This IP address has been reported a total of
5
times from
5 distinct
sources.
47.149.254.38 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 2
reports;
Czechia
with 1
report;
France
with 1
report.
The most common categories in these recent reports were:
DDoS Attack
2
times;
Brute-Force
2
times;
Bad Web Bot
2
times;
Exploited Host
2
times;
VPN IP
1
time;
Other
2
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36
show less
Botnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordu ...
show moreBotnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordunet), Georgia, on 2026-09-15 from 14:17 local time (+04:00). This source sustained more than 800 packets/sec toward a single UDP port, against about 200 packets/sec for a legitimate player of that server. It was one of 8847 sources in 2396 networks and 160 countries recorded inside a single 25-minute window - the server's entire real audience is about a hundred players. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. Not a scan and not brute force - a packet flood, so the host is most likely compromised. Evidence: [email protected].
show less
UDP flood (DDoS) vs AS215599: 99 pkts / 0.14 MB to UDP 8443 across 52 dst IP(s), 2026-08-19 21:46 to ...
show moreUDP flood (DDoS) vs AS215599: 99 pkts / 0.14 MB to UDP 8443 across 52 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
DDoS Attack
Exploited Host
Showing 1 to
5
of 5 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ