This IP address has been reported a total of
16
times from
13 distinct
sources.
138.121.113.175 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0. ...
show moreMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Fail2Ban: 138.121.113.175 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/ ...
show moreFail2Ban: 138.121.113.175 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
show less
UDP flood (DDoS) vs AS215599: 10 pkts / 0.01 MB to UDP 80/8443 across 9 dst IP(s), 2026-08-19 21:46 ...
show moreUDP flood (DDoS) vs AS215599: 10 pkts / 0.01 MB to UDP 80/8443 across 9 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
UDP flood (DDoS) vs AS215599: 10 pkts / 0.01 MB to UDP 80/8443 across 9 dst IP(s), 2026-08-19 21:46 ...
show moreUDP flood (DDoS) vs AS215599: 10 pkts / 0.01 MB to UDP 80/8443 across 9 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show moreDistributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in printer-friendly.asp
show less
UDP flood attack on 31.56.58.1 UDP:22 (2026-08-15 17:53-18:05 UTC). Peak aggregate 47 Gbps / 4.2 Mpp ...
show moreUDP flood attack on 31.56.58.1 UDP:22 (2026-08-15 17:53-18:05 UTC). Peak aggregate 47 Gbps / 4.2 Mpps against victim AS215599. This IP (AS263791) sent ~46197 packets (63.88 MB) during the attack window. Likely a compromised device (Mirai-like botnet).
show less
(imapd) Failed IMAP login from 138.121.113.175 (AR/Argentina/Formosa/Formosa/-/[AS263791 REFSA TELEC ...
show more(imapd) Failed IMAP login from 138.121.113.175 (AR/Argentina/Formosa/Formosa/-/[AS263791 REFSA TELECOMUNICACIONES]): 1 in the last 3600 secs
show less
Large-scale coordinated botnet (777+k IPs). Attacker: mikhail-smirnov-79830323 (LinkedIn/profile ID) ...
show moreLarge-scale coordinated botnet (777+k IPs). Attacker: mikhail-smirnov-79830323 (LinkedIn/profile ID) employed by Angara Technologies Group (Explicitly identified himself as enemy a week before attack began) | Attack Signature Blocked: /wishlist/index/add/product/4192/form_key/SD6MXzMYyMPTYe9D/ | UA: Mozilla/5.0 (iPod; U; CPU iPhone OS 4_0 like Mac OS X; ar-EG) AppleWebKit/534.13.5 (KHTML, like Gecko) Version/3.0.5 Mobile/8B119 Safari/6534.13.5 | (Magento Site)
show less