AbuseIPDB » 159.223.101.104

159.223.101.104 was found in our database!

This IP was reported 19 times. Confidence of Abuse is 87%: ?

87%
ISP DigitalOcean, LLC
Usage Type Data Center/Web Hosting/Transit
ASN AS14061
Domain Name digitalocean.com
Country ๐Ÿ‡บ๐Ÿ‡ธ United States of America
City North Bergen, New Jersey

IP info including ISP, Usage Type, and Location provided by IPInfo. Updated weekly.

IP Abuse Reports for 159.223.101.104:

This IP address has been reported a total of 19 times from 16 distinct sources. 159.223.101.104 was first reported on , and the most recent report was .

Recent Reports: We have received reports of abusive activity from this IP address within the last week. It is potentially still actively engaged in abusive activities.

Reporter IoA Timestamp (UTC) Comment Categories
๐Ÿ‡ฌ๐Ÿ‡ง gbzret4d
Honeypot [uk-production01]: Empty payload (likely service probe); 27019 [14] TCP
Port Scan
๐Ÿ‡ฒ๐Ÿ‡ณ Public CSIRT/CC of Mongolia
Honeypot hit: Empty payload (likely service probe); 9203 [14] TCP
Port Scan
๐Ÿ‡ณ๐Ÿ‡ฑ donarev419
Connection to port 10086 with data transfer. Data preview:
Port Scan Hacking
๐Ÿ‡บ๐Ÿ‡ธ drewf.ink
[00:12] Port scanning. Port(s) scanned: TCP/9300
Port Scan
๐Ÿ‡ฌ๐Ÿ‡ง gbzret4d
Honeypot [uk-production01]: Unauthorized traffic (4 bytes of payload); 15672 [13] TCP
Port Scan
๐Ÿ‡ฆ๐Ÿ‡ช abusiveIntelligence
RDP connect attempt: Nmap Scanner
Brute-Force
๐Ÿ‡ซ๐Ÿ‡ท TheHoneyPotter
Port Scan
๐Ÿ‡ฉ๐Ÿ‡ช guldkage
Unauthorized connection attempt detected from IP address 159.223.101.104 to port 1434 (ger-03) [h]
Brute-Force Exploited Host
๐Ÿ‡ง๐Ÿ‡ท somosbr
[2026-06-20T08:03:13Z] Unsolicited scan from 159.223.101.104 to port 300/tcp
Port Scan
๐Ÿ‡ฉ๐Ÿ‡ช _ArminS_
SP-Scan 31845:9300 detected 2026.06.20 09:51:48 blocked until 2026.08.09 02:54:35
Port Scan
๐Ÿ‡ฉ๐Ÿ‡ช Axel
[2026-06-20 05:52:38 UTC] Honeypot Elasticsearch Alt connection attempt | AXFRA HONEYPOT
Hacking
๐Ÿ‡ฉ๐Ÿ‡ช dispaisyenterprises
Port Scan
Anonymous
Heralding honeypot: mysql on port 3306
Brute-Force
๐Ÿ‡จ๐Ÿ‡ฆ dpinse
Honeypot [honeypot-ca-sensor1]: MSSQL traffic (on 1433) without login credentials
Port Scan
๐Ÿ‡บ๐Ÿ‡ธ drewf.ink
[14:05] Port scanning. Port(s) scanned: TCP/5984
Port Scan

Showing 1 to 15 of 19 reports


Think this IP has been falsely reported? You may request to have the associated reports reviewed and removed. Request Takedown ๐Ÿšฉ

Recently Reported IPs:

๐Ÿ‡ฒ๐Ÿ‡ฝ 187.190.35.163
๐Ÿ‡ธ๐Ÿ‡ฌ 172.217.47.25
๐Ÿ‡ณ๐Ÿ‡ฟ 103.75.11.188
๐Ÿ‡จ๐Ÿ‡ณ 222.129.37.92
๐Ÿ‡ฎ๐Ÿ‡ฉ 103.59.94.61
๐Ÿ‡ง๐Ÿ‡ฌ 94.155.124.98
๐Ÿ‡ธ๐Ÿ‡ฌ 43.159.51.254
๐Ÿ‡ฐ๐Ÿ‡ท 43.155.134.4
๐Ÿ‡จ๐Ÿ‡ณ 27.17.182.108
๐Ÿ‡บ๐Ÿ‡ธ 20.169.107.174
๐Ÿ‡บ๐Ÿ‡ธ 2a04:c300:400::1ce
๐Ÿ‡ซ๐Ÿ‡ท 176.171.152.211
๐Ÿ‡ธ๐Ÿ‡ฌ 165.154.200.48
๐Ÿ‡บ๐Ÿ‡ธ 134.122.125.153
๐Ÿ‡ง๐Ÿ‡ฌ 78.128.114.102
๐Ÿ‡บ๐Ÿ‡ธ 76.33.73.139
๐Ÿ‡ฉ๐Ÿ‡ช 167.94.146.46
๐Ÿ‡จ๐Ÿ‡ณ 153.0.82.52
๐Ÿ‡ธ๐Ÿ‡ฌ 152.42.177.64