This IP address has been reported a total of
39
times from
22 distinct
sources.
103.113.149.48 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0
show less
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0. ...
show moreMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
show less
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0. ...
show moreMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
show less
KelvaTLS: TCP connection-limit abuse against TCP port 1194 on our infrastructure. nft veil1194off_co ...
show moreKelvaTLS: TCP connection-limit abuse against TCP port 1194 on our infrastructure. nft veil1194off_conn+veil1194off_rate: held more concurrent connections to the OpenVPN listener than the per-source limit permits; opened new connections to the OpenVPN listener faster than the per-source limit permits from this source. UTC 2026-08-30T02:17:54Z. incident kelva-20260830-013346Z.
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
UDP flood (DDoS) vs AS215599: 1062 pkts / 1.52 MB to UDP 80/8443 across 437 dst IP(s), 2026-08-19 21 ...
show moreUDP flood (DDoS) vs AS215599: 1062 pkts / 1.52 MB to UDP 80/8443 across 437 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
UDP flood (DDoS) vs AS215599: 1062 pkts / 1.52 MB to UDP 80/8443 across 437 dst IP(s), 2026-08-19 21 ...
show moreUDP flood (DDoS) vs AS215599: 1062 pkts / 1.52 MB to UDP 80/8443 across 437 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
DDoS Attack
Exploited Host
Anonymous
Distributed scraper residential proxy pool โ www.publicprinceton.com /store/filtered/ (WineCommerce ...
show moreDistributed scraper residential proxy pool โ www.publicprinceton.com /store/filtered/ (WineCommerce WAF)
show less
BnL006: Obvious dumb distributed botnet crawler stepping into honeypot trap, violating robots.txt an ...
show moreBnL006: Obvious dumb distributed botnet crawler stepping into honeypot trap, violating robots.txt and meta directives
103.113.149.48 443 - [15/Aug/2026:13:11:48 +0000] "GET [redacted] HTTP/1.1" 503 6135 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
show less