This IP address has been reported a total of
26
times from
17 distinct
sources.
103.120.200.58 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 3
reports;
United States of America
with 3
reports;
France
with 1
report.
The most common categories in these recent reports were:
Bad Web Bot
6
times;
DDoS Attack
3
times;
Exploited Host
2
times;
Web App Attack
1
time;
Brute-Force
1
time;
Other
1
time.
Old Reports
The most recent abuse report for this IP address is from
. It is possible that this IP is no
longer involved in abusive activities.
Repeated requests classified as pathological web bot behavior, for example: /[redacted]?topics%5B2%5 ...
show moreRepeated requests classified as pathological web bot behavior, for example: /[redacted]?topics%5B2%5D=89&topics%5B3%5D=37&topics%5B4%5D=31&topics%5B5%5D=44 (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36")
show less
Client failed challenge verification, marked as suspicious. HTTP request received over TCP on applic ...
show moreClient failed challenge verification, marked as suspicious. HTTP request received over TCP on application ports 80/443. Observed 2026-09-09T17:38:41Z.
show less
Botnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18: ...
show moreBotnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18:00 and 19:30 local time (+04:00). This source sent UDP to port 47472 of 185.143.177.x at more than 800 packets/sec. Nothing listens on that port - repeated full packet captures of all traffic reaching this machine recorded its services on other UDP ports and never a single packet to 47472 - so this cannot be a client of anything; it is flood by definition, independent of any rate measurement. One of 2743 sources in 1270 networks and 136 countries in the same wave. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. The host is almost certainly compromised and part of a botnet. Evidence: [email protected].
show less
DDoS Attack
Exploited Host
Anonymous
denied traffic to a non-approved destination port. destination port 10839.
| [Dangerous/Bangladesh] Aggressive IP 103.120.200.58 (~30 hits). Type: DoS Defender- Web server 400 ...
show more| [Dangerous/Bangladesh] Aggressive IP 103.120.200.58 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Fail2Ban: 103.120.200.58 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5 ...
show moreFail2Ban: 103.120.200.58 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5.0 (iPhone; CPU iPhone OS 11_0 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.4820.1224 Mobile Safari/537.36
show less
BnL006: Obvious dumb distributed botnet crawler stepping into honeypot trap despite it clearly being ...
show moreBnL006: Obvious dumb distributed botnet crawler stepping into honeypot trap despite it clearly being a burning bag of dog poop.
103.120.200.58 443 - [24/Jun/2026:14:53:57 +0000] "GET [redacted] HTTP/1.1" 503 6164 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
show less