Log in to view charts and search reports for this IP.
Log In
Reports Activity
Example preview
Report Categories (Last 60 Days)
Example preview
Top Reporter Countries (Last 60 Days)
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 103.116.116.246
This IP address has been reported a total of
36
times from
22 distinct
sources.
103.116.116.246 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 6
reports;
France
with 4
reports;
Germany
with 3
reports.
The most common categories in these recent reports were:
Bad Web Bot
7
times;
DDoS Attack
7
times;
Exploited Host
4
times;
Web App Attack
4
times;
Brute-Force
3
times;
Other
4
times.
Old Reports
The most recent abuse report for this IP address is from
. It is possible that this IP is no
longer involved in abusive activities.
Repeated requests classified as pathological web bot behavior, for example: /[redacted]?topics%5B1%5 ...
show moreRepeated requests classified as pathological web bot behavior, for example: /[redacted]?topics%5B1%5D=68&topics%5B2%5D=43&topics%5B3%5D=31&topics%5B4%5D=33 (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.75 Safari/537.36")
show less
Automated fake-account registration attack against a web platform in Portugal. Part of a distributed ...
show moreAutomated fake-account registration attack against a web platform in Portugal. Part of a distributed campaign of 5300 fraudulent registration attempts from 1544 source IPs across 501 ASNs in 51 countries between 2026-09-13 03:39:43 and 09:43:22 UTC, at a deliberately low sustained rate (~14.6/min) consistent with a commercial residential proxy network.
show less
Brute-Force
Web App Attack
Anonymous
denied traffic to a honeypot network. destination port 50504.
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show moreDistributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in email-link.asp
show less
UDP flood (DDoS) vs AS215599: 1072 pkts / 1.53 MB to UDP 80/8443 across 433 dst IP(s), 2026-08-19 21 ...
show moreUDP flood (DDoS) vs AS215599: 1072 pkts / 1.53 MB to UDP 80/8443 across 433 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
UDP flood (DDoS) vs AS215599: 1072 pkts / 1.53 MB to UDP 80/8443 across 433 dst IP(s), 2026-08-19 21 ...
show moreUDP flood (DDoS) vs AS215599: 1072 pkts / 1.53 MB to UDP 80/8443 across 433 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less