AbuseIPDB » 2.26.123.59
2.26.123.59 was found in our database!
This IP was reported 6 times. Confidence of
Abuse
is 20% : ?
ISP
VPSPay - vpspay.cloud
Usage Type
Data Center/Web Hosting/Transit
ASN
AS201988
Domain Name
vpspay.cloud
Country
๐ฉ๐ช
Germany
City
Frankfurt am Main, Hesse
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 2.26.123.59 :
This IP address has been reported a total of
6
times from
6 distinct
sources.
2.26.123.59 was first reported on
May 16th 2026 , and the most recent report was
1 month ago .
Old Reports:
The most recent abuse report for this IP address is from
1 month ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐บ๐ธ
Gowtham A
2026-05-17 19:46:45
(1 month ago)
CrowdSec: crowdsecurity/http-probing
2.26.123.59 - - [15/May/2026:08:06:37 +0000] "GET /wp-includes/ ...
show more
CrowdSec: crowdsecurity/http-probing
2.26.123.59 - - [15/May/2026:08:06:37 +0000] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 403 45071 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv)"
13 alerts in 32s | Action: ban 4h
show less
Web App Attack
๐ง๐ท
kmtnck
2026-05-17 18:29:58
(1 month ago)
Fail2Ban (traefik-botsearch): Ban 2.26.123.59 after 13 failures
2.26.123.59 - - [15/May/2026:15:57:5 ...
show more
Fail2Ban (traefik-botsearch): Ban 2.26.123.59 after 13 failures
2.26.123.59 - - [15/May/2026:15:57:59 +0000] "GET /test.php HTTP/1.1" 403 49409 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
2.26.123.59 - - [15/May/2026:15:57:59 +0000] "GET /console/ HTTP/1.1" 401 487 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฎ๐น
melochef
2026-05-17 01:50:18
(1 month ago)
ModSecurity: Access denied with code 403 (phase 2). [id "942100"] [msg "SQL Injection Attack Detecte ...
show more
ModSecurity: Access denied with code 403 (phase 2). [id "942100"] [msg "SQL Injection Attack Detected via libinjection"] [severity "CRITICAL"] [tag "OWASP_CRS/4.0"] [hostname "waf.cdn-edge.net"] [uri "/solr/admin/info/system"] [unique_id "ae2645905b2c722d"]
2.26.123.59 - - [15/May/2026:06:15:55 +0000] "GET /solr/admin/info/system HTTP/1.1" 403 1381 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
๐ท๐ด
Victor Hernandez
2026-05-16 22:20:44
(1 month ago)
CrowdSec Detection: crowdsecurity/http-path-traversal-probing
2.26.123.59 - - [14/May/2026:10:33:39 ...
show more
CrowdSec Detection: crowdsecurity/http-path-traversal-probing
2.26.123.59 - - [14/May/2026:10:33:39 +0000] "GET /remote/logincheck HTTP/1.1" 401 45257 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
10 alerts in 16s. Decision: ban 4h
show less
Web App Attack
๐ท๐ด
soham bhore
2026-05-16 22:12:44
(1 month ago)
Port sweep detected - this IP scanned over 200 ports on our server.
Port Scan
๐ท๐ด
kp_5036
2026-05-16 22:09:55
(1 month ago)
AS201988 VPSPay bulletproof hosting. Active in SNI spoofing, hosting phishing kits, C2 infrastructur ...
show more
AS201988 VPSPay bulletproof hosting. Active in SNI spoofing, hosting phishing kits, C2 infrastructure, and proxy/VPN abuse services.
show less
Hacking
Exploited Host
Showing 1 to
6
of 6 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: