This IP address has been reported a total of
27
times from
18 distinct
sources.
165.101.42.147 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 9
reports;
Germany
with 2
reports;
Switzerland
with 1
report.
The most common categories in these recent reports were:
Bad Web Bot
12
times;
DDoS Attack
6
times;
Web App Attack
2
times;
Exploited Host
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Fail2Ban: 165.101.42.147 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5 ...
show moreFail2Ban: 165.101.42.147 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0. ...
show moreMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
show less
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0. ...
show moreMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
show less
Repeated requests classified as pathological web bot behavior, for example: /search?f%5B0%5D=key_ter ...
show moreRepeated requests classified as pathological web bot behavior, for example: /search?f%5B0%5D=key_terms%3A311&f%5B10%5D=key_terms%3A525&f%5B11%5D=key_terms%3A543&f%5B12%5D=key_terms%3A718&f%5B1%5D=key_terms%3A312&f%5B2%5D=key_terms%3A316&f%5B3%5D=key_terms%3A317&f%5B4%5D=key_terms%3A318&f%5B5%5D=key_terms%3A325&f%5B6%5D=key_terms%3A336&f%5B7%5D=key_terms%3A519&f%5B8%5D=key_terms%3A522&f%5B9%5D=key_terms%3A524 (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36")
show less
Botnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18: ...
show moreBotnet UDP flood (DDoS) against a host in AS203136 (LLC Ordunet), Georgia, on 2026-09-09 between 18:00 and 19:30 local time (+04:00). This source sent UDP to port 47472 of 185.143.177.x at more than 800 packets/sec. Nothing listens on that port - repeated full packet captures of all traffic reaching this machine recorded its services on other UDP ports and never a single packet to 47472 - so this cannot be a client of anything; it is flood by definition, independent of any rate measurement. One of 2743 sources in 1270 networks and 136 countries in the same wave. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. The host is almost certainly compromised and part of a botnet. Evidence: [email protected].
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36
show less
KelvaTLS: TCP connection-limit abuse against TCP port 1194 on our infrastructure. nft veil1194off_ra ...
show moreKelvaTLS: TCP connection-limit abuse against TCP port 1194 on our infrastructure. nft veil1194off_rate: opened new connections to the OpenVPN listener faster than the per-source limit permits from this source. UTC 2026-08-27T03:40:12Z. incident kelva-20260827-025741Z.
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36
show less