This IP address has been reported a total of
37
times from
23 distinct
sources.
91.239.104.160 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Blocked by UFW (TCP on 23)
Source port: 49850
TTL: 53
Packet length: 60
TOS: 0x00
This report (for ...
show moreBlocked by UFW (TCP on 23)
Source port: 49850
TTL: 53
Packet length: 60
TOS: 0x00
This report (for 91.239.104.160) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Blocked by fail2ban on o2VPS [23/tcp]
Source Port: 38215
TTL: 46
Packet Length: 60
TOS: 0x00
Analyz ...
show moreBlocked by fail2ban on o2VPS [23/tcp]
Source Port: 38215
TTL: 46
Packet Length: 60
TOS: 0x00
Analyzed by https://ip.wiredalter.com
show less
DDoS flood attack against 82.152.54.0 (2026-08-20 16:18:25 -> 2026-08-20 16:33:25 UTC) targeting AS2 ...
show moreDDoS flood attack against 82.152.54.0 (2026-08-20 16:18:25 -> 2026-08-20 16:33:25 UTC) targeting AS215599. This IP (AS59497) sent ~2160 packets (3.07 MB) during the attack window. Likely a compromised device (botnet).
show less
DDoS flood attack against 46.232.235.0 (2026-08-20 15:59:40 -> 2026-08-20 16:14:40 UTC) targeting AS ...
show moreDDoS flood attack against 46.232.235.0 (2026-08-20 15:59:40 -> 2026-08-20 16:14:40 UTC) targeting AS215599. This IP (AS59497) sent ~1933 packets (2.75 MB) during the attack window. Likely a compromised device (botnet).
show less
DDoS flood attack against 46.232.235.0 (2026-08-20 15:37:20 -> 2026-08-20 15:52:20 UTC) targeting AS ...
show moreDDoS flood attack against 46.232.235.0 (2026-08-20 15:37:20 -> 2026-08-20 15:52:20 UTC) targeting AS215599. This IP (AS59497) sent ~4347 packets (6.18 MB) during the attack window. Likely a compromised device (botnet).
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0
show less
Bad Web Bot
Anonymous
denied traffic to a honeypot network. destination port 23.
UDP flood (DDoS) vs AS215599: 243 pkts / 0.35 MB to UDP 80/8443 across 174 dst IP(s), 2026-08-19 21: ...
show moreUDP flood (DDoS) vs AS215599: 243 pkts / 0.35 MB to UDP 80/8443 across 174 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
UDP flood (DDoS) vs AS215599: 243 pkts / 0.35 MB to UDP 80/8443 across 174 dst IP(s), 2026-08-19 21: ...
show moreUDP flood (DDoS) vs AS215599: 243 pkts / 0.35 MB to UDP 80/8443 across 174 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
Verified scan activity detected by local IDS/firewall correlation. SCAN: HIGHRISK_SINGLEPORT | PORTS ...
show moreVerified scan activity detected by local IDS/firewall correlation. SCAN: HIGHRISK_SINGLEPORT | PORTS=23 | HITS=2 | IPSET=ADD | FIRST=2026-08-19 19:47:38 | LAST=2026-08-19 19:47:39. Last seen 2026-08-19 19:47:39.
show less