Log in to view charts and search reports for this IP.
Log In
Top Reporter Countries (Last 60 Days)
Example preview
Report Categories (Last 60 Days)
Example preview
Reports Activity
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 167.99.68.8:
This IP address has been reported a total of
61
times from
48 distinct
sources.
167.99.68.8 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 29
reports;
United States of America
with 8
reports;
France
with 6
reports.
The most common categories in these recent reports were:
Web App Attack
46
times;
Brute-Force
16
times;
Bad Web Bot
12
times;
Hacking
9
times;
SQL Injection
3
times;
Other
6
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-login.php. Blocked ...
show moreAutomated honeypot detection. honeypot against a Next.js application. Paths: /wp-login.php. Blocked at the edge.
show less
malicious bot detected: violations="hit-honeypot"; user_agent="Mozilla/5.0 (Macintosh; Intel Mac OS ...
show moremalicious bot detected: violations="hit-honeypot"; user_agent="Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.15"
show less
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb.
Events: 1. First: 2026-09-07T ...
show moreAuto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb.
Events: 1. First: 2026-09-07T16:07:02+0200. Last: 2026-09-07T16:07:02+0200.
Samples:
- 2026-09-06 00:33:25,249 fail2ban.actions [4095059]: NOTICE [abuseipdb] Ban 167.99.68.8
show less
(php-url-fopen) Failed php-url-fopen trigger from 167.99.68.8 (SG/Singapore/-/Singapore/-/[redacted] ...
show more(php-url-fopen) Failed php-url-fopen trigger from 167.99.68.8 (SG/Singapore/-/Singapore/-/[redacted])
show less
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb.
Events: 1. First: 2026-09-07T ...
show moreAuto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb.
Events: 1. First: 2026-09-07T11:07:02+0200. Last: 2026-09-07T11:07:02+0200.
Samples:
- 2026-09-06 00:33:25,249 fail2ban.actions [4095059]: NOTICE [abuseipdb] Ban 167.99.68.8
show less
Web App Attack
Anonymous
(caddyscan) Scanner path probe from 167.99.68.8 (SG/Singapore/-): 5 in the last 3600 secs; Ports: *; ...
show more(caddyscan) Scanner path probe from 167.99.68.8 (SG/Singapore/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 167.99.68.8 - - [07/Sep/2026:08:09:58 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 167.99.68.8 - - [07/Sep/2026:08:10:39 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 167.99.68.8 - - [07/Sep/2026:08:10:39 +0000] "GET /wp-admin/ HTTP/1.1"
[REDACTED] 200 2627 167.99.68.8 - - [07/Sep/2026:08:43:01 +0000] "GET /wp-login.php HTTP/1.1"
[REDACTED] 200 2627 167.99.68.8 - - [07/Sep/2026:08:43:02 +0000] "GET /wp-login.php HTTP/1.1"
show less
Repeated requests for suspicious nonexistent URLs, for example: /wp-login.php (HTTP/1.1 port 443, us ...
show moreRepeated requests for suspicious nonexistent URLs, for example: /wp-login.php (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36")
show less