This IP address has been reported a total of
10
times from
9 distinct
sources.
116.68.198.5 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 1
report;
France
with 1
report;
United Kingdom of Great Britain and Northern Ireland
with 1
report.
The most common categories in these recent reports were:
Bad Web Bot
3
times;
Exploited Host
2
times;
Web App Attack
2
times;
DDoS Attack
1
time;
SSH
1
time;
Other
2
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Sustained failed SSH authentication attempts recorded by a honeypot sensor network.
Threat score: 17 ...
show moreSustained failed SSH authentication attempts recorded by a honeypot sensor network.
Threat score: 17/100 (low) | Phase: reconnaissance (pre-auth probing / scanning)
Failed auth: 101 (15 bad password, 86 invalid user) | 0 success | 217 total SSH log events | seen on 1 sensor(s)
Origin: Bangladesh (BD) | AS23923 Agni Systems Limited | 116.68.198.0/24
First seen: 2026-10-03 16:26:38 UTC | Last seen: 2026-10-03 16:29:15 UTC
Source: Linux OpenSSH journalctl telemetry, multi-sensor CERT honeypot.
show less
Repeated requests classified as pathological web bot behavior, for example: /[redacted]?topics%5B1%5 ...
show moreRepeated requests classified as pathological web bot behavior, for example: /[redacted]?topics%5B1%5D=49&topics%5B2%5D=60&topics%5B3%5D=28&topics%5B4%5D=70 (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:144.0) Gecko/20100101 Firefox/144.0")
show less
DDoS Attack
Bad Web Bot
Anonymous
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show moreDistributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in thread-skip.asp
show less
Exploited Host
Bad Web Bot
Anonymous
Large-scale coordinated botnet (1.2M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a ...
show moreLarge-scale coordinated botnet (1.2M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/Shursky [yordim|LIS|MOW]); Attacker: Mikhail Smirnov (mikhail-smirnov-79830323/Aidan [MOW]) employed by Angara Technologies Group | Attack Signature Blocked: /wishlist/index/add/product/12295/form_key/IcesKEvL3iGHQqQw/ | UA: Opera/8.25.(Windows 95; nan-TW) Presto/2.9.161 Version/12.00 | (Magento Site)
show less
NOQUEUE - IP: 116.68.198.5 - Jun 1 15:50:04 plesk postfix/smtpd[3172114]: NOQUEUE: reject: RCPT fro ...
show moreNOQUEUE - IP: 116.68.198.5 - Jun 1 15:50:04 plesk postfix/smtpd[3172114]: NOQUEUE: reject: RCPT from unknown[116.68.198.5]: 554 5.7.1 Service unavailable; Client host [116.68.198.5] blocked using dnsbl-2.uceprotect.net; Net 116.68.192.0/20 is UCEPROTECT-Level2 listed because 108 impacts are seen from AGNI-AS Agni Systems Limited, BD/AS23923 there. See: http://www.uceprotect.net/rblcheck.php?ipr=116.68.198.5; from=<REDACTED@REDACTED> to=<REDACTED@REDACTED> proto=ESMTP helo=<116.68.198.6>
show less