This IP address has been reported a total of
39
times from
26 distinct
sources.
103.96.235.150 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
BnL006: Obvious dumb distributed botnet crawler stepping into honeypot trap, violating robots.txt an ...
show moreBnL006: Obvious dumb distributed botnet crawler stepping into honeypot trap, violating robots.txt and meta directives
103.96.235.150 443 - [25/Aug/2026:22:14:48 +0000] "GET [redacted] HTTP/1.1" 200 7913 "-" "Mozilla/5.0 (iPad; CPU iPad OS 12_5_7 like Mac OS X) AppleWebKit/536.1 (KHTML, like Gecko) CriOS/49.0.833.0 Mobile/19G630 Safari/536.1"
show less
UDP flood (DDoS) vs AS215599: 51 pkts / 0.07 MB to UDP 80/8443 across 42 dst IP(s), 2026-08-19 21:46 ...
show moreUDP flood (DDoS) vs AS215599: 51 pkts / 0.07 MB to UDP 80/8443 across 42 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
UDP flood (DDoS) vs AS215599: 51 pkts / 0.07 MB to UDP 80/8443 across 42 dst IP(s), 2026-08-19 21:46 ...
show moreUDP flood (DDoS) vs AS215599: 51 pkts / 0.07 MB to UDP 80/8443 across 42 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less