This IP address has been reported a total of
28
times from
18 distinct
sources.
103.172.139.51 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0. ...
show moreMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36 Edg/144.0.0.0
show less
UDP flood (DDoS) vs AS215599: 47 pkts / 0.07 MB to UDP 80/8443 across 45 dst IP(s), 2026-08-19 21:46 ...
show moreUDP flood (DDoS) vs AS215599: 47 pkts / 0.07 MB to UDP 80/8443 across 45 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
UDP flood (DDoS) vs AS215599: 47 pkts / 0.07 MB to UDP 80/8443 across 45 dst IP(s), 2026-08-19 21:46 ...
show moreUDP flood (DDoS) vs AS215599: 47 pkts / 0.07 MB to UDP 80/8443 across 45 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
HTTP application-layer DoS / botnet traffic from 103.172.139.51: repeated high-cost dynamic page and ...
show moreHTTP application-layer DoS / botnet traffic from 103.172.139.51: repeated high-cost dynamic page and feed requests (profile/tag views, forums, tracker, RSS) at abusive rates via completed TCP/HTTPS. Likely compromised end-user host.
show less