This IP address has been reported a total of
32
times from
24 distinct
sources.
103.138.173.131 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Botnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:8888/udp in AS203136 (LLC Ordu ...
show moreBotnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:8888/udp in AS203136 (LLC Ordunet), Georgia, on 2026-09-15 from 14:17 local time (+04:00). This source sustained more than 800 packets/sec toward a single UDP port, against about 200 packets/sec for a legitimate player of that server. It was one of 8847 sources in 2396 networks and 160 countries recorded inside a single 25-minute window - the server's entire real audience is about a hundred players. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. Not a scan and not brute force - a packet flood, so the host is most likely compromised. Evidence: [email protected].
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36 Edg/144.0.0.0
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36 Edg/144.0.0.0
show less
DDoS flood attack against 31.56.58.0 (2026-08-20 15:38:33 -> 2026-08-20 15:53:33 UTC) targeting AS21 ...
show moreDDoS flood attack against 31.56.58.0 (2026-08-20 15:38:33 -> 2026-08-20 15:53:33 UTC) targeting AS215599. This IP (AS139029) sent ~3950 packets (5.61 MB) during the attack window. Likely a compromised device (botnet).
show less
UDP flood (DDoS) vs AS215599: 17 pkts / 0.02 MB to UDP 8443 across 15 dst IP(s), 2026-08-19 21:46 to ...
show moreUDP flood (DDoS) vs AS215599: 17 pkts / 0.02 MB to UDP 8443 across 15 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
UDP flood (DDoS) vs AS215599: 17 pkts / 0.02 MB to UDP 8443 across 15 dst IP(s), 2026-08-19 21:46 to ...
show moreUDP flood (DDoS) vs AS215599: 17 pkts / 0.02 MB to UDP 8443 across 15 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
BnL006: Obvious dumb distributed botnet crawler stepping into honeypot trap despite it clearly being ...
show moreBnL006: Obvious dumb distributed botnet crawler stepping into honeypot trap despite it clearly being a burning bag of dog poop.
103.138.173.131 443 - [21/Jul/2026:04:24:49 +0000] "GET [redacted] HTTP/1.1" 200 7097 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
show less