This IP address has been reported a total of
22
times from
16 distinct
sources.
104.199.189.162 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 5
reports;
United Kingdom of Great Britain and Northern Ireland
with 4
reports;
Belarus
with 3
reports.
The most common categories in these recent reports were:
Web App Attack
20
times;
Hacking
7
times;
Brute-Force
4
times;
Bad Web Bot
4
times;
DDoS Attack
1
time;
Other
3
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
{"level":"info","ts":1790937532.269627,"logger":"http.log.access.log1","msg":"handled request","requ ...
show more{"level":"info","ts":1790937532.269627,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"104.199.189.162","remote_port":"33044","client_ip":"104.199.189.162","proto":"HTTP/2.0","method":"GET","host":"up.hj.rs","uri":"/assets/manifest.json","headers":{"Sec-Ch-Ua":["\"Chromium\";v=\"152\", \"Not?A_Brand\";v=\"24\", \"Google Chrome\";v=\"152\""],"Sec-Ch-Ua-Platform":["\"macOS\""],"Accept-Language":["en-US,en;q=0.9"],"Sec-Fetch-Mode":["no-cors"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Accept":["*/*"],"Sec-Fetch-Site":["same-origin"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"Sec-Ch-Ua-Mobile":["?0"],"Sec-Fetch-Dest":["script"],"User-Agent":["Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"],"Priority":["u=1"]},"tls":{
...
show less
[AI Threat Score: 75/100 via Gemini] [AbuseIPDB Score: 63] The IP address 104.199.189.162 launched a ...
show more[AI Threat Score: 75/100 via Gemini] [AbuseIPDB Score: 63] The IP address 104.199.189.162 launched a series of malicious requests targeting majikah.solutions, including path traversal attempts on /userfiles and sensitive process file probes like /@fs/proc/self/cmdline and /@fs/proc/self/environ. CrowdSec corroborates this activity, classifying the IP as malicious with active behaviors including http:exploit, http:scan, and http:crawl, while AbuseIPDB reports 13 external abuse entries. Likely motive: Executing automated web application reconnaissance and sensitive file extraction.
show less