 AMTried to access http ip directly.
7020691.224.92.120Mozilla/5.0 (X11; Linux x86_64) Gecko/20100101 Firefox/122.011/1/2025 11:41:54 PMEvil 404 /wp-login.php
70205107.170.45.102Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.3611/1/2025 10:55:14 PMTried to access http ip directly.
70204209.38.34.183Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.3611/1/2025 09:05:30 PMTried to access http ip directly.
70203167.172.73.213Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.3611/1/2025 08:55:40 PMEvil 404 /wp-includes/ID3/license.txt
7020245.142.154.25Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.3611/1/2025 07:13:31 PMTried to access http ip directly.
7020168.183.82.182Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);11/1/2025 07:06:16 PMEvil 404 .env (AWS vulnerability)
70200143.244.187.201ivre-masscan/1.3 https://github.com/robertdavidgraham/11/1/2025 05:41:27 PMTried to access http ip directly.
7019944.212.1.106Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.3611/1/2025 01:45:15 PMTried to access http ip directly.
70198194.187.176.157Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.011/1/2025 01:29:17 PMTried to access http ip directly.
70197135.237.127.112Mozilla/5.0 zgrab/0.x11/1/2025 01:24:32 PMUser Agent Mozilla/5.0 zgrab/0.x
70196159.223.0.20Mozilla/5.0 zgrab/0.x11/1/2025 01:20:13 PMTried to access http ip directly.
70195216.180.246.60'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)'11/1/2025 12:14:12 PMTried to access http ip directly.
70194158.220.115.215libredtail-http11/1/2025 09:14:14 AMTried to access http ip directly.
7019391.224.92.180Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.3611/1/2025 07:09:53 AMEvil 404 /wp-login.php
70192173.254.215.92libredtail-http11/1/2025 05:59:03 AMTried to access http ip directly.
70191185.180.140.135Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.3611/1/2025 03:17:53 AMTried to access http ip directly.
7019045.156.128.126Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.3611/1/2025 02:37:31 AMTried to access http ip directly.
70189165.227.142.251libredtail-http11/1/2025 01:44:35 AMTried to access http ip directly.
7018890.187.158.237Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.3611/1/2025 01:28:50 AMEvil 404 /db/phpmyadmin/index.php?lang=en
7018735.203.210.22Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity11/1/2025 12:59:47 AMTried to access http ip directly.
70186165.154.233.77libredtail-http11/1/2025 12:49:09 AMTried to access http ip directly.
7018582.165.93.136ivre-masscan/1.3 https://github.com/robertdavidgraham/10/31/2025 11:23:47 PMTried to access http ip directly.
701843.26.51.36python-httpx/0.24.110/31/2025 07:13:25 PMUser Agent python-httpx/0.24.1
70183107.170.44.115Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);10/31/2025 07:06:56 PMEvil 404 .env (AWS vulnerability)
70182148.113.221.28Mozilla/5.0 (compatible; ModatScanner/1.1; +https://modat.io/)10/31/2025 04:05:10 PMTried to access http ip directly.
7018123.234.78.118Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.3610/31/2025 03:26:18 PMTried to access http ip directly.
7018054.196.205.163Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.3610/31/2025 01:47:58 PMTried to access http ip directly.
70179208.84.101.119Mozilla/5.0 (Windows NT 10.0; Win64; x64)10/31/2025 10:38:47 AMEvil 404 /wp-admin/setup-config.php
70178136.144.19.12Go-http-client/1.110/31/2025 10:26:10 AMEvil 404 /wp-content/style.php
70177208.84.101.102Mozilla/5.0 (Windows NT 10.0; Win64; x64)10/31/2025 08:46:59 AMEvil 404 /wp-admin/setup-config.php
7017652.146.21.82Mozilla/5.0 zgrab/0.x10/31/2025 08:23:57 AMUser Agent Mozilla/5.0 zgrab/0.x
7017591.232.238.112ivre-masscan/1.3 https://github.com/robertdavidgraham/10/31/2025 07:24:14 AMTried to access http ip directly.
7017494.141.161.246libredtail-http10/31/2025 07:14:51 AMTried to access http ip directly.
7017345.126.209.102ivre-masscan/1.3 https://github.com/robertdavidgraham/10/31/2025 06:21:01 AMTried to access http ip directly.
70172172.237.118.18Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.010/31/2025 03:55:39 AMTried to access http ip directly.
7017145.119.85.39Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.3610/31/2025 03:48:04 AMEvil 404 /wp-login.php
70170192.241.154.87Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.010/31/2025 03:07:05 AMTried to access http ip directly.
701692.58.56.112Mozilla/5.0 (Windows NT 10.0; Win64; x64)10/31/2025 02:50:01 AMEvil 404 /wp-admin/setup-config.php
70168138.197.164.219Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.3610/31/2025 01:04:04 AMTried to access http ip directly.
7016745.82.78.103Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:142.0) Gecko/20100101 Firefox/142.010/31/2025 12:27:57 AMTried to access http ip directly.
7016680.94.95.226Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.3319.102 Safari/537.3610/31/2025 12:18:24 AMEvil 404 /cgi-bin/luci/;stok=/locale?form=country
70165194.61.40.76Go-http-client/1.110/30/2025 11:08:54 PMEvil 404 /wp-includes/css/buttons.css