This IP address has been reported a total of
21
times from
16 distinct
sources.
200.123.52.98 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 4
reports;
France
with 3
reports;
Germany
with 2
reports.
The most common categories in these recent reports were:
Brute-Force
3
times;
Bad Web Bot
3
times;
DDoS Attack
3
times;
Exploited Host
3
times;
Port Scan
2
times;
Other
4
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2026-10-09 UTC, chalkwild.com: WordPress admin login brute-force / credential stuffing. 1 failed POS ...
show more2026-10-09 UTC, chalkwild.com: WordPress admin login brute-force / credential stuffing. 1 failed POST to /wp-login.php (HTTP 200 = rejected), 2 requests total. Sequence: GET /wp-login.php 08:32:18;POST /wp-login.php 08:32:21. Zero requests for any login-page CSS or JS - a real browser rendering wp-login.php fetches eight assets, this fetched none, so it is a headless client, not a visitor. UA claims Chrome/151. One of 37 distinct IPs that each sent only 1-2 login attempts against this host today and nothing else, a distributed pool paced deliberately under rate-based blocking. No login succeeded.
show less
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0. ...
show moreMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36
show less
UDP flood (DDoS) vs AS215599: 928 pkts / 1.33 MB to UDP 80/8443 across 425 dst IP(s), 2026-08-19 21: ...
show moreUDP flood (DDoS) vs AS215599: 928 pkts / 1.33 MB to UDP 80/8443 across 425 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
UDP flood (DDoS) vs AS215599: 928 pkts / 1.33 MB to UDP 80/8443 across 425 dst IP(s), 2026-08-19 21: ...
show moreUDP flood (DDoS) vs AS215599: 928 pkts / 1.33 MB to UDP 80/8443 across 425 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
Verified scan activity detected by local IDS/firewall correlation. SCAN: HIGHRISK_MULTIPORT | PORTS= ...
show moreVerified scan activity detected by local IDS/firewall correlation. SCAN: HIGHRISK_MULTIPORT | PORTS=22,23 | HITS=2 | IPSET=ADD | FIRST=2026-08-17 23:03:01 | LAST=2026-08-17 23:03:01. Last seen 2026-08-17 23:03:01.
show less
DDoS flood attack against 31.56.58.23 (2026-08-15 17:54:21 -> 2026-08-15 18:09:21 UTC) targeting AS2 ...
show moreDDoS flood attack against 31.56.58.23 (2026-08-15 17:54:21 -> 2026-08-15 18:09:21 UTC) targeting AS215599. This IP (AS272928) sent ~884 packets (1.17 MB) during the attack window. Likely a compromised device (botnet).
show less
DDoS Attack
Exploited Host
Anonymous
denied traffic to a honeypot network. destination port 23.