AbuseIPDB » 108.196.85.215

108.196.85.215 was found in our database!

This IP was reported 81 times. Confidence of Abuse is 100%: ?

100%
ISP AT&T Enterprises, LLC
Usage Type Fixed Line ISP
ASN AS7018
Hostname(s) 108-196-85-215.lightspeed.irvnca.sbcglobal.net
Domain Name att.com
Country ๐Ÿ‡บ๐Ÿ‡ธ United States of America
City Irvine, California

IP info including ISP, Usage Type, and Location provided by IPInfo. Updated weekly.

IP Abuse Reports for 108.196.85.215:

This IP address has been reported a total of 81 times from 53 distinct sources. 108.196.85.215 was first reported on , and the most recent report was .

Recent Reports: We have received reports of abusive activity from this IP address within the last week. It is potentially still actively engaged in abusive activities.

Reporter IoA Timestamp (UTC) Comment Categories
๐Ÿ‡ซ๐Ÿ‡ท adnscom.net
IPS trigger: Brute force SSH scanning/attack
Brute-Force SSH
๐Ÿ‡ฉ๐Ÿ‡ช von44bis33
Cowrie SSH honeypot: unauthorized login attempts/commands observed.
Brute-Force SSH
๐Ÿ‡ง๐Ÿ‡ท noconex
Port Scan Brute-Force SSH
๐Ÿ‡บ๐Ÿ‡ธ MPL
tcp ports: 22,23 (8 or more attempts)
Port Scan
๐Ÿ‡ฎ๐Ÿ‡ณ evicky2002
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking Brute-Force SSH
๐Ÿ‡บ๐Ÿ‡ธ HamSammich
Automated sensor: 2 SSH connection/probe attempts over the last 24h (latest 2026-08-27T04:55Z).
Brute-Force SSH
๐Ÿ‡ฆ๐Ÿ‡น urnilxfgbez
Last 24 Hours suspicious: (DPT=445|DPT=3389|DPT=22|DPT=3306|DPT=8080|DPT=23|DPT=5900|DPT=1433)
Port Scan
๐Ÿ‡บ๐Ÿ‡ธ NetVexor
Attack source identified and submitted via NetVexor BGP Blackhole Network
Port Scan Hacking Brute-Force
Anonymous
AS7018: 108.192.0.0/13 - AT&T Enterprises, LLC (US)
Port Scan
Anonymous
denied traffic to a honeypot network. destination port 23.
Port Scan Hacking
๐Ÿ‡ฌ๐Ÿ‡ง dwmosaics
refused connect from 108.196.85.215 (108.196.85.215)
Brute-Force SSH
๐Ÿ‡บ๐Ÿ‡ธ ne1for23
Unauthorized access to SSH at 26/Aug/2026:00:56:35 +0000.
Port Scan SSH
๐Ÿ‡บ๐Ÿ‡ธ RAP
2026-08-25 11:25:07 UTC Unauthorized activity to TCP port 22. SSH
SSH
๐Ÿ‡ฎ๐Ÿ‡น CoreTech srl
[DC: IP:151.1.252.27] ntopng alert: blacklisted_client_contact
Hacking
๐Ÿ‡ฆ๐Ÿ‡น urnilxfgbez
Last 24 Hours suspicious: (DPT=445|DPT=3389|DPT=22|DPT=3306|DPT=8080|DPT=23|DPT=5900|DPT=1433)
Port Scan

Showing 1 to 15 of 81 reports


Think this IP has been falsely reported? You may request to have the associated reports reviewed and removed. Request Takedown ๐Ÿšฉ

Recently Reported IPs:

๐Ÿ‡ท๐Ÿ‡บ 178.67.214.197
๐Ÿ‡บ๐Ÿ‡ธ 147.185.132.54
๐Ÿ‡ฉ๐Ÿ‡ช 89.246.164.172
๐Ÿ‡ณ๐Ÿ‡ฑ 185.242.226.73
๐Ÿ‡ณ๐Ÿ‡ฑ 185.38.142.195
๐Ÿ‡ฎ๐Ÿ‡ณ 139.5.198.26
๐Ÿ‡ฐ๐Ÿ‡ท 112.164.195.219
๐Ÿ‡ณ๐Ÿ‡ฑ 94.154.43.104
๐Ÿ‡บ๐Ÿ‡ธ 40.119.37.54
๐Ÿ‡น๐Ÿ‡ผ 221.120.57.172
๐Ÿ‡ณ๐Ÿ‡ฑ 213.227.139.244
๐Ÿ‡บ๐Ÿ‡ธ 207.180.11.166
๐Ÿ‡ต๐Ÿ‡ฑ 178.219.104.100
๐Ÿ‡ฎ๐Ÿ‡ฉ 139.255.254.163
๐Ÿ‡ง๐Ÿ‡ฉ 114.130.85.36
๐Ÿ‡ฎ๐Ÿ‡ฉ 103.59.160.52
๐Ÿ‡บ๐Ÿ‡ธ 99.64.165.99
๐Ÿ‡บ๐Ÿ‡ธ 73.43.184.216
๐Ÿ‡ฉ๐Ÿ‡ช 69.5.169.9