This IP address has been reported a total of
67
times from
57 distinct
sources.
139.59.130.75 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2026-06-07T14:29:31.886263+02:00 mail postfix/submission/smtpd[233013]: improper command pipelining ...
show more2026-06-07T14:29:31.886263+02:00 mail postfix/submission/smtpd[233013]: improper command pipelining after CONNECT from unknown[139.59.130.75]: \026\003\003\001\245\001\000\001\241\003\003\301Y\006\273\273\360=)$\257\232\210\020\310\226.\314V&\262K\006\367\246?\226;!(\220Us \352\r\323\346G\022~dg\f+\2752\n\n\227\032,Y\233\336\016\217\fy9Xj\314\230\262\363\000\212\000\026\0003\000g\300\236\300\242\000\236\0009\000k\300\237\300\243\000\237
2026-06-07T14:29:32.111818+02:00 mail postfix/submission/smtpd[233013]: improper command pipelining after CONNECT from unknown[139.59.130.75]: \026\003\003\001\245\001\000\001\241\003\003%\2466|\f\036\023L.!\017{\273\225\320\255\223\346\353{\243\207AN\251\215&\235~saE \226@"_\304\v\227k\340f`4)\337\233\2431(\304)\370?|4r\217\373q\331\317\246x\000\212\000\005\000\004\000\a\000\300\000\204\000\272\000A\000\235\300\241\300\235\000=
2026-06-07T14:29:32.327593+02:00 mail postfix/submission/smtpd[233013]: improper command pipelining after CONNECT from unknown
...
show less
2026/06/07 13:58:36 [info] 7081#0: *19876 client sent plain HTTP request to HTTPS port while reading ...
show more2026/06/07 13:58:36 [info] 7081#0: *19876 client sent plain HTTP request to HTTPS port while reading client request headers, client: 139.59.130.75, server: zimbra, request: "GET /query?q=SHOW+DIAGNOSTICS HTTP/1.1", host: "83.238.86.42:443"
...
show less
[2026-06-07 10:18:46] 139.59.130.75 triggered a honeypot. Requested on port 80. URI: /v2/_catalog, U ...
show more[2026-06-07 10:18:46] 139.59.130.75 triggered a honeypot. Requested on port 80. URI: /v2/_catalog, UA: Go-http-client/1.1
...
show less
Bad Web Bot
Brute-Force
Web App Attack
Hacking
SQL Injection
Honeypot [uk-production01]: HTTP/1.1 request on 1911
GET /cgi-bin/authLogin.cgi
User-Agent: Go-http ...
show moreHoneypot [uk-production01]: HTTP/1.1 request on 1911
GET /cgi-bin/authLogin.cgi
User-Agent: Go-http-client/1.1; 1911 [3] TCP
show less
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb.
Events: 1. First: 2026-06-07T ...
show moreAuto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb.
Events: 1. First: 2026-06-07T11:07:01+0200. Last: 2026-06-07T11:07:01+0200.
Samples:
- 2026-06-07 00:27:53,502 fail2ban.actions [1405153]: NOTICE [abuseipdb] Ban 139.59.130.75
show less
Honeypot hit: HTTP/1.1 request on 11434
GET /query?q=SHOW+DIAGNOSTICS
User-Agent: Go-http-client/1. ...
show moreHoneypot hit: HTTP/1.1 request on 11434
GET /query?q=SHOW+DIAGNOSTICS
User-Agent: Go-http-client/1.1; 11434 [3] TCP
Reported by: https://github.com/sefinek/T-Pot-To-AbuseIPDB
show less
2026-06-07T05:42:46.244152 liberator sendmail[1445242]: 6575gGSY1445242: [139.59.130.75] did not iss ...
show more2026-06-07T05:42:46.244152 liberator sendmail[1445242]: 6575gGSY1445242: [139.59.130.75] did not issue MAIL/EXPN/VRFY/ETRN during connection to MSA
...
show less