This IP address has been reported a total of
9
times from
9 distinct
sources.
159.89.197.73 was first reported on
January 5th 2023 , and the most recent report was
2 hours ago .
In the last 60 days, the top reporter locations were:
Germany
with 3
reports;
Canada
with 1
report;
France
with 1
report.
The most common categories in these recent reports were:
Web App Attack
5
times;
Brute-Force
2
times;
Exploited Host
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ฉ๐ช
FeG Deutschland
2026-10-06 18:47:03
(2 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
๐จ๐ฆ
DRI
2026-10-06 16:54:49
(4 hours ago)
Web attack/Malicious activity detected
Web App Attack
Anonymous
2026-10-06 16:48:10
(4 hours ago)
[Tue Oct 06 17:25:32.970866 2026] [authz_core:error] [pid 4478:tid 4516] [client 159.89.197.73:51561 ...
show more
[Tue Oct 06 17:25:32.970866 2026] [authz_core:error] [pid 4478:tid 4516] [client 159.89.197.73:51561] AH01630: client denied by server configuration: /var/www/cimt-precision/wp-login.php, referer: https://www.bing.com/
[Tue Oct 06 17:25:41.769785 2026] [authz_core:error] [pid 36072:tid 36115] [client 159.89.197.73:52523] AH01630: client denied by server configuration: /var/www/cimt-precision/wp-login.php, referer: https://duckduckgo.com/
[Tue Oct 06 17:25:45.820177 2026] [authz_core:error] [pid 36072:tid 36114] [client 159.89.197.73:52523] AH01630: client denied by server configuration: /var/www/cimt-precision/wp-admin/, referer: https://t.co/
[Tue Oct 06 18:48:09.675758 2026] [authz_core:error] [pid 15309:tid 15361] [client 159.89.197.73:64279] AH01630: client denied by server configuration: /var/www/cimt-precision/wp-login.php
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-10-06 16:47:21
(4 hours ago)
WordPress wp-login.php Brute Force Attack
Brute-Force
Web App Attack
๐ฉ๐ช
R.G.
2026-10-06 14:30:11
(7 hours ago)
(WPLOGINorWHATEVER) Get lost please 159.89.197.73 (SG/Singapore/-): 7 in the last 600 secs; Ports: * ...
show more
(WPLOGINorWHATEVER) Get lost please 159.89.197.73 (SG/Singapore/-): 7 in the last 600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
Anonymous
2026-05-20 00:10:37
(4 months ago)
curl https://gsocket.io/y
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
maxpower
2026-05-19 00:01:06
(4 months ago)
(wp_login) REGOLA 1 - WP Login Attack 159.89.197.73 (SG/Singapore/-): 5 in the last 3600 secs; Ports ...
show more
(wp_login) REGOLA 1 - WP Login Attack 159.89.197.73 (SG/Singapore/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 159.89.197.73 - - [19/May/2026:02:00:44 +0200] "GET /wp-login.php HTTP/2.0" 301 0 "-" "Mozila/5.0" "159.89.197.73" host=yogiraji.it
159.89.197.73 - - [19/May/2026:02:00:46 +0200] "GET /wp-login.php HTTP/2.0" 302 0 "-" "Mozila/5.0" "159.89.197.73" host=www.yogiraji.it
159.89.197.73 - - [19/May/2026:02:00:46 +0200] "GET /wp-login.php HTTP/2.0" 302 0 "-" "Mozila/5.0" "159.89.197.73" host=www.yogiraji.it
159.89.197.73 - - [19/May/2026:02:00:47 +0200] "GET /wp-login.php HTTP/2.0" 302 0 "-" "Mozila/5.0" "159.89.197.73" host=www.yogiraji.it
159.89.197.73 - - [19/May/2026:02:00:47 +0200] "GET /wp-login.php HTTP/2.0" 302 0 "-" "Mozila/5.0" "159.89.197.73" host=www.yogiraji.it
show less
Port Scan
๐ซ๐ท
Lunix
2026-05-18 14:25:17
(4 months ago)
Brute-Force
Web App Attack
๐จ๐ณ
ThreatBook.io
2023-01-05 22:24:28
(3 years ago)
ThreatBook Intelligence: cdn more details on http://threatbook.io/ip/159.89.197.73
SSH
Showing 1 to
9
of 9 reports