Log in to view charts and search reports for this IP.
Log In
Reports Activity
Example preview
Report Categories (Last 60 Days)
Example preview
Top Reporter Countries (Last 60 Days)
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 159.203.76.27
This IP address has been reported a total of
79
times from
55 distinct
sources.
159.203.76.27 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 12
reports;
Netherlands
with 6
reports;
United States of America
with 4
reports.
The most common categories in these recent reports were:
Web App Attack
23
times;
Bad Web Bot
13
times;
Hacking
8
times;
Brute-Force
7
times;
Web Spam
2
times;
Other
4
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[pit,ycr] HTTP-Probe on port 443 (via domain). 29 distinct paths probed in 3s. Sustained 58 req/min, ...
show more[pit,ycr] HTTP-Probe on port 443 (via domain). 29 distinct paths probed in 3s. Sustained 58 req/min, 28 nonexistent paths (404). Paths: /2023/, /2024/, /backup/, /blog/, /blog2/, /cms/, /content/, /de/, /en/, /fr/, /home/, /main/, /media/, /new/, /news/, /old/, /portal/, /press/, /shop/, /site/, /site1/, /store/, /us/, /v2/, /web/, /website/, /wordpress/, /wp/
show less
Bad Web Bot
Web App Attack
Anonymous
Automated web attack from 159.203.76.27 against our web server.
28 malicious requests on 2026-09-22 ...
show moreAutomated web attack from 159.203.76.27 against our web server.
28 malicious requests on 2026-09-22 (UTC), denied with HTTP 403.
Classified as: probing for backup archives.
Probed for site copies and backups under names such as /old/, /backup/ and /wordpress/. All denied 403.
This address made 6 such requests.
The source requested 28 distinct paths, consistent with an automated vulnerability scanner run against a broad template set.
Sample request: HEAD /backup/
This source sent 17 distinct browser User-Agent strings in 28 requests over 12 seconds.
Probed for: nonexistent/suspicious paths, WordPress endpoints.
User-Agent: "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6540.18 Safari/537.36".
AS14061 DIGITALOCEAN-ASN.
All timestamps are UTC.
show less