This IP address has been reported a total of
17
times from
12 distinct
sources.
103.47.132.89 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Czechia
with 2
reports;
Germany
with 1
report;
Spain
with 1
report.
The most common categories in these recent reports were:
Brute-Force
4
times;
Bad Web Bot
2
times;
DDoS Attack
1
time;
Email Spam
1
time;
Web App Attack
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
(exim_invalid_user) srv201 Exim auth on non-existent account 103.47.132.89 (ID/Indonesia/host-103-47 ...
show more(exim_invalid_user) srv201 Exim auth on non-existent account 103.47.132.89 (ID/Indonesia/host-103-47-132-89.myrepublic.co.id): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Email account brute force: 1 attempts were recorded from 103.47.132.89
2026-10-07T10:35:28+02:00 war ...
show moreEmail account brute force: 1 attempts were recorded from 103.47.132.89
2026-10-07T10:35:28+02:00 warning: unknown[103.47.132.89]: SASL PLAIN authentication failed: authentication failure, [email protected]show less
Email account brute force: 1 attempts were recorded from 103.47.132.89
2026-10-06T15:47:53+02:00 war ...
show moreEmail account brute force: 1 attempts were recorded from 103.47.132.89
2026-10-06T15:47:53+02:00 warning: unknown[103.47.132.89]: SASL PLAIN authentication failed: authentication failure, [email protected]show less
Repeated requests classified as pathological web bot behavior, for example: /[redacted]?topics%5B1%5 ...
show moreRepeated requests classified as pathological web bot behavior, for example: /[redacted]?topics%5B1%5D=59&topics%5B2%5D=79&topics%5B3%5D=67&topics%5B4%5D=45 (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.67 Safari/537.36")
show less
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show moreAsking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-11 13:25 UTC
show less
Distributed application-layer DoS against git.mills.io (self-hosted Gitea). High-volume automated re ...
show moreDistributed application-layer DoS against git.mills.io (self-hosted Gitea). High-volume automated requests to expensive Git repository endpoints (commit/diff/blame/archive views), ~1 request per IP, spoofed browser UA, rejected with HTTP 429. Residential-proxy botnet campaign, 2026-06-13/14 UTC.
show less
Blocked by UFW (TCP on 51196)
Source port: 41123
TTL: 115
Packet length: 52
TOS: 0x00
This report ( ...
show moreBlocked by UFW (TCP on 51196)
Source port: 41123
TTL: 115
Packet length: 52
TOS: 0x00
This report (for 103.47.132.89) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Honeypot detection: SMB / Windows file sharing exploitation attempt on port 445. Severity: HIGH. Aar ...
show moreHoneypot detection: SMB / Windows file sharing exploitation attempt on port 445. Severity: HIGH. Aaran.cloud
show less