This IP address has been reported a total of
36
times from
20 distinct
sources.
98.91.81.246 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Blocked abusive HTTP application-layer DoS / botnet traffic from 98.91.81.246: traffic from this add ...
show moreBlocked abusive HTTP application-layer DoS / botnet traffic from 98.91.81.246: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
Blocked abusive HTTP application-layer DoS / botnet traffic from 98.91.81.246: traffic from this add ...
show moreBlocked abusive HTTP application-layer DoS / botnet traffic from 98.91.81.246: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
Blocked abusive HTTP application-layer DoS / botnet traffic from 98.91.81.246: traffic from this add ...
show moreBlocked abusive HTTP application-layer DoS / botnet traffic from 98.91.81.246: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -139.874 (Bad < -10 / Very Bad < -20 ...
show moreBot/Spam/Scrapper attack detected on www.handytreff.de - Score: -139.874 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amzn-SearchBot/0.1) Chrome/119.0.6045
show less
Honeypot triggered:
IP: 98.91.81.246
Request to: https://xserverx.ru/.env
Method: GET
Host: xserverx ...
show moreHoneypot triggered:
IP: 98.91.81.246
Request to: https://xserverx.ru/.env
Method: GET
Host: xserverx.ru
User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amzn-SearchBot/0.1) Chrome/119.0.6045.214 Safari/537.36
Referer: Direct
Country: US
ASN: Unknown
Triggered rules: (\.env|\.env\.local|\.env\.production)
Timestamp: 2026-08-14T06:41:31.869Z
show less
Blocked abusive HTTP application-layer DoS / botnet traffic from 98.91.81.246: traffic from this add ...
show moreBlocked abusive HTTP application-layer DoS / botnet traffic from 98.91.81.246: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
Blocked abusive HTTP application-layer DoS / botnet traffic from 98.91.81.246: traffic from this add ...
show moreBlocked abusive HTTP application-layer DoS / botnet traffic from 98.91.81.246: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
(antiscrape_rule) Web application abuse detected 98.91.81.246 (US/United States/ec2-98-91-81-246.com ...
show more(antiscrape_rule) Web application abuse detected 98.91.81.246 (US/United States/ec2-98-91-81-246.compute-1.amazonaws.com): 5 in the last 900 secs
show less
(mod_security) mod_security (id:225080) triggered by 98.91.81.246 (ec2-98-91-81-246.compute-1.amazon ...
show more(mod_security) mod_security (id:225080) triggered by 98.91.81.246 (ec2-98-91-81-246.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 07:22:28.809229 2026] [security2:error] [pid 21879:tid 21879] [client 98.91.81.246:0] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^[\\\\d\\\\.ab]+$" against "ARGS_GET:C" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "143"] [id "225080"] [rev "1"] [msg "COMODO WAF: XSS vulnerability in Plupload before 2.1.9 or MediaElement.js before 2.21.0, as used in WordPress before 4.5.2 (CVE-2016-4566 & CVE-2016-4567)||kirklandhighlands.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kirklandhighlands.org"] [uri "/wp-includes/js/tinymce/plugins/hr/"] [unique_id "ako-dKgR8-DJsmEMTREsDAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Showing 1 to
15
of 36 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ