AbuseIPDB » 159.65.234.89
IP info including ISP, Usage Type, and Location provided by IPInfo. Updated weekly.
Top Reporter Countries (Last 60 Days)
Example previewReport Categories (Last 60 Days)
Example previewIP Abuse Reports for 159.65.234.89:
This IP address has been reported a total of 80 times from 45 distinct sources. 159.65.234.89 was first reported on , and the most recent report was . In the last 60 days, the top reporter locations were: United States of America with 39 reports; Germany with 11 reports; Brazil with 4 reports. The most common categories in these recent reports were: Port Scan 69 times; Hacking 13 times; Brute-Force 8 times; Web App Attack 4 times; DNS Poisoning 1 time; Other 4 times.
| Reporter | IoA Timestamp (UTC) | Comment | Categories | |
|---|---|---|---|---|
| 🇺🇸 RAP |
2026-09-06 09:40:20 UTC Unauthorized activity to TCP port 8443. Web App
|
Port Scan Web App Attack | ||
| 🇺🇸 xmission.com |
|
Port Scan | ||
| 🇺🇸 gu-alvareza |
Nmap.Script.Scanner
|
Port Scan | ||
| Anonymous |
tls scan
|
Port Scan | ||
| 🇩🇪 pigro |
|
Web App Attack | ||
| 🇩🇪 wlt-blocker |
Illegal port scans
|
Port Scan | ||
| 🇺🇸 MPL |
tcp/443 (2 or more attempts)
|
Port Scan | ||
| 🇦🇺 2000cn.com.au |
This IP was detected by CrowdSec triggering crowdsecurity/http-cve-probing
|
Web App Attack Hacking | ||
| 🇦🇺 LiftUp Hosting |
Honeypot hit: Empty payload (likely service probe); 62078 [39] TCP
|
Port Scan | ||
| 🇷🇸 Scan |
MultiHost/MultiPort Probe, Scan, Hack -
|
Port Scan Hacking | ||
| 🇸🇬 drewf.ink |
[22:11] Port scanning. Port(s) scanned: TCP/50070
|
Port Scan | ||
| 🇸🇪 NordhTech |
More than 3 malicious connection attempts, trying port(s) 3389/tcp, then blocked from services ...
|
Port Scan Hacking | ||
| 🇩🇪 Jochen Pretli |
connection to honeypot
|
Email Spam Port Scan | ||
| 🇺🇸 xmission.com |
|
Port Scan | ||
| 🇺🇸 xmission.com |
|
Port Scan |
Think this IP has been falsely reported? You may request to have the associated reports reviewed and removed. Request Takedown 🚩