Ban Hackers

Back in the day, hackers were unemployed or unemployable programmers or teenagers with nothing to do.
Now days, it's criminal organizations and Programmers (with a capital P) with masters degrees hired by foreign (and not so foreign) governments to hack into every server they can find. They even try to scan every possible IP address for web servers. When they find one, somebody later tries to hack it.
So, I set up a website for them to visit. It says Coming Soon.
Then, it records their IP Address and bans it from the server with iptables. It also adds their IP Address and User Agent string to the database.

Here are the IP addresses I've banned over the last week:
BannedID IP User Agent String Date Hacked Banned Reason
73290105.157.245.241Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.303/7/2026 12:07:43 AMEvil 404 .env (AWS vulnerability)
7328949.149.75.204Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Mobile Safari/537.363/6/2026 11:38:17 PMEvil 404 .env (AWS vulnerability)
73288169.150.203.200Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.363/6/2026 10:57:00 PMEvil 404 /wp-includes/wlwmanifest.xml
7328763.32.117.71Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)3/6/2026 10:31:40 PMTried to access http ip directly.
7328614.236.60.35Mozilla/5.0 (Windows 98; hi-IN; rv:1.9.0.20) Gecko/9398-04-28 13:12:53.756226 Firefox/7.03/6/2026 08:56:13 PMTried to access http ip directly.
73285162.216.150.238Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity3/6/2026 08:42:45 PMTried to access http ip directly.
7328420.83.167.33Mozilla/5.0 zgrab/0.x3/6/2026 08:23:15 PMUser Agent Mozilla/5.0 zgrab/0.x
7328315.235.198.134Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.363/6/2026 04:17:23 PMEvil 404 .env (AWS vulnerability)
7328215.235.198.134Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.363/6/2026 04:17:23 PMEvil 404 .env (AWS vulnerability)
732813.94.111.96Go-http-client/1.13/6/2026 04:11:52 PMTried to access http ip directly.
73280183.81.169.235Mozilla/5.0 (compatible; FastScan/1.0)3/6/2026 03:33:30 PMTried to access http ip directly.
7327954.162.56.156Go-http-client/1.13/6/2026 02:43:50 PMTried to access http ip directly.
7327813.220.113.59Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.363/6/2026 10:59:03 AMTried to access http ip directly.
73277144.31.25.36Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.5 Safari/605.1.153/6/2026 10:31:22 AMEvil 404 /wp-admin/
7327620.207.200.31Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.363/6/2026 09:42:41 AMEvil 404 /wp-content/themes/haha.php
7327558.51.241.4Mozilla/5.0(WindowsNT10.0;Win64;x64)AppleWebKit/537.36(KHTML,likeGecko)Chrome/86.0.4240.111Safari/537.363/6/2026 07:41:46 AMTried to access http ip directly.
7327491.224.92.162Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.363/6/2026 07:20:26 AMEvil 404 /wp-login.php
73273146.190.156.6Mozilla/5.0 (Macintosh; Intel Mac OS X 11) AppleWebKit/538.41 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.363/6/2026 06:12:32 AMTried to access http ip directly.
73272198.44.177.67libredtail-http3/6/2026 02:06:13 AMTried to access http ip directly.
7327185.217.149.67Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)3/6/2026 01:41:08 AMTried to access http ip directly.
7327020.89.57.111Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.363/6/2026 01:38:25 AMEvil 404 /wp-content/uploads/index.php
7326920.15.200.1Mozilla/5.0 zgrab/0.x3/6/2026 12:55:26 AMUser Agent Mozilla/5.0 zgrab/0.x
7326835.203.211.171Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity3/6/2026 12:17:53 AMTried to access http ip directly.
73267103.143.10.79libredtail-http3/6/2026 12:02:45 AMTried to access http ip directly.
732664.194.42.236Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.363/5/2026 11:40:12 PMEvil 404 /wp-content/uploads/index.php
7326520.169.104.49Mozilla/5.0 zgrab/0.x3/5/2026 11:04:00 PMUser Agent Mozilla/5.0 zgrab/0.x
7326420.219.132.149Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.363/5/2026 10:24:33 PMEvil 404 /wp-content/plugins/hello-dolly/
73263179.43.177.134Go-http-client/1.13/5/2026 09:08:41 PMTried to access http ip directly.
73262216.180.246.112Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)3/5/2026 07:57:40 PMTried to access http ip directly.
73261176.65.149.235Mozilla/1.03/5/2026 07:02:42 PMTried to access http ip directly.
7326020.65.136.10Mozilla/5.0 zgrab/0.x3/5/2026 05:06:58 PMUser Agent Mozilla/5.0 zgrab/0.x
7325985.11.183.27Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.363/5/2026 04:14:46 PMTried to access http ip directly.
7325834.79.181.63python-requests/2.32.53/5/2026 03:25:49 PMTried to access http ip directly.
73257104.208.72.234Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.363/5/2026 02:43:57 PMEvil 404 /wp-content/uploads/index.php
7325654.169.210.208Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.363/5/2026 01:43:05 PMEvil 404 .env (AWS vulnerability)
7325544.205.244.201Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.363/5/2026 11:00:35 AMTried to access http ip directly.
7325489.253.237.136Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.363/5/2026 09:36:35 AMEvil 404 .env (AWS vulnerability)
7325389.253.237.136Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.363/5/2026 09:36:35 AMEvil 404 .env (AWS vulnerability)
7325220.205.42.22Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.363/5/2026 06:38:00 AMEvil 404 /wp-content/plugins/hello-dolly/
73251138.199.35.3Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.363/5/2026 06:34:47 AMEvil 404 /wp-includes/wlwmanifest.xml
73250161.97.112.109Go-http-client/1.13/5/2026 06:18:32 AMTried to access http ip directly.
73249144.123.76.121Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.363/5/2026 05:45:59 AMTried to access http ip directly.
73248216.180.246.170Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)3/5/2026 03:49:19 AMTried to access http ip directly.
73247194.187.179.57Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.03/5/2026 03:22:11 AMTried to access http ip directly.
73246164.90.220.2Mozilla/5.03/5/2026 01:04:29 AMEvil 404 /wp-login.php
73245174.138.94.32Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.363/5/2026 12:12:18 AMTried to access http ip directly.
7324482.180.147.64Go-http-client/1.13/5/2026 12:06:31 AMTried to access http ip directly.
7324334.62.131.131python-requests/2.32.53/4/2026 11:41:37 PMTried to access http ip directly.
7324265.49.1.162Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:140.0) Gecko/20100101 Firefox/140.03/4/2026 09:39:08 PMTried to access http ip directly.
7324137.221.66.19favicon-prober/speed3/4/2026 08:25:05 PMTried to access http ip directly.
7324040.80.83.34Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.363/4/2026 07:52:03 PMEvil 404 /wp-content/themes/haha.php
7323991.231.89.197Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.03/4/2026 07:23:39 PMTried to access http ip directly.
73238172.239.105.139Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.03/4/2026 06:56:47 PMTried to access http ip directly.
7323746.202.208.94libredtail-http3/4/2026 04:55:29 PMTried to access http ip directly.
73236176.65.139.44Go-http-client/1.13/4/2026 04:54:29 PMTried to access http ip directly.
7323552.253.113.41Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.363/4/2026 01:54:45 PMEvil 404 /wp-content/themes/haha.php
73234172.105.55.36Go-http-client/1.13/4/2026 12:46:42 PMEvil 404 .env (AWS vulnerability)
7323357.128.247.37Go-http-client/1.13/4/2026 11:36:14 AMTried to access http ip directly.
73232105.159.219.159Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.303/4/2026 09:19:07 AMEvil 404 .env (AWS vulnerability)
73231193.121.51.31libredtail-http3/4/2026 09:02:53 AMTried to access http ip directly.
73230164.90.164.89Go-http-client/1.13/4/2026 09:01:34 AMTried to access http ip directly.
73229104.248.247.129Mozilla/5.0 (compatible; Odin; https://docs.getodin.com/)3/4/2026 09:01:33 AMTried to access http ip directly.
7322864.226.122.184Go-http-client/1.13/4/2026 09:01:33 AMEvil 404 /cgi-bin/authLogin.cgi
73227139.59.142.93Go-http-client/1.13/4/2026 09:01:33 AMEvil 404 /solr/admin/info/system
73226130.12.180.34Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.363/4/2026 07:39:24 AMEvil 404 .env (AWS vulnerability)
73225159.69.64.245Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.363/4/2026 06:30:40 AMEvil 404 /wp-login.php
7322434.158.79.105Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/120.0.0.03/4/2026 06:01:11 AMEvil 404 .env (AWS vulnerability)
73223135.237.126.18Mozilla/5.0 zgrab/0.x3/4/2026 04:22:11 AMTried to access http ip directly.
73222107.150.119.229libredtail-http3/4/2026 04:17:00 AMTried to access http ip directly.
73221103.161.26.158Go-http-client/1.13/4/2026 03:55:03 AMEvil 404 .env (AWS vulnerability)
73220159.223.135.80Mozilla/5.0 zgrab/0.x3/3/2026 10:47:04 PMTried to access http ip directly.
73219216.180.246.149Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)3/3/2026 08:25:57 PMTried to access http ip directly.
7321834.138.109.14"Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0"3/3/2026 08:13:58 PMTried to access http ip directly.
73217162.216.150.16Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity3/3/2026 07:41:39 PMTried to access http ip directly.
73216167.99.230.208Mozilla/5.0 (X11; Linux x86_64; rv:142.0) Gecko/20100101 Firefox/142.03/3/2026 07:12:33 PMTried to access http ip directly.
7321531.171.130.77Go-http-client/1.13/3/2026 06:19:27 PMEvil 404 /wp-content/txets.php
7321445.156.128.86Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.86 Safari/537.36 BitSightBot/1.03/3/2026 05:21:10 PMTried to access http ip directly.
7321318.97.19.132Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/55.0.3090.96 Safari/537.323/3/2026 05:11:25 PMTried to access http ip directly.
73212136.119.200.86Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Safari/605.1.153/3/2026 03:56:56 PMEvil 404 .env (AWS vulnerability)
73211193.111.248.141Mozilla/5.0 (compatible; silver.inc/2.0)3/3/2026 03:34:48 PMEvil 404 .env (AWS vulnerability)
73210176.65.134.22Linux Gnu (cow)3/3/2026 02:09:34 PMTried to access http ip directly.
7320954.238.91.29Go-http-client/1.13/3/2026 01:17:53 PMTried to access http ip directly.
7320880.94.92.206Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.363/3/2026 12:29:52 PMEvil 404 .env (AWS vulnerability)
7320713.218.58.57Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.363/3/2026 10:56:09 AMTried to access http ip directly.
7320618.191.183.192Go-http-client/1.13/3/2026 10:21:29 AMTried to access http ip directly.
7320543.160.246.48Go-http-client/1.13/3/2026 05:57:29 AMTried to access http ip directly.
73204160.187.210.184Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.363/3/2026 03:54:25 AMEvil 404 /wp-login.php
7320334.122.176.91Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.363/3/2026 02:58:45 AMEvil 404 /wp-includes/wlwmanifest.xml
73202147.185.133.12Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity3/3/2026 02:37:40 AMTried to access http ip directly.
7320120.169.104.211Mozilla/5.0 zgrab/0.x3/3/2026 12:04:46 AMUser Agent Mozilla/5.0 zgrab/0.x
7320020.15.225.63Mozilla/5.0 zgrab/0.x3/3/2026 12:03:32 AMUser Agent Mozilla/5.0 zgrab/0.x
731995.252.177.87Mozilla/5.0 (X11; Linux x86_64; rv:140.0) Gecko/20100101 Firefox/140.03/2/2026 07:15:50 PMTried to access http ip directly.
73198167.99.109.64Mozilla/5.0 (Macintosh; Intel Mac OS X 11) AppleWebKit/538.41 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.363/2/2026 06:37:57 PMTried to access http ip directly.
73197180.252.87.230Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.363/2/2026 05:40:31 PMTried to access http ip directly.
73196165.154.227.162libredtail-http3/2/2026 04:42:16 PMTried to access http ip directly.
73195216.180.246.31Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)3/2/2026 04:12:33 PMTried to access http ip directly.
7319420.89.241.129Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.363/2/2026 03:45:02 PMEvil 404 /wp-admin/css/bolt.php
73193147.185.132.195Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity3/2/2026 03:39:42 PMTried to access http ip directly.
7319240.85.218.182Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.363/2/2026 12:11:11 PMEvil 404 /wp-content/uploads/index.php
73191172.71.164.52Wget/1.21.3 (linux-gnu)3/2/2026 11:31:29 AMUser Agent Wget/1.21.3 (linux-gnu)
731903.83.3.226Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.363/2/2026 10:59:09 AMTried to access http ip directly.
7318920.151.114.166Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.363/2/2026 09:42:59 AMEvil 404 /cgi-bin/
7318882.158.224.115libredtail-http3/2/2026 09:42:49 AMTried to access http ip directly.
73187165.154.11.170Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Edg/120.0.0.03/2/2026 09:03:29 AMTried to access http ip directly.
7318640.80.200.216Mozilla/5.0 zgrab/0.x3/2/2026 07:12:47 AMUser Agent Mozilla/5.0 zgrab/0.x
73185172.71.148.110curl/8.4.03/2/2026 06:04:31 AMUser Agent curl/8.4.0
7318452.66.57.216Go-http-client/1.13/2/2026 05:31:41 AMTried to access http ip directly.
7318334.116.165.233Mozilla/5.0 (iPhone13,2; U; CPU iPhone OS 14_0 like Mac OS X) AppleWebKit/602.1.50 (KHTML, like Gecko) Version/10.0 Mobile/15E148 Safari/602.13/2/2026 04:28:35 AMTried to access http ip directly.
73182104.208.116.225Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.363/2/2026 04:12:17 AMEvil 404 /wp-includes/Requests/src/Response/about.php
73181104.28.203.60Go-http-client/1.13/2/2026 01:43:52 AMEvil 404 /wp-content/style.php
7318043.228.157.37ALittle Client3/2/2026 01:10:51 AMEvil 404 /admin/jquery-file-upload/server/php/index.php?fil
73179147.185.133.161Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity3/2/2026 12:33:17 AMTried to access http ip directly.
7317820.221.72.115Mozilla/5.0 zgrab/0.x3/1/2026 11:52:48 PMUser Agent Mozilla/5.0 zgrab/0.x
73177216.180.246.174Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)3/1/2026 09:55:34 PMTried to access http ip directly.
7317685.217.149.16Mozilla/5.0 (compatible; ModatScanner/1.2; +https://modat.io/)3/1/2026 08:15:59 PMTried to access http ip directly.
7317534.31.125.187Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:135.0) Gecko/20100101 Firefox/144.03/1/2026 08:03:02 PMEvil 404 .env (AWS vulnerability)
73174124.223.225.25libredtail-http3/1/2026 07:50:53 PMTried to access http ip directly.
73173134.209.235.25Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.03/1/2026 07:40:27 PMTried to access http ip directly.
7317220.104.97.185Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.363/1/2026 07:04:53 PMEvil 404 /wp-content/uploads/index.php
7317118.218.78.79Go-http-client/1.13/1/2026 05:26:43 PMTried to access http ip directly.
73170176.65.149.233Mozilla/1.03/1/2026 03:55:58 PMTried to access http ip directly.
731694.193.97.168Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.363/1/2026 03:53:02 PMEvil 404 /wp-includes/
73168216.180.246.66Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)3/1/2026 02:45:28 PMTried to access http ip directly.
7316777.37.92.171Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.363/1/2026 12:58:07 PMEvil 404 .env (AWS vulnerability)
7316677.37.92.171Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.363/1/2026 12:58:07 PMEvil 404 .env (AWS vulnerability)
73165139.59.255.45Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.363/1/2026 12:53:39 PMEvil 404 /wp-includes/ID3/license.txt
7316420.151.11.87Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.363/1/2026 12:01:26 PMEvil 404 /cgi-bin/
7316354.145.158.145Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.363/1/2026 11:00:31 AMTried to access http ip directly.
7316243.162.97.123libredtail-http3/1/2026 10:20:01 AMTried to access http ip directly.
7316162.60.131.73python-requests/2.32.43/1/2026 09:45:25 AMTried to access http ip directly.
73160153.92.11.95Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.363/1/2026 07:54:25 AMEvil 404 .env (AWS vulnerability)
7315989.117.27.125Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.363/1/2026 07:38:46 AMEvil 404 .env (AWS vulnerability)
7315854.160.105.34Go-http-client/1.13/1/2026 07:37:24 AMTried to access http ip directly.
7315734.60.218.115Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.363/1/2026 07:22:48 AMEvil 404 /wp-includes/wlwmanifest.xml
7315634.22.170.248python-requests/2.32.53/1/2026 06:55:30 AMTried to access http ip directly.
7315589.117.51.126libredtail-http3/1/2026 06:34:55 AMTried to access http ip directly.
7315484.247.187.159Go-http-client/1.13/1/2026 05:42:23 AMTried to access http ip directly.
73153216.180.246.49Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)3/1/2026 04:31:07 AMTried to access http ip directly.
73152206.189.57.26Go-http-client/1.13/1/2026 04:18:41 AMEvil 404 /cgi-bin/authLogin.cgi
73151207.154.196.114Mozilla/5.03/1/2026 04:06:45 AMEvil 404 /wp-login.php
73150104.248.91.29Mozilla/5.03/1/2026 03:04:58 AMEvil 404 /wp-login.php
73149104.248.33.41Mozilla/5.03/1/2026 02:47:14 AMEvil 404 /wp-login.php
7314820.214.137.177Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.363/1/2026 02:26:46 AMEvil 404 /wp-includes/
7314782.24.64.32libredtail-http3/1/2026 12:20:33 AMTried to access http ip directly.
7314620.64.104.235Mozilla/5.0 zgrab/0.x2/28/2026 11:17:03 PMTried to access http ip directly.
73145139.59.93.244Mozilla/5.02/28/2026 11:07:58 PMEvil 404 /wp-login.php
73144136.144.33.43Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/117.02/28/2026 10:57:57 PMEvil 404 /wp-login.php
7314345.156.129.108Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.86 Safari/537.36 BitSightBot/1.02/28/2026 10:34:32 PMTried to access http ip directly.
7314245.156.129.106Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.86 Safari/537.36 BitSightBot/1.02/28/2026 10:33:48 PMEvil 404 /cgi-bin/authLogin.cgi
7314145.156.129.105Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.86 Safari/537.36 BitSightBot/1.02/28/2026 10:33:11 PMTried to access http ip directly.
73140167.71.234.55Mozilla/5.02/28/2026 10:28:31 PMEvil 404 /wp-login.php
73139165.232.83.109Mozilla/5.02/28/2026 09:55:41 PMEvil 404 /wp-login.php
7313880.94.92.123Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.362/28/2026 08:54:06 PMEvil 404 .env (AWS vulnerability)
7313720.205.226.191Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.362/28/2026 08:38:49 PMEvil 404 /wp-admin/css/bolt.php
7313689.248.168.239Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.362/28/2026 08:24:54 PMEvil 404 .env (AWS vulnerability)
7313587.236.176.108Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)2/28/2026 07:50:54 PMTried to access http ip directly.
73134142.93.167.243Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.362/28/2026 06:40:20 PMTried to access http ip directly.
73133162.216.149.172Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity2/28/2026 06:05:27 PMTried to access http ip directly.
73132178.16.128.177Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.362/28/2026 05:23:17 PMEvil 404 .env (AWS vulnerability)
7313145.131.195.241Go-http-client/1.12/28/2026 05:06:38 PMEvil 404 /wp-includes/css/buttons.css
73130176.65.149.234Mozilla/1.02/28/2026 05:04:38 PMTried to access http ip directly.
7312920.239.137.159Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.362/28/2026 04:59:57 PMEvil 404 /wp-admin/css/bolt.php
7312852.231.70.237Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.362/28/2026 04:52:42 PMEvil 404 /wp-admin/css/bolt.php
7312735.241.216.72python-requests/2.32.52/28/2026 03:51:49 PMTried to access http ip directly.
7312620.53.243.118Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.362/28/2026 03:22:35 PMEvil 404 /wp-includes/Requests/src/Response/about.php
73125138.2.0.137libredtail-http2/28/2026 02:45:42 PMTried to access http ip directly.
731248.209.91.228curl/7.64.12/28/2026 12:10:43 PMTried to access http ip directly.
7312345.142.154.112Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.362/28/2026 11:52:46 AMTried to access http ip directly.
73122119.163.47.128Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.362/28/2026 11:52:02 AMTried to access http ip directly.
7312118.206.155.169Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.362/28/2026 10:57:43 AMTried to access http ip directly.
7312020.104.96.199Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.362/28/2026 10:50:01 AMEvil 404 /wp-includes/Text/Diff/Renderer/
73119107.21.52.176Go-http-client/1.12/28/2026 10:18:33 AMTried to access http ip directly.
7311891.230.225.106Go-http-client/1.12/28/2026 09:08:38 AMEvil 404 /wp-content/txets.php
73117161.35.21.188Go-http-client/1.12/28/2026 07:51:06 AMEvil 404 /solr/admin/info/system
73116152.42.181.232Shodan-Pull/1.02/28/2026 06:15:29 AMTried to access http ip directly.
7311552.180.144.125Mozilla/5.0 zgrab/0.x2/28/2026 06:15:23 AMUser Agent Mozilla/5.0 zgrab/0.x
73114152.42.217.251Shodan-Pull/1.02/28/2026 03:56:49 AMTried to access http ip directly.