Neutral Activity
There is no recent abuse activity, or the IP address is whitelisted.
Whitelisted Subnet
Whitelisted netblocks are typically owned by trusted entities, such as Google or Microsoft who
may use them for search engine spiders. However, these same entities sometimes also provide cloud
servers and mail services which are easily abused. Pay special attention when trusting or
distrusting these IPs.
Log in to view charts and search reports for this IP.
Log In
Reports Activity
Example preview
Report Categories (Last 60 Days)
Example preview
Top Reporter Countries (Last 60 Days)
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 162.159.122.111
This IP address has been reported a total of
9
times from
8 distinct
sources.
162.159.122.111 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Belgium
with 2
reports;
Brazil
with 1
report;
United States of America
with 1
report.
The most common categories in these recent reports were:
Web App Attack
3
times;
Brute-Force
2
times;
SSH
1
time;
Bad Web Bot
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2026-09-25T11:51:57.147620+00:00 edge-con-sao01.int.pdx.net.uk sshd-session[2545960]: pam_unix(sshd: ...
show more2026-09-25T11:51:57.147620+00:00 edge-con-sao01.int.pdx.net.uk sshd-session[2545960]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=162.159.122.111
2026-09-25T11:51:59.136876+00:00 edge-con-sao01.int.pdx.net.uk sshd-session[2545960]: Failed password for invalid user arika from 162.159.122.111 port 53477 ssh2
2026-09-25T11:52:03.429917+00:00 edge-con-sao01.int.pdx.net.uk sshd-session[2545960]: Failed password for invalid user arika from 162.159.122.111 port 53477 ssh2
...
show less
Confirmed malicious activity observed via T-Pot honeypot Observed 11 events on port 80 (unknown) fro ...
show moreConfirmed malicious activity observed via T-Pot honeypot Observed 11 events on port 80 (unknown) from 2026-01-01T15:39:17+00:00 to 2026-01-01T15:41:40.598000+00:00. Sample: {"src_port": 13106, "dest_port": 80, "src_ip": "162.159.122.111"}
show less
[Tue Dec 23 13:01:11.626913 2025] [php:error] [pid 821239] [client 162.159.122.111:12818] script '/v ...
show more[Tue Dec 23 13:01:11.626913 2025] [php:error] [pid 821239] [client 162.159.122.111:12818] script '/var/www/html/alfi.php' not found or unable to stat, referer: https://www.google.fr/
[Tue Dec 23 13:01:11.857055 2025] [php:error] [pid 821239] [client 162.159.122.111:12818] script '/var/www/html/DC.php' not found or unable to stat, referer: https://www.yahoo.com/
[Tue Dec 23 13:01:13.195972 2025] [php:error] [pid 821239] [client 162.159.122.111:12818] script '/var/www/html/Ninja.php' not found or unable to stat, referer: https://www.google.fr/
[Tue Dec 23 13:01:13.417861 2025] [php:error] [pid 821239] [client 162.159.122.111:12818] script '/var/www/html/wp-incleude.php' not found or unable to stat, referer: https://www.google.co.uk/
[Tue Dec 23 13:01:14.544361 2025] [php:error] [pid 821239] [client 162.159.122.111:12818] script '/var/www/html/Alfa.php' not found or unable to stat, referer: https://www.google.com/
...
show less
Brute-Force
Web App Attack
Anonymous
[Mon Dec 01 08:55:30.185801 2025] [authz_core:error] [pid 26170] [client 162.159.122.111:12633] AH01 ...
show more[Mon Dec 01 08:55:30.185801 2025] [authz_core:error] [pid 26170] [client 162.159.122.111:12633] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://www.bing.com/
[Mon Dec 01 08:55:31.263730 2025] [authz_core:error] [pid 26170] [client 162.159.122.111:12633] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://www.yahoo.com/
[Mon Dec 01 08:55:31.502205 2025] [authz_core:error] [pid 26170] [client 162.159.122.111:12633] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://www.google.co.uk/
...
show less
Web App Attack
Showing 1 to
9
of 9 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ