This IP address has been reported a total of
75
times from
57 distinct
sources.
136.92.2.251 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 15
reports;
Netherlands
with 12
reports;
Finland
with 8
reports.
The most common categories in these recent reports were:
Web App Attack
60
times;
Brute-Force
22
times;
Bad Web Bot
17
times;
Hacking
12
times;
Port Scan
7
times;
Other
4
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
ET EXPLOIT Apache HTTP Server 2.4.49 - Path Traversal Attempt (CVE-2021-41773) M2
ET EXPLOIT Grafa ...
show moreET EXPLOIT Apache HTTP Server 2.4.49 - Path Traversal Attempt (CVE-2021-41773) M2
ET EXPLOIT Grafana 8.x Path Traversal (CVE-2021-43798)
ET EXPLOIT VMware Spring Cloud Directory Traversal (CVE-2020-5410)
ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt
ET WEB_SERVER Generic PHP Remote File Include
ET WEB_SERVER Likely Malicious Request for /proc/self/environ
ET WEB_SERVER Next.js Middleware Authorization Bypass (CVE-2025-29927)
ET WEB_SERVER PHP Possible php Remote File Inclusion Attempt
ET WEB_SERVER PHP tags in HTTP POST
ET WEB_SERVER PHP.//Input in HTTP POST
ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body
ET WEB_SERVER allow_url_include PHP config option in uri
ET WEB_SERVER auto_prepend_file PHP config option in uri
ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577)
ET WEB_SPECIFIC_APPS Vite Arbitrary File Read Via raw parameter (CVE-2025-30208)
GPL WEB_SERVER .htpasswd access
GPL WEB_SERVER 403 Forbidden
show less
136.92.2.251 - - [08/Oct/2026:03:14:18 +0100] "GET /@fs/var/run/secrets/kubernetes.io/serviceaccount ...
show more136.92.2.251 - - [08/Oct/2026:03:14:18 +0100] "GET /@fs/var/run/secrets/kubernetes.io/serviceaccount/ca.crt?raw?? HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
Anonymous
Sensitive Configuration File Disclosure; Apache HTTP Server Directory Traversal; Web Servers Directo ...
show moreSensitive Configuration File Disclosure; Apache HTTP Server Directory Traversal; Web Servers Directory Traversal; Web Servers Malicious URL Directory Traversal; Next.js Authentication Bypass (CVE-2025-29927).
show less