This IP address has been reported a total of
427
times from
300 distinct
sources.
4.194.147.153 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
256 requests, including :
GET /images/ HTTP/1.1
GET /wp-content/classwithtostring.php HTTP/1.1
GET ...
show more256 requests, including :
GET /images/ HTTP/1.1
GET /wp-content/classwithtostring.php HTTP/1.1
GET /wp-includes/certificates/ HTTP/1.1
GET /wp-editor.php HTTP/1.1
GET /wp-includes/js/codemirror/index.php HTTP/1.1
GET /wp-content/themes/admin.php HTTP/1.1
GET /.well-known/acme-challenge/file.php HTTP/1.1
GET /admin.php HTTP/1.1
GET /<<removed>>.php HTTP/1.1
GET /cgi-bin/index.php HTTP/1.1
GET /wp-<<removed>>.php HTTP/1.1
GET /wp-includes/css/index.php HTTP/1.1
GET /.well-known/index.php HTTP/1.1
show less
256 requests, including :
GET /<<removed>>.php HTTP/1.1
GET /wp.php HTTP/1.1
GET /modules/mod_simpl ...
show more256 requests, including :
GET /<<removed>>.php HTTP/1.1
GET /wp.php HTTP/1.1
GET /modules/mod_simplefileuploadv1.3/elements/ HTTP/1.1
GET /wp-includes/sitemaps/wp-conflg.php HTTP/1.1
GET /wp-includes/html-api/index.php HTTP/1.1
GET /wp-<<removed>>.php HTTP/1.1
GET /.well-known/acme-challenge/file.php HTTP/1.1
GET /wp-includes/Requests/index.php HTTP/1.1
GET /images/ HTTP/1.1
GET /wp-content/uploads/2024/ HTTP/1.1
GET /wp-includes/sitemaps/autoload_classmap.php HTTP/1.1
GET /wp-includes/style-engine/autoload_classmap.php HTTP/1.1
show less
This IP was detected 50 times on my original honeypot and also performed automated reconnaissance an ...
show moreThis IP was detected 50 times on my original honeypot and also performed automated reconnaissance and vulnerability scanning against my server between 2025-12-27T14:02:52Z UTC and 2025-12-27T14:03:51Z UTC.
The honeypot folders included examples such as: /wp-content/themes/, /cgi-bin/, /wp-content/upgrade/ and others.
The honeypot files included examples such as: /404.php, /403.php, /wp-trackback.php and others.
It issued 215 HTTP requests targeting 50 distinct suspicious paths within about 59 seconds.
The targeted paths included examples such as: /index.php, /wp-content/upgrade/index.php, /wp-includes/SimplePie/about.php and others.
Many of the requests specifically probed WordPress-related paths (wp-admin, wp-content, wp-includes, themes, plugins, etc.).
The scan also attempted to access .well-known paths that are often misused in compromised environments.
Multiple requests used filenames that resemble PHP web shells or exploitation payloads.
show less
Auto-ban: 35 malicious requests on 2025-12-26 (e.g., env/backup probes, brute-force, or error bursts ...
show moreAuto-ban: 35 malicious requests on 2025-12-26 (e.g., env/backup probes, brute-force, or error bursts).
show less
Hacking
Web App Attack
SSH
Showing 1 to
15
of 427 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ