AbuseIPDB » 112.94.252.128

112.94.252.128
Recent Activity This IP has received recent abuse reports, which causes the score to increase.
168 reports found in our database
60% Elevated
Abuse confidence score ?
ISP
United-Communications-Network-Technology-Co-Ltd, GuangZhou
Usage Type
Fixed Line ISP
ASN
Domain Name
chinaunicom.cn
Country
🇨🇳 China
City
Guangzhou, Guangdong

IP info including ISP, Usage Type, and Location provided by IPInfo. Updated weekly.

Log in to view charts and search reports for this IP. Log In

Top Reporter Countries (Last 60 Days)

Example preview

Report Categories (Last 60 Days)

Example preview

Reports Activity

Example preview
Account required for the enhanced features Log in Sign up

IP Abuse Reports for 112.94.252.128:

This IP address has been reported a total of 168 times from 61 distinct sources. 112.94.252.128 was first reported on , and the most recent report was . In the last 60 days, the top reporter locations were: United States of America with 13 reports; Mongolia with 3 reports; Germany with 2 reports. The most common categories in these recent reports were: Port Scan 22 times; Web App Attack 3 times; Brute-Force 3 times; Hacking 3 times; Bad Web Bot 2 times; Other 4 times.

Reporter IoA Timestamp (UTC) Comment Categories
🇺🇸 MPL
tcp/20527
Port Scan
🇺🇸 sumnone
Port probing on unauthorized port 9200
Port Scan Hacking Exploited Host
🇺🇸 MPL
tcp/24644
Port Scan
🇫🇷 EvoX
🛡️ Honeypot [bsts-tpot-hive]: Large payload (1457 bytes); 11310 [1] TCP
Bad Web Bot
🇩🇪 _ArminS_
SP-Scan 61169:8447 detected 2026.08.29 07:02:04 blocked until 2026.10.18 00:04:51
Port Scan
Anonymous
MikroTik Enterprise Honeypot
Port Scan
🇺🇸 MPL
tcp/4000 (2 or more attempts)
Port Scan
🇷🇴 abuse_IP_reporter
Aug 24 19:40:32 server UFW BLOCK SRC=112.94.252.128 PROTO=TCP SPT=50541 DPT=16082
Port Scan
🇲🇳 Public CSIRT/CC of Mongolia
Honeypot hit: Empty payload (likely service probe); 6480 [1] TCP
Port Scan
🇲🇳 Public CSIRT/CC of Mongolia
Honeypot hit: Empty payload (likely service probe); 5248 [1] TCP
Port Scan
🇺🇸 RAP
2026-08-12 21:16:25 UTC Unauthorized activity to TCP port 8089. Web App
Port Scan Web App Attack
🇳🇱 COMPLEX
Unsolicited TCP traffic | Action: DROP | Port 27002
Brute-Force
🇺🇸 sandra361
Port Scan
🇺🇸 MPL
tcp/2180
Port Scan
🇺🇸 MPL
tcp/631 (2 or more attempts)
Port Scan

Showing 1 to 15 of 168 reports


Think this IP has been falsely reported? You may request to have the associated reports reviewed and removed. Request Takedown 🚩

Recently Reported IPs:

🇦🇷 201.250.11.121
🇫🇮 147.185.133.4
🇺🇸 136.119.144.165
🇫🇷 135.125.1.158
🇨🇳 222.211.66.73
🇺🇸 216.75.132.215
🇦🇷 201.250.11.179
🇹🇼 198.235.24.72
🇹🇷 180.235.176.207
🇺🇸 143.198.127.95
🇷🇴 143.20.185.204
🇨🇳 110.183.6.88
🇫🇷 91.231.89.239
🇳🇱 77.239.124.201
🇩🇪 69.5.169.129
🇳🇱 45.148.10.157