AbuseIPDB » 162.158.139.10
162.158.139.10 was found in our database!
This IP was reported 7 times. Confidence of
Abuse
is 0% : ?
ISP
Cloudflare, Inc.
Usage Type
Data Center/Web Hosting/Transit
ASN
AS13335
Domain Name
cloudflare.com
Country
๐ฐ๐ท
Korea (the Republic of)
City
Seoul, Seoul
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
Important Note: 162.158.139.10 is an IP address from within
our whitelist belonging to the subnet
162.158.0.0/15 ,
which we identify as: "Cloudflare Reverse Proxy" .
Whitelisted netblocks are typically owned by trusted entities, such as Google
or Microsoft who may use them for search engine spiders. However, these same entities
sometimes also provide cloud servers and mail services which are easily abused. Pay special
attention when trusting or distrusting these IPs.
IP Abuse Reports for 162.158.139.10 :
This IP address has been reported a total of
7
times from
6 distinct
sources.
162.158.139.10 was first reported on
November 29th 2025 , and the most recent report was
2 days ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ฉ๐ช
acadeova
2026-07-25 16:09:05
(2 days ago)
๐จ Recon detected (nft drop)
SRC=162.158.139.10
Observed=TCP dpt=80 in=enp0s6 ttl=54
Time=recent(jour ...
show more
๐จ Recon detected (nft drop)
SRC=162.158.139.10
Observed=TCP dpt=80 in=enp0s6 ttl=54
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
Anonymous
2026-06-20 07:05:10
(1 month ago)
162.158.139.10 - - [20/Jun/2026:09:04:35 +0200] "GET /.env_1 HTTP/1.1" 403 124 "-" "curl/8.7.1"
162. ...
show more
162.158.139.10 - - [20/Jun/2026:09:04:35 +0200] "GET /.env_1 HTTP/1.1" 403 124 "-" "curl/8.7.1"
162.158.139.10 - - [20/Jun/2026:09:04:35 +0200] "GET /.env.stage HTTP/1.1" 403 124 "-" "curl/8.7.1"
162.158.139.10 - - [20/Jun/2026:09:04:35 +0200] "GET /config.env HTTP/1.1" 403 124 "-" "curl/8.7.1"
162.158.139.10 - - [20/Jun/2026:09:04:36 +0200] "GET /.pam_environment HTTP/1.1" 403 124 "-" "curl/8.7.1"
162.158.139.10 - - [20/Jun/2026:09:04:36 +0200] "GET /.environment HTTP/1.1" 403 124 "-" "curl/8.7.1"
162.158.139.10 - - [20/Jun/2026:09:04:37 +0200] "GET /.env.production HTTP/1.1" 403 124 "-" "curl/8.7.1"
162.158.139.10 - - [20/Jun/2026:09:04:37 +0200] "GET /.env.production.local HTTP/1.1" 403 124 "-" "curl/8.7.1"
162.158.139.10 - - [20/Jun/2026:09:04:38 +0200] "GET /.powenv HTTP/1.1" 403 124 "-" "curl/8.7.1"
162.158.139.10 - - [20/Jun/2026:09:04:38 +0200] "GET /.rbenv-gemsets HTTP/1.1" 403 124 "-" "curl/8.7.1"
162.158.139.10 - - [20/Jun/2026:09:04:39 +0200] "GET /.envs HTTP/1.1" 403 124 "
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-06-17 22:00:46
(1 month ago)
162.158.139.10 - - [18/Jun/2026:00:00:38 +0200] "GET /public/phpinfo.php HTTP/1.1" 404 441 "-" "Mozi ...
show more
162.158.139.10 - - [18/Jun/2026:00:00:38 +0200] "GET /public/phpinfo.php HTTP/1.1" 404 441 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
162.158.139.10 - - [18/Jun/2026:00:00:38 +0200] "GET /public/phpinfo.php HTTP/1.1" 404 245 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
162.158.139.10 - - [18/Jun/2026:00:00:39 +0200] "GET /php-info.php HTTP/1.1" 404 441 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
162.158.139.10 - - [18/Jun/2026:00:00:39 +0200] "GET /php-info.php HTTP/1.1" 404 245 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
162.158.139.10 - - [18/Jun/2026:00:00:40 +0200] "GET /_phpinfo.php HTTP/1.1" 404 441 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/53
...
show less
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-03-25 23:36:51
(4 months ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
๐บ๐ธ
iwle
2026-01-10 23:27:55
(6 months ago)
162.158.139.10 - - [10/Jan/2026:18:27:47 -0500] "GET /wp-includes/blocks/missing/index.php HTTP/2.0" ...
show more
162.158.139.10 - - [10/Jan/2026:18:27:47 -0500] "GET /wp-includes/blocks/missing/index.php HTTP/2.0" 404 196 "https://www.google.fr/" "Mozilla/5.0 (Linux; Android 13; M2101K6G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36"
162.158.139.10 - - [10/Jan/2026:18:27:50 -0500] "GET /wp-includes/blocks/social-link/index.php HTTP/2.0" 404 196 "https://www.yahoo.com/" "Mozilla/5.g (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Mobile Safari/537.36"
162.158.139.10 - - [10/Jan/2026:18:27:53 -0500] "GET /wp-includes/js/plupload/index.php HTTP/2.0" 404 196 "https://www.google.co.uk/" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1"
...
show less
Brute-Force
๐ฉ๐ช
alive
2025-12-30 23:03:20
(6 months ago)
Confirmed malicious activity observed via T-Pot honeypot Observed 34 events on port 443 (unknown) fr ...
show more
Confirmed malicious activity observed via T-Pot honeypot Observed 34 events on port 443 (unknown) from 2025-12-30T23:03:20+00:00 to 2025-12-30T23:04:31.074000+00:00. Sample: {"src_port": 13479, "src_ip": "162.158.139.10", "dest_port": 443}
show less
Port Scan
๐ง๐ท
SOC Blue Team
2025-11-29 17:35:45
(7 months ago)
Tatic: TA0006 | Technique: T1110 | Source: TAP | Country Destination: BR
Brute-Force
Showing 1 to
7
of 7 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: