Ban Hackers

Back in the day, hackers were unemployed or unemployable programmers or teenagers with nothing to do.
Now days, it's criminal organizations and Programmers (with a capital P) with masters degrees hired by foreign (and not so foreign) governments to hack into every server they can find. They even try to scan every possible IP address for web servers. When they find one, somebody later tries to hack it.
So, I set up a website for them to visit. It says Coming Soon.
Then, it records their IP Address and bans it from the server with iptables. It also adds their IP Address and User Agent string to the database.

Here are the IP addresses I've banned over the last week:
BannedID IP User Agent String Date Hacked Banned Reason
7260162.201.244.25Mozilla/5.02/5/2026 12:19:16 AMTried to access http ip directly.
72600185.186.25.226python-requests/2.32.42/5/2026 12:08:17 AMUser Agent python-requests/2.32.4
72599176.65.148.201Linux Gnu (cow)2/4/2026 11:53:38 PMTried to access http ip directly.
7259818.189.91.7Go-http-client/1.12/4/2026 06:53:21 PMTried to access http ip directly.
7259723.234.109.47Mozilla/5.0 zgrab/0.x2/4/2026 03:01:40 PMTried to access http ip directly.
72596159.223.42.132Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.362/4/2026 02:50:55 PMEvil 404 /wp-includes/ID3/license.txt
7259591.196.152.191Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.02/4/2026 12:14:31 PMTried to access http ip directly.
7259420.210.129.57Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.362/4/2026 11:22:08 AMEvil 404 /wp-admin/css/colors/blue/index.php
7259354.227.131.131Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.362/4/2026 11:00:59 AMTried to access http ip directly.
72592160.30.137.9Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.362/4/2026 10:22:48 AMEvil 404 /wp-login.php
72591213.139.77.117Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML2/4/2026 09:36:20 AMTried to access http ip directly.
7259020.194.17.220Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.362/4/2026 08:57:48 AMEvil 404 /wp-admin/css/colors/blue/index.php
72589136.0.9.104Mozilla/5.0 (Linux; Android 5.0; SM-G900V Build/LRX21T) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.84 Mobile Safari/537.362/4/2026 08:13:51 AMEvil 404 .env (AWS vulnerability)
7258820.219.8.139Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.362/4/2026 07:40:11 AMEvil 404 /cgi-bin/
7258747.245.81.50Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0;2/4/2026 06:11:53 AMTried to access http ip directly.
7258635.233.94.99python-requests/2.32.52/4/2026 05:29:03 AMTried to access http ip directly.
72585120.48.123.57libredtail-http2/4/2026 05:11:51 AMTried to access http ip directly.
72584134.209.92.127Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);2/4/2026 04:32:24 AMEvil 404 .env (AWS vulnerability)
72583125.99.250.202Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Edg/120.0.0.02/4/2026 04:07:34 AMTried to access http ip directly.
72582147.185.132.204Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity2/4/2026 03:50:38 AMTried to access http ip directly.
7258120.255.75.91Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.362/4/2026 02:18:04 AMEvil 404 /cgi-bin/
7258020.196.192.167Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.362/4/2026 01:31:59 AMEvil 404 /wp-content/themes/admin.php
7257931.171.130.151Go-http-client/1.12/4/2026 01:16:39 AMTried to access http ip directly.
7257820.64.105.194Mozilla/5.0 zgrab/0.x2/4/2026 12:55:09 AMUser Agent Mozilla/5.0 zgrab/0.x
7257743.143.7.239Go-http-client/1.12/4/2026 12:48:51 AMTried to access http ip directly.
7257645.156.248.107Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.362/3/2026 10:48:47 PMEvil 404 .env (AWS vulnerability)
72575176.65.139.12Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.462/3/2026 10:01:19 PMTried to access http ip directly.
72574213.209.159.55Go-http-client/1.12/3/2026 06:00:49 PMEvil 404 .env (AWS vulnerability)
72573185.247.137.169Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)2/3/2026 04:58:09 PMTried to access http ip directly.
72572212.90.61.10Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.362/3/2026 04:43:56 PMTried to access http ip directly.
72571104.248.193.254Mozilla/5.0 (X11; Linux x86_64; rv:142.0) Gecko/20100101 Firefox/142.02/3/2026 11:25:24 AMTried to access http ip directly.
725703.90.6.14Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.362/3/2026 10:57:23 AMTried to access http ip directly.
7256920.163.2.151Mozilla/5.0 zgrab/0.x2/3/2026 10:45:20 AMUser Agent Mozilla/5.0 zgrab/0.x
7256867.205.180.128Mozilla/5.0 (X11; Linux x86_64; rv:142.0) Gecko/20100101 Firefox/142.02/3/2026 09:37:01 AMTried to access http ip directly.
72567152.32.192.230Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.362/3/2026 09:30:56 AMTried to access http ip directly.
72566159.203.123.9Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.362/3/2026 09:03:06 AMTried to access http ip directly.
72565172.174.236.56Mozilla/5.0 zgrab/0.x2/3/2026 07:50:04 AMUser Agent Mozilla/5.0 zgrab/0.x
7256445.135.193.11Go-http-client/1.12/3/2026 07:37:05 AMTried to access http ip directly.
7256320.98.128.111Mozilla/5.0 zgrab/0.x2/3/2026 05:07:37 AMTried to access http ip directly.
72562185.2.104.81Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.362/3/2026 03:45:25 AMTried to access http ip directly.
7256145.148.10.244Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.02/3/2026 12:42:39 AMEvil 404 .env (AWS vulnerability)
7256034.118.63.78Mozilla/5.0 (iPhone13,2; U; CPU iPhone OS 14_0 like Mac OS X) AppleWebKit/602.1.50 (KHTML, like Gecko) Version/10.0 Mobile/15E148 Safari/602.12/3/2026 12:06:38 AMTried to access http ip directly.
72559181.113.30.194Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.362/2/2026 09:53:43 PMTried to access http ip directly.
7255864.226.84.104Mozilla/5.0 (compatible; Odin; https://docs.getodin.com/)2/2/2026 07:49:17 PMTried to access http ip directly.
72557103.172.78.45masscan/1.3 (https://github.com/robertdavidgraham/masscan)2/2/2026 06:51:25 PMTried to access http ip directly.
7255689.185.81.112libredtail-http2/2/2026 06:40:06 PMTried to access http ip directly.
7255547.250.95.30curl/7.64.12/2/2026 06:33:30 PMTried to access http ip directly.
72554104.248.130.58Go-http-client/1.12/2/2026 05:38:34 PMTried to access http ip directly.
72553209.38.211.43Go-http-client/1.12/2/2026 05:38:34 PMEvil 404 /cgi-bin/authLogin.cgi
72552165.227.158.182Mozilla/5.0 (compatible; Odin; https://docs.getodin.com/)2/2/2026 05:38:33 PMTried to access http ip directly.
7255143.204.119.140Go-http-client/1.12/2/2026 05:33:29 PMTried to access http ip directly.
725503.145.168.139Go-http-client/1.12/2/2026 05:14:05 PMTried to access http ip directly.
72549139.59.210.36Go-http-client/1.12/2/2026 04:18:08 PMEvil 404 /solr/admin/info/system
72548164.92.174.223Go-http-client/1.12/2/2026 04:18:08 PMEvil 404 /cgi-bin/authLogin.cgi
72547159.223.38.93Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);2/2/2026 03:17:42 PMEvil 404 .env (AWS vulnerability)
72546176.65.139.7Go-http-client/1.12/2/2026 03:02:19 PMTried to access http ip directly.
7254543.224.137.203Go-http-client/1.12/2/2026 02:02:26 PMTried to access http ip directly.
72544129.204.4.253Go-http-client/1.12/2/2026 01:21:39 PMTried to access http ip directly.
7254320.75.89.92Mozilla/5.0 (Linux x86_64; X11) Gecko/20022702 Firefox/20.02/2/2026 12:23:03 PMTried to access http ip directly.
7254243.128.81.242libredtail-http2/2/2026 11:45:47 AMTried to access http ip directly.
72541103.155.161.119Go-http-client/1.12/2/2026 11:24:35 AMTried to access http ip directly.
7254054.152.220.72Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.362/2/2026 10:56:44 AMTried to access http ip directly.
7253940.115.138.186Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.362/2/2026 09:00:25 AMEvil 404 /cgi-bin/
7253820.118.240.192Mozilla/5.0 zgrab/0.x2/2/2026 08:00:47 AMTried to access http ip directly.
725372.58.56.147Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.362/2/2026 07:12:27 AMTried to access http ip directly.
7253635.238.109.167Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.362/2/2026 07:12:22 AMEvil 404 /wp-includes/wlwmanifest.xml
725353.110.191.144Go-http-client/1.12/2/2026 06:49:11 AMTried to access http ip directly.
7253434.134.185.102Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.362/2/2026 06:45:12 AMEvil 404 /wp-includes/wlwmanifest.xml
7253368.183.188.59Linux Gnu (cow)2/2/2026 06:43:49 AMTried to access http ip directly.
72532170.64.149.23Mozilla/5.02/2/2026 04:45:13 AMTried to access http ip directly.
72531147.185.133.118Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity2/2/2026 04:31:09 AMTried to access http ip directly.
7253094.138.144.38Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.362/2/2026 04:30:57 AMTried to access http ip directly.
72529106.53.123.143Go-http-client/1.12/2/2026 02:59:58 AMTried to access http ip directly.
72528185.102.115.142Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.362/1/2026 11:03:34 PMEvil 404 /wp-login.php
72527104.28.214.117Go-http-client/1.12/1/2026 09:44:38 PMEvil 404 /wp-content/style.php
72526195.40.154.8libredtail-http2/1/2026 07:54:59 PMTried to access http ip directly.
72525170.64.215.143Mozilla/5.02/1/2026 07:31:16 PMTried to access http ip directly.
72524140.245.124.110python-requests/2.32.52/1/2026 06:40:48 PMUser Agent python-requests/2.32.5
725235.63.19.3Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.362/1/2026 06:37:47 PMEvil 404 /wp-login.php
7252220.200.210.155Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.362/1/2026 06:16:51 PMEvil 404 /wp-content/upgrade/index.php
72521204.76.203.210Mozilla/5.0 zgrab/0.x2/1/2026 05:19:23 PMTried to access http ip directly.
72520104.211.72.80Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.362/1/2026 05:15:37 PMEvil 404 /wp-admin/css/colors/coffee/
72519164.92.88.230Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.362/1/2026 03:14:34 PMTried to access http ip directly.
72518109.205.211.39Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.152/1/2026 02:41:12 PMEvil 404 /wp-admin/
7251720.64.106.118Mozilla/5.0 zgrab/0.x2/1/2026 01:52:18 PMUser Agent Mozilla/5.0 zgrab/0.x
72516146.19.24.133python-requests/2.31.02/1/2026 12:19:56 PMTried to access http ip directly.
7251544.204.29.60Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.362/1/2026 10:59:43 AMTried to access http ip directly.
7251451.96.134.13Go-http-client/1.12/1/2026 10:25:35 AMTried to access http ip directly.
7251352.231.68.175Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.362/1/2026 10:10:53 AMEvil 404 /cgi-bin/
72512101.43.79.101Go-http-client/1.12/1/2026 08:54:10 AMTried to access http ip directly.
72511138.118.241.89Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.362/1/2026 06:23:56 AMTried to access http ip directly.
7251018.205.63.110Go-http-client/1.12/1/2026 06:08:58 AMTried to access http ip directly.
72509199.45.155.109Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)2/1/2026 05:41:05 AMTried to access http ip directly.
72508206.189.187.126Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);2/1/2026 03:53:47 AMEvil 404 .env (AWS vulnerability)
7250762.171.180.237libredtail-http2/1/2026 03:21:58 AMTried to access http ip directly.
72506185.193.89.25Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:147.0) Gecko/20100101 Firefox/147.02/1/2026 02:46:46 AMEvil 404 .env (AWS vulnerability)
7250520.29.23.198Mozilla/5.0 zgrab/0.x2/1/2026 02:40:31 AMUser Agent Mozilla/5.0 zgrab/0.x
72504185.213.174.141Mozilla/5.02/1/2026 01:11:10 AMTried to access http ip directly.
72503205.185.116.204Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.362/1/2026 12:45:12 AMEvil 404 /wp-login.php
7250243.225.157.162Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.362/1/2026 12:40:40 AMEvil 404 .env (AWS vulnerability)
72501129.159.56.14Mozilla/5.0 (X11; Linux x86_64; rv:83.0) Gecko/20100101 Firefox/83.01/31/2026 09:04:25 PMEvil 404 .env (AWS vulnerability)
7250091.230.168.165Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.01/31/2026 08:48:11 PMTried to access http ip directly.
72499135.237.126.194Mozilla/5.0 zgrab/0.x1/31/2026 08:36:54 PMUser Agent Mozilla/5.0 zgrab/0.x
72498135.237.127.14Mozilla/5.0 zgrab/0.x1/31/2026 07:21:30 PMUser Agent Mozilla/5.0 zgrab/0.x
72497115.159.124.100Go-http-client/1.11/31/2026 07:10:38 PMTried to access http ip directly.
724963.26.66.253Go-http-client/1.11/31/2026 06:59:23 PMTried to access http ip directly.
7249548.217.233.215Mozilla/5.0 zgrab/0.x1/31/2026 06:24:27 PMUser Agent Mozilla/5.0 zgrab/0.x
72494104.236.115.66Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.361/31/2026 05:47:48 PMTried to access http ip directly.
72493170.64.146.87Mozilla/5.01/31/2026 04:11:39 PMTried to access http ip directly.
72492161.97.110.246libredtail-http1/31/2026 03:59:34 PMTried to access http ip directly.
72491170.64.152.230Mozilla/5.01/31/2026 02:30:54 PMTried to access http ip directly.
72490148.135.136.171Go-http-client/1.11/31/2026 01:56:36 PMTried to access http ip directly.
72489135.225.84.187Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.5615.137 Safari/537.361/31/2026 12:08:37 PMEvil 404 .env (AWS vulnerability)
7248820.212.211.10Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.361/31/2026 11:24:36 AMEvil 404 /wp-includes/Requests/src/Response/about.php
7248754.83.72.14Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.361/31/2026 11:00:14 AMTried to access http ip directly.
7248645.78.235.65libredtail-http1/31/2026 10:40:15 AMTried to access http ip directly.
72485165.154.174.27curl/7.29.01/31/2026 10:08:26 AMTried to access http ip directly.
7248420.188.62.49Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.361/31/2026 09:51:13 AMEvil 404 /wp-admin.php
7248384.105.19.130python-requests/2.27.11/31/2026 09:23:56 AMUser Agent python-requests/2.27.1
72482193.138.218.204Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.361/31/2026 07:16:08 AMTried to access http ip directly.
7248134.78.140.118python-requests/2.32.51/31/2026 07:07:07 AMTried to access http ip directly.
7248020.211.1.249Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.361/31/2026 04:24:02 AMEvil 404 /wp-admin.php
7247918.230.218.179Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.4 Safari/605.1.151/31/2026 03:28:33 AMTried to access http ip directly.
7247820.64.104.31Mozilla/5.0 zgrab/0.x1/31/2026 03:24:35 AMUser Agent Mozilla/5.0 zgrab/0.x
7247756.125.174.238Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1.1 Safari/605.1.151/31/2026 03:09:50 AMTried to access http ip directly.
7247618.97.26.13Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/60.0.3011.108 Safari/537.321/31/2026 02:06:10 AMTried to access http ip directly.
72475217.154.69.208libredtail-http1/31/2026 01:34:26 AMTried to access http ip directly.
72474104.200.30.32ANK-WALK Internet Research Project - see https://your-domain.com1/30/2026 11:56:33 PMTried to access http ip directly.
72473147.185.132.37Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity1/30/2026 11:29:24 PMTried to access http ip directly.
72472216.180.246.42'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)'1/30/2026 10:47:46 PMTried to access http ip directly.
72471135.237.125.221Mozilla/5.0 zgrab/0.x1/30/2026 09:41:14 PMUser Agent Mozilla/5.0 zgrab/0.x
7247020.169.81.111Mozilla/5.0 zgrab/0.x1/30/2026 07:50:55 PMTried to access http ip directly.
7246920.46.176.183Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.361/30/2026 07:23:17 PMEvil 404 /wp-content/upgrade/index.php
724684.193.194.148Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.361/30/2026 07:22:23 PMEvil 404 /cgi-bin/
72467147.185.133.175Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity1/30/2026 07:12:19 PMTried to access http ip directly.
72466157.173.199.44libredtail-http1/30/2026 06:01:14 PMTried to access http ip directly.
72465194.180.49.39Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Safari/605.1.151/30/2026 05:44:06 PMEvil 404 /wp-login.php
72464115.190.108.231libredtail-http1/30/2026 05:19:01 PMTried to access http ip directly.
7246320.214.137.92Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.361/30/2026 04:25:13 PMEvil 404 /shell.php
7246220.78.152.240Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.361/30/2026 03:08:37 PMEvil 404 /cgi-bin/
7246120.211.164.12Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.361/30/2026 02:42:19 PMEvil 404 /admin/function.php
72460138.124.66.86Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:147.0) Gecko/20100101 Firefox/147.01/30/2026 02:36:01 PMEvil 404 .env (AWS vulnerability)
72459164.92.103.174Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);1/30/2026 02:15:27 PMEvil 404 .env (AWS vulnerability)
7245852.140.123.244Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.361/30/2026 01:31:52 PMEvil 404 /cgi-bin/
72457185.187.99.159Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.361/30/2026 12:44:28 PMTried to access http ip directly.
7245613.75.54.243Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.361/30/2026 12:40:59 PMEvil 404 /wp-includes/Requests/src/Response/about.php
72455139.255.40.124Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.361/30/2026 12:23:35 PMTried to access http ip directly.
7245420.89.106.10Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.361/30/2026 11:50:00 AMEvil 404 /cgi-bin/
72453192.227.159.123Mozilla/5.0 (Macintosh; Intel Mac OS X 15_7_3) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.0 Safari/605.1.151/30/2026 11:46:32 AMTried to access http ip directly.
7245293.123.109.205Mozilla/5.0 (Macintosh; arm64 Mac OS X 12_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.1 Safari/605.1.151/30/2026 09:49:40 AMTried to access http ip directly.
72451138.124.66.84Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:147.0) Gecko/20100101 Firefox/147.01/30/2026 09:46:29 AMEvil 404 .env (AWS vulnerability)
7245040.115.138.121Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.361/30/2026 08:23:07 AMEvil 404 /wp-includes/
72449176.65.139.8Python-urllib/3.101/30/2026 07:00:32 AMUser Agent Python-urllib/3.10
7244845.83.31.168Mozilla/5.0 (adaptive-bot)1/30/2026 05:14:46 AMEvil 404 .env (AWS vulnerability)
7244720.163.1.211Mozilla/5.0 zgrab/0.x1/30/2026 02:59:24 AMUser Agent Mozilla/5.0 zgrab/0.x
7244643.153.9.143Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.11/30/2026 02:39:53 AMTried to access http ip directly.
72445106.53.114.19Go-http-client/1.11/30/2026 02:13:54 AMTried to access http ip directly.
7244445.55.32.64Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.361/30/2026 01:34:18 AMTried to access http ip directly.
72443158.94.211.37Mozilla/6.6.61/30/2026 12:40:57 AMTried to access http ip directly.
72442172.202.49.251Mozilla/5.0 zgrab/0.x1/29/2026 08:30:13 PMUser Agent Mozilla/5.0 zgrab/0.x
7244140.124.173.173Mozilla/5.0 zgrab/0.x1/29/2026 07:31:16 PMTried to access http ip directly.
72440165.227.46.34Mozilla/5.0 (X11; Linux x86_64; rv:142.0) Gecko/20100101 Firefox/142.01/29/2026 07:08:00 PMTried to access http ip directly.
72439193.46.255.154Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.361/29/2026 06:43:26 PMTried to access http ip directly.
7243852.230.35.34Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.361/29/2026 05:50:44 PMEvil 404 /wp-includes/
72437162.216.150.156Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity1/29/2026 04:45:51 PMTried to access http ip directly.
72436172.239.127.5Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.01/29/2026 03:17:49 PMTried to access http ip directly.
72435188.166.252.103Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.361/29/2026 03:03:41 PMEvil 404 /wp-includes/ID3/license.txt
72434212.244.129.14Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.361/29/2026 12:27:00 PMTried to access http ip directly.
72433134.209.202.86Mozilla/5.0; Keydrop.io/1.0(onlyscans.com/about);1/29/2026 12:01:17 PMEvil 404 .env (AWS vulnerability)
72432206.189.48.148Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.361/29/2026 11:36:03 AMTried to access http ip directly.
72431100.24.34.255Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.361/29/2026 11:04:18 AMTried to access http ip directly.
7243052.87.225.23Go-http-client/1.11/29/2026 08:24:22 AMTried to access http ip directly.
7242994.74.70.65libredtail-http1/29/2026 07:44:06 AMTried to access http ip directly.
72428143.198.239.150Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.361/29/2026 06:55:52 AMTried to access http ip directly.
72427139.186.178.91Go-http-client/1.11/29/2026 06:40:12 AMTried to access http ip directly.
72426170.64.195.95Mozilla/5.01/29/2026 06:24:45 AMTried to access http ip directly.
72425101.36.123.102libredtail-http1/29/2026 05:34:33 AMTried to access http ip directly.
72424134.199.164.102Mozilla/5.01/29/2026 03:57:23 AMTried to access http ip directly.
7242320.205.97.28Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.361/29/2026 03:48:10 AMEvil 404 /wp-includes/
7242220.219.8.79Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.361/29/2026 03:12:18 AMEvil 404 /wp-includes/
72421209.38.27.37Mozilla/5.01/29/2026 02:16:57 AMTried to access http ip directly.
72420194.146.42.105libredtail-http1/29/2026 01:07:51 AMTried to access http ip directly.