Report for IP: 27.150.128.157

Threat LevelCRITICAL80/1001 rule type
1 incident on record · last seen 31d ago
PTR 157.128.150.27.broad.xm.fj.dynamic.163data.com.cn
Org / ASN Chinanet FJ
Country 🇨🇳 China
City Xiamen, Fujian
Timezone Asia/Shanghai
Botnet InfrastructureChinaNet (AS4134, China Telecom)
ChinaNet (AS4134) is one of the highest-volume attack-originating ASNs globally, consistently ranking in SANS/DShield top-10 attacker lists. Activity ranges from compromised consumer endpoints to dedicated scan infrastructure. SSH brute-force from this network targets common username dictionaries at scale — automated, persistent credential-harvesting botnet behavior.

Attack Analysis

🇨🇳 China · Xiamen · 133776 · CHINANET FUJIAN PROVINCE NETWORK
Bad Bot Flood
This IP generated over 20 HTTP 4xx errors in 60 seconds using a User-Agent identified as a bad bot (scraper, headless browser, or attack proxy). The high error rate indicates automated probing for vulnerabilities while trying to appear as generic traffic. Legitimate services respect robots.txt and do not flood servers with errors.

Reports (1)

Date Severity Description
1 Jul 2026 - 08:52 high Web: Bad bot 4xx flood — 20+ errors in 60s