This IP address has been reported a total of
14
times from
8 distinct
sources.
157.66.128.164 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 5
reports;
Canada
with 1
report;
Italy
with 1
report.
The most common categories in these recent reports were:
Bad Web Bot
7
times;
DDoS Attack
3
times;
Web App Attack
2
times;
Blog Spam
1
time;
Web Spam
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Repeated requests classified as pathological web bot behavior, for example: /[redacted]?topics%5B3%5 ...
show moreRepeated requests classified as pathological web bot behavior, for example: /[redacted]?topics%5B3%5D=89&topics%5B4%5D=39&topics%5B5%5D=43&topics%5B6%5D=69 (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36")
show less
Web spam bot from 157.66.128.164: automated HTTPS requests for fake pharmacy / prescription / drug S ...
show moreWeb spam bot from 157.66.128.164: automated HTTPS requests for fake pharmacy / prescription / drug SEO URLs (bbs and blog product-style paths). 2 hits; paths: /blogs/naughtyaccessories/Nuvigil-Purchase-Uk-Delivery">can.
show less
Fail2Ban: 157.66.128.164 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5 ...
show moreFail2Ban: 157.66.128.164 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
show less
This IP accessed the path /Byrd-Station/Byrd/src/commit/378acf97a03dae13e04742f6a72942ae64d98d16/.en ...
show moreThis IP accessed the path /Byrd-Station/Byrd/src/commit/378acf97a03dae13e04742f6a72942ae64d98d16/.envrc, which is banned. Powered by ListenCaddy
show less
Repeated requests classified as pathological web bot behavior, for example: /[redacted]?topics%5B1%5 ...
show moreRepeated requests classified as pathological web bot behavior, for example: /[redacted]?topics%5B1%5D=64&topics%5B3%5D=50&topics%5B4%5D=25&topics%5B5%5D=61 (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36")
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
show less
06/24/2026-20:24:57.324738 [Drop] [**] [1:921373:1] Suricata Dibuat Gemini TCP SYN port scanner - W ...
show more06/24/2026-20:24:57.324738 [Drop] [**] [1:921373:1] Suricata Dibuat Gemini TCP SYN port scanner - Win 65535 [**] [Classification: (null)] [Priority: 3] {TCP} 157.66.128.164:59424 -> 103.166.156.58:443
...
show less
Distributed application-layer DoS against git.mills.io (self-hosted Gitea). High-volume automated re ...
show moreDistributed application-layer DoS against git.mills.io (self-hosted Gitea). High-volume automated requests to expensive Git repository endpoints (commit/diff/blame/archive views), ~1 request per IP, spoofed browser UA, rejected with HTTP 429. Residential-proxy botnet campaign, 2026-06-13/14 UTC.
show less