Neutral Activity
There is no recent abuse activity, or the IP address is whitelisted.
Whitelisted Subnet
Whitelisted netblocks are typically owned by trusted entities, such as Google or Microsoft who
may use them for search engine spiders. However, these same entities sometimes also provide cloud
servers and mail services which are easily abused. Pay special attention when trusting or
distrusting these IPs.
This IP address has been reported a total of
217
times from
42 distinct
sources.
141.101.98.199 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 15
reports;
Belgium
with 4
reports;
Germany
with 4
reports.
The most common categories in these recent reports were:
Web App Attack
31
times;
Bad Web Bot
18
times;
Brute-Force
15
times;
Port Scan
2
times;
Hacking
2
times;
Other
2
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[03/Oct/2026:14:37:39 +0300] -- 141.101.98.199 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp- ...
show more[03/Oct/2026:14:37:39 +0300] -- 141.101.98.199 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-content/plugins/woocommerce/readme.txt HTTP/1.1
show less
[01/Oct/2026:19:59:04 +0300] -- 141.101.98.199 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more[01/Oct/2026:19:59:04 +0300] -- 141.101.98.199 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.local HTTP/1.1
show less
Probing for various exploits. โThank youโ CloudFlare for enabling perps to probe exploits through yo ...
show moreProbing for various exploits. โThank youโ CloudFlare for enabling perps to probe exploits through your reverse proxy which is conveniently whitelisted by AbuseIPDB.
141.101.98.199 443 - [30/Sep/2026:22:21:31 +0000] "GET /index%20copy.php HTTP/1.1" 404 7455 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0"
141.101.98.199 443 - [30/Sep/2026:22:21:39 +0000] "GET /index.php.txt HTTP/1.1" 301 5461 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1"
141.101.98.199 443 - [30/Sep/2026:22:21:39 +0000] "GET /.htaccess HTTP/1.1" 301 653 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
show less
CMS/framework probe: 141.101.98.199 - - [30/Sep/2026:22:33:12 +0200] "GET /.aws/credentials HTTP/2.0 ...
show moreCMS/framework probe: 141.101.98.199 - - [30/Sep/2026:22:33:12 +0200] "GET /.aws/credentials HTTP/2.0" 499 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" asn=13335 org="Cloudflare, Inc." country=GB
...
show less
Web App Attack
Anonymous
Attacks websites by trying to access known vulnerables of plugins, brute-force of backends or probin ...
show moreAttacks websites by trying to access known vulnerables of plugins, brute-force of backends or probing of administrative tools
show less