Log in to view charts and search reports for this IP.
Log In
Reports Activity
Example preview
Report Categories (Last 60 Days)
Example preview
Top Reporter Countries (Last 60 Days)
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 4.149.168.134
This IP address has been reported a total of
391
times from
154 distinct
sources.
4.149.168.134 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 1
report;
Finland
with 1
report.
The most common categories in these recent reports were:
Port Scan
1
time;
SQL Injection
1
time;
Web App Attack
1
time;
Bad Web Bot
1
time;
Brute-Force
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
This address is enumerating paths that do not exist on our sites โ asking for scripts, plugins, admi ...
show moreThis address is enumerating paths that do not exist on our sites โ asking for scripts, plugins, admin consoles or endpoints the sites never had, one after another. This is vulnerability scanning: looking for something to exploit. Blocked; please check the machine behind it for a scanner or malware. | method: GET | path: /access/api/v1/system/ping (+2 more) | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 | 2026-09-27 22:33 UTC
show less
[MonJun0119:20:41.1092582026][security2:error][pid3065993:tid3066087][client4.149.168.134:0]ModSecur ...
show more[MonJun0119:20:41.1092582026][security2:error][pid3065993:tid3066087][client4.149.168.134:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\${encodeuricomponent\(string\(res\)\)}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=\(function\(\){var_r=typeofrequire\!==undefined\?require:\(process.mainmodule\?process.mainmodule.require.bind\(process.mainmodule\):\(typeofglobalthis.require\!==undefined\?globalthis.require:null\)\)return12899339148110000}\)\(\)throwobject.assign\(newerror\(next_redirect\){...\"][tag\"attack-rce\"][
show less
Apr 10 12:54:41 odin sshd[19179]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 ...
show moreApr 10 12:54:41 odin sshd[19179]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=4.149.168.134
Apr 10 12:54:43 odin sshd[19179]: Failed password for invalid user centos from 4.149.168.134 port 30848 ssh2
Apr 10 12:56:29 odin sshd[20162]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=4.149.168.134
show less
Brute-Force
SSH
Anonymous
2026-04-10T12:44:58.892344+02:00 hosting15 sshd[3079901]: pam_unix(sshd:auth): authentication failur ...
show more2026-04-10T12:44:58.892344+02:00 hosting15 sshd[3079901]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=4.149.168.134
2026-04-10T12:45:01.114728+02:00 hosting15 sshd[3079901]: Failed password for invalid user centos from 4.149.168.134 port 30852 ssh2
2026-04-10T12:54:06.746891+02:00 hosting15 sshd[3081702]: Invalid user centos from 4.149.168.134 port 30848
...
show less
2026-04-10 05:49:38.764985-0500 localhost sshd-session[25780]: Failed password for invalid user cen ...
show more2026-04-10 05:49:38.764985-0500 localhost sshd-session[25780]: Failed password for invalid user centos from 4.149.168.134 port 30849 ssh2
show less