This IP address has been reported a total of
9
times from
9 distinct
sources.
123.189.128.187 was first reported on
September 27th 2026 , and the most recent report was
41 minutes ago .
In the last 60 days, the top reporter locations were:
Germany
with 2
reports;
United States of America
with 2
reports;
Brazil
with 1
report.
The most common categories in these recent reports were:
Port Scan
7
times;
Brute-Force
4
times;
Hacking
4
times;
IoT Targeted
3
times;
Exploited Host
2
times;
Other
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ฉ๐ช
zupan
2026-10-04 06:21:36
(41 minutes ago)
Blocked by UFW on vps [23/tcp] | SPT: 31985 | TTL: 51 | LEN: 40 | TOS: 0x00 โข Reported by: github.co ...
show more
Blocked by UFW on vps [23/tcp] | SPT: 31985 | TTL: 51 | LEN: 40 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
IoT Targeted
๐ง๐ท
Host One
2026-10-01 16:40:03
(2 days ago)
T-Pot Honeypot alert: 1171 malicious events (exploit_attempt, port_scan, ssh_activity, ssh_bruteforc ...
show more
T-Pot Honeypot alert: 1171 malicious events (exploit_attempt, port_scan, ssh_activity, ssh_bruteforce) detected.
show less
Port Scan
Hacking
Brute-Force
SSH
๐ช๐ธ
whatda
2026-10-01 12:47:34
(2 days ago)
TELNET unauthorized access: "start"
IoT Targeted
Brute-Force
๐บ๐ธ
sumnone
2026-10-01 12:29:50
(2 days ago)
Port probing on unauthorized port 23
Port Scan
Hacking
Exploited Host
Anonymous
2026-09-29 12:30:15
(4 days ago)
1790685014 - 09/29/2026 14:30:14 Host: 123.189.128.187/123.189.128.187 Port: 23 TCP Blocked
...
Port Scan
Anonymous
2026-09-29 04:47:23
(5 days ago)
2026-09-29T06:47:22.316539+02:00 vps kernel: [7028031.361916] [PORTSCAN DETECTED] IN=ens3 OUT= MAC=f ...
show more
2026-09-29T06:47:22.316539+02:00 vps kernel: [7028031.361916] [PORTSCAN DETECTED] IN=ens3 OUT= MAC=fa:16:3e:66:f6:24:02:37:19:0d:c2:f3:08:00 SRC=123.189.128.187 DST=54.37.14.118 LEN=40 TOS=0x00 PREC=0x00 TTL=45 ID=49566 PROTO=TCP SPT=31985 DPT=2323 WINDOW=5626 RES=0x00 SYN URGP=0
...
show less
Port Scan
Brute-Force
๐บ๐ธ
RAP
2026-09-28 16:22:55
(5 days ago)
2026-09-28 16:22:55 UTC Unauthorized activity to TCP port 23. Telnet
Port Scan
Anonymous
2026-09-28 05:08:12
(6 days ago)
denied traffic to a honeypot network. destination port 23.
Port Scan
Hacking
๐ซ๐ฎ
Birdo
2026-09-27 06:08:13
(1 week ago)
[Honeypot Report] Attempted malware delivery following Telnet intrusion
An automated malware loader ...
show more
[Honeypot Report] Attempted malware delivery following Telnet intrusion
An automated malware loader brute-forced our emulated Telnet service, then obtained shell access and executed commands, and finally attempted to retrieve a remote payload. Credentials and request paths match DVR / IP camera (OEM default).
Observed: 2026-09-27 05:40 to 2026-09-27 06:08 UTC | 11 sessions | 176 events | Telnet (port 23)
Attack chain:
1. 11 credential attempts: root/888888, 888888/888888, root/1234567890, telnet/telnet, default/default (+6 more pairs)
2. Shell access obtained; 11 distinct commands executed: start ; enable ; config terminal
3. Payload retrieval attempted from: http://175.150.93.234:32800/i
Full evidence: https://github.com/1Birdo/lyrebird-intel/blob/main/incidents/2026/09/123.189.128.187.md
Reported by birdo.uk (Lyrebird honeypot lyrebird-01). Emulated service - no host was compromised.
show less
Exploited Host
Hacking
IoT Targeted
Brute-Force
Showing 1 to
9
of 9 reports