This IP address has been reported a total of
68
times from
58 distinct
sources.
3.95.148.126 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 18
reports;
Germany
with 14
reports;
Brazil
with 5
reports.
The most common categories in these recent reports were:
Port Scan
52
times;
Hacking
18
times;
Web App Attack
10
times;
Brute-Force
8
times;
SSH
5
times;
Other
8
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Blocked by UFW (TCP on 80)
Source port: 22220
TTL: 121
Packet length: 60
TOS: 0x00
This report (for ...
show moreBlocked by UFW (TCP on 80)
Source port: 22220
TTL: 121
Packet length: 60
TOS: 0x00
This report (for 3.95.148.126) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Auto-blocked by Seczar SecureOps โ High-Risk Port Probe (admin-managed entries) โ SSH (24 events in ...
show moreAuto-blocked by Seczar SecureOps โ High-Risk Port Probe (admin-managed entries) โ SSH (24 events in 5min) at 2026-10-10 21:12
show less
Automated scan detection against redacted protected targets. Hits=3; port 8443 proto 6 detection dar ...
show moreAutomated scan detection against redacted protected targets. Hits=3; port 8443 proto 6 detection dark_ip; port 8443 proto 6 detection dark_ip; port 8443 proto 6 detection dark_ip
show less
[probe-68-69] 2026-10-10 16:31:26, Client: 3.95.148.126, Protocol: 6, Unauthorized activity to HTTP: ...
show more[probe-68-69] 2026-10-10 16:31:26, Client: 3.95.148.126, Protocol: 6, Unauthorized activity to HTTP: GET /
show less
Connection to port 1244 with data transfer.
Data preview: GET / HTTP/1.1
Host: 198.23.188.201:1244
...
show moreConnection to port 1244 with data transfer.
Data preview: GET / HTTP/1.1
Host: 198.23.188.201:1244
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) App
show less
Cloudmax IPS Block - Suspicious activity. Possible port scanning, service reconnaissance, or vulnera ...
show moreCloudmax IPS Block - Suspicious activity. Possible port scanning, service reconnaissance, or vulnerability probing
show less
Honeypot Finding: repeated TCP service probing on TCP/56001 (service); 5 application-level events ac ...
show moreHoneypot Finding: repeated TCP service probing on TCP/56001 (service); 5 application-level events across 5 source port(s). Sensor(s): Honeytrap.
show less
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10 ...
show more[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10m window.
Origin: US / AS14618 Amazon.com, Inc.
Active: 18:54:52 UTC
Volume: 1 HTTP req
Probed: /favicon.ico
Status mix: 444ร1
Vhost fishing: 67.217.240.72
UA: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Honeypot/Firewall detectou varredura nรฃo solicitada ou brute-force Inbound nas portas: 80. Total de ...
show moreHoneypot/Firewall detectou varredura nรฃo solicitada ou brute-force Inbound nas portas: 80. Total de conexรตes droppadas: 3.
show less
Blocked by UFW (TCP on 8080)
Source port: 54408
TTL: 119
Packet length: 60
TOS: 0x00
This report (f ...
show moreBlocked by UFW (TCP on 8080)
Source port: 54408
TTL: 119
Packet length: 60
TOS: 0x00
This report (for 3.95.148.126) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less