This IP address has been reported a total of
21
times from
14 distinct
sources.
157.66.175.39 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 2
reports;
Indonesia
with 1
report.
The most common categories in these recent reports were:
Bad Web Bot
2
times;
DDoS Attack
1
time;
Hacking
1
time;
Email Spam
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36
show less
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show moreDistributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in thread-skip.asp
show less
Bad web bot: Spoofed/obsolete UA (Mozilla/5.0 (Macintosh; U; PPC Mac OS X 10_10_7 rv:3.0; lb-LU) App ...
show moreBad web bot: Spoofed/obsolete UA (Mozilla/5.0 (Macintosh; U; PPC Mac OS X 10_10_7 rv:3.0; lb-LU) AppleWebKit/534.2.6 (KHTML; like Gecko) Version/5.0 Safari/534.2.6). Mass-scanning WordPress plugin. Coordinated large-scale bot attack.
show less
Bad web bot: Spoofed/obsolete UA (Mozilla/5.0 (Macintosh; PPC Mac OS X 10_12_9 rv:4.0; nb-NO) AppleW ...
show moreBad web bot: Spoofed/obsolete UA (Mozilla/5.0 (Macintosh; PPC Mac OS X 10_12_9 rv:4.0; nb-NO) AppleWebKit/533.10.1 (KHTML; like Gecko) Version/5.0.2 Safari/533.10.1). Mass-scanning WordPress plugin. Coordinated large-scale bot attack.
show less
Malformed or malicious web request
157.66.175.39 - - [16/Apr/2026:12:28:08 +0200] "POST /xmlrpc.php ...
show moreMalformed or malicious web request
157.66.175.39 - - [16/Apr/2026:12:28:08 +0200] "POST /xmlrpc.php HTTP/1.1" 404 4187 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
Anonymous
2026-04-12T13:49:56.557726+02:00 zanati wp(www.sahpa.co.za)[1210920]: Blocked authentication attempt ...
show more2026-04-12T13:49:56.557726+02:00 zanati wp(www.sahpa.co.za)[1210920]: Blocked authentication attempt for [email protected] from 157.66.175.39
...
show less
[Mon Oct 20 08:27:27.975853 2025] [security2:error] [pid 317660:tid 139643199645376] [client 157.66. ...
show more[Mon Oct 20 08:27:27.975853 2025] [security2:error] [pid 317660:tid 139643199645376] [client 157.66.175.39:50109] ModSecurity: Access denied with code 403 (phase 1). Match of "pm matomo.staklim-malang.info " against "SERVER_NAME" required. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "164"] [id "440235"] [msg "BAD REQUEST Bro"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: format= found within SERVER_NAME: staklim-jatim.bmkg.go.id request_line = GET /index.php/using-joomla/extensions/components/search-component/search?searchword=ANalisis%20Hujan%20Bulanan&searchphrase=all&format=opensearch HTTP/2.0 Request URI RAW = /index.php/using-joomla/extensions/components/search-component/search?searchword=ANalisis%20Hujan%20Bulanan&searchphrase=all&format=opensearch Request Base..."] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/using-joomla/extensions/components/search-c
...
show less
LF_IMAPD: (imapd) Failed IMAP login from 157.66.175.39 (ID/Indonesia/39.175.as152749): 1 in the last ...
show moreLF_IMAPD: (imapd) Failed IMAP login from 157.66.175.39 (ID/Indonesia/39.175.as152749): 1 in the last 3600 secs
show less