Neutral Activity
There is no recent abuse activity, or the IP address is whitelisted.
Whitelisted Subnet
Whitelisted netblocks are typically owned by trusted entities, such as Google or Microsoft who
may use them for search engine spiders. However, these same entities sometimes also provide cloud
servers and mail services which are easily abused. Pay special attention when trusting or
distrusting these IPs.
This IP address has been reported a total of
229
times from
53 distinct
sources.
141.101.99.12 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 38
reports;
Germany
with 6
reports;
Ukraine
with 5
reports.
The most common categories in these recent reports were:
Web App Attack
56
times;
Bad Web Bot
42
times;
Brute-Force
36
times;
Hacking
6
times;
Port Scan
5
times;
Other
11
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[ycr] HTTP-Probe on port 443 (via domain). 5 distinct paths probed in 3s. Sustained 5 req/min, 5 non ...
show more[ycr] HTTP-Probe on port 443 (via domain). 5 distinct paths probed in 3s. Sustained 5 req/min, 5 nonexistent paths (404). Paths: /%252f%252eaws%252fcredentials, /.docker/config.json, /.npmrc, /application.yml, /index.php.bak
show less
Bad Web Bot
Web App Attack
Anonymous
Network service scanning detected by FortiGate; source quarantined.
Repeated suspicious HTTP service scan against a blocked web sinkhole; threshold=3 events/10m; result ...
show moreRepeated suspicious HTTP service scan against a blocked web sinkhole; threshold=3 events/10m; result=blocked; user-agent=unknown
show less
Repeated suspicious HTTP service scan against a blocked web sinkhole; threshold=3 events/10m; result ...
show moreRepeated suspicious HTTP service scan against a blocked web sinkhole; threshold=3 events/10m; result=blocked; user-agent=Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0
show less
[08/Oct/2026:18:49:47 +0300] -- 141.101.99.12 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more[08/Oct/2026:18:49:47 +0300] -- 141.101.99.12 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.local HTTP/1.1
show less
DDoS Attack
FTP Brute-Force
Ping of Death
Port Scan
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
IoT Targeted