HTTP application-layer DoS / botnet traffic from 121.37.90.137: repeated high-cost dynamic page and ...
show moreHTTP application-layer DoS / botnet traffic from 121.37.90.137: repeated high-cost dynamic page and feed requests (profile/tag views, forums, tracker, RSS) at abusive rates via completed TCP/HTTPS. Likely compromised end-user host.
show less
CrowdSec: REPEAT OFFENDER (previously banned, came back) - distributed L7 HTTP flood on WordPress 'T ...
show moreCrowdSec: REPEAT OFFENDER (previously banned, came back) - distributed L7 HTTP flood on WordPress 'The Events Calendar' AJAX endpoints (request_format~json) - DDoS | req: /calendrier-2/action~agenda/time_limit~1700866800/cat_ids~139/tag_ids~437,333,444/request_format~json/ | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36
show less
Attribution: mikhail-smirnov-79830323 (LinkedIn/profile ID) employed by Angara Technologies Group (E ...
show moreAttribution: mikhail-smirnov-79830323 (LinkedIn/profile ID) employed by Angara Technologies Group (Explicitly identified himself as enemy a week before attack began) | Aggressive search filter manipulation / web scraper probe on port 443 | URI: Heavy query parameter abuse: /brands/hp/printers/shopby/manufacturer-hp.html?dir=desc&mode=grid&order=most_viewed&rating=6&p=2 | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36 | (Magento Site)
show less
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show moreDistributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in printer-friendly.asp
show less
ThreatBook Intelligence: IDC,vpn_proxy more details on https://threatbook.io/ip/121.37.90.137
2026-0 ...
show moreThreatBook Intelligence: IDC,vpn_proxy more details on https://threatbook.io/ip/121.37.90.137
2026-04-12 12:27:38 /wxshare11/wxs.php,{"body":"url=http%3A%2F%2Fnxnews.net%2Fyc%2Fztyx%2F202303%2Ft20230318_7890613.html","content_type":"application/x-www-form-urlencoded","header":{"Accept":["application/json, text/javascript, */*; q=0.01"],"Accept-Encoding":["gzip, deflate"],"Accept-Language":["zh-CN,zh;q=0.9"],"Connection":["keep-alive"],"Content-Length":["73"],"Content-Type":["application/x-www-form-urlencoded; charset=UTF-8"],"Origin":["http://nxnews.net"],"User-Agent":["Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"]},"host":"fx.nxnews.net","method":"POST","proto":"HTTP/1.1","remote_addr":"121.37.90.137:51588","status_code":200,"url":"/wxshare11/wxs.php","user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"}
show less
121.37.90.137 | Port: 13960 | DNS: mail.aei3g.com 2026-04-09T00:44:57+08:00 Asia/Shanghai | MAIL Dat ...
show more121.37.90.137 | Port: 13960 | DNS: mail.aei3g.com 2026-04-09T00:44:57+08:00 Asia/Shanghai | MAIL Data Center/Web Hosting/Transit Spam list | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36 HTTP/1.1 443 GET | URL: /zh/%e5%88%9d%e5%ad%a6%e8%80%85%e6%8c%87%e5%8d%97/%e5%93%aa%e7%a7%8d%e9%a3%9f%e7%94%a8%e8%89%b2%e7%b4%a0%e6%9b%b4%e9%80%82%e5%90%88gumpaste?2bcdba1c2aecfa1d31fb=b3a3cebeebbef1a222cf | Ref: - | Country: CN/China/+08:00 IP City: Beijing macOS 9e92bd4e9d07f7bd-LAX/Los Angeles, CA, United States 1 hits/0 secs Browser 1
show less
Brute-Force
Web App Attack
Blog Spam
Web Spam
Exploited Host
ThreatBook Intelligence: IDC,vpn_proxy more details on https://threatbook.io/ip/121.37.90.137
2026-0 ...
show moreThreatBook Intelligence: IDC,vpn_proxy more details on https://threatbook.io/ip/121.37.90.137
2026-04-05 12:41:14 /wxshare11/wxs.php,{"body":"url=http%3A%2F%2Fnxnews.net%2Fyc%2Fztyx%2F202109%2Ft20210925_7282216.html","content_type":"application/x-www-form-urlencoded","header":{"Accept":["application/json, text/javascript, */*; q=0.01"],"Accept-Encoding":["gzip, deflate"],"Accept-Language":["zh-CN,zh;q=0.9"],"Connection":["keep-alive"],"Content-Length":["73"],"Content-Type":["application/x-www-form-urlencoded; charset=UTF-8"],"Origin":["http://nxnews.net"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"]},"host":"fx.nxnews.net","method":"POST","proto":"HTTP/1.1","remote_addr":"121.37.90.137:45434","status_code":200,"url":"/wxshare11/wxs.php","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"}
2026-04-05 13:24:00 /data/cache/jss.php/xj123/xj/news104024
show less
Web App Attack
Showing 1 to
15
of 18 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ