This IP address has been reported a total of
20
times from
17 distinct
sources.
159.89.14.14 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 3
reports;
United Kingdom of Great Britain and Northern Ireland
with 2
reports;
Azerbaijan
with 1
report.
The most common categories in these recent reports were:
DDoS Attack
4
times;
Brute-Force
3
times;
SSH
2
times;
Bad Web Bot
1
time;
Port Scan
1
time;
Other
4
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Honeypot trap triggered: unsolicited TCP connection(s) to unused port(s) 23 on a host running no suc ...
show moreHoneypot trap triggered: unsolicited TCP connection(s) to unused port(s) 23 on a host running no such service. There is no legitimate reason to connect to these ports.
Observed 3 connection(s) from 2026-10-04T20:28:47Z to 2026-10-04T20:28:49Z UTC.
2026-10-04T20:28:47Z tcp/23 connect, no payload (bare TCP probe)
2026-10-04T20:28:49Z tcp/23 connect, no payload (bare TCP probe)
2026-10-04T20:28:50Z tcp/23 connect, no payload (bare TCP probe)
Connection was blocked automatically at the firewall. Reported by an automated honeypot.
show less
Malicious activity detected from 14061 DigitalOcean, LLC towards host sillydev.co.uk (GET HTTP/2) @ ...
show moreMalicious activity detected from 14061 DigitalOcean, LLC towards host sillydev.co.uk (GET HTTP/2) @ 2026-10-04T21:44:43Z (2 occurrences)
show less
2026-10-02T13:49:06.053009+03:30 digitalogic sshd-session[1021368]: pam_unix(sshd:auth): authenticat ...
show more2026-10-02T13:49:06.053009+03:30 digitalogic sshd-session[1021368]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=159.89.14.14
2026-10-02T13:49:08.193165+03:30 digitalogic sshd-session[1021368]: Failed password for invalid user Admin from 159.89.14.14 port 35880 ssh2
2026-10-02T13:49:09.934773+03:30 digitalogic sshd-session[1021368]: Connection closed by invalid user Admin 159.89.14.14 port 35880 [preauth]
...
show less
Participated in a distributed HTTP flood (L7 DDoS) against 10x.gg on 2026-10-02 08:19:25-08:20:09 UT ...
show moreParticipated in a distributed HTTP flood (L7 DDoS) against 10x.gg on 2026-10-02 08:19:25-08:20:09 UTC. 518 requests from this IP to a single API endpoint (GET .../funding), HTTP/2 via Cloudflare (CF-Connecting-IP), spoofed browser UA + rotated referrers. nginx rate-limited (HTTP 429). First seen 2026-10-02T08:19:25+00:00. Part of a 1,572-IP rented-proxy pool; this IP had no other traffic to the site that day.
show less
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 159.89.14.14 (DE/Germany/-): 1 in the ...
show more(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 159.89.14.14 (DE/Germany/-): 1 in the last 3600 secs (0-195)
show less
Unwanted traffic detected by honeypot on March 02, 2026: port scans (1 port 22 scan), and brute forc ...
show moreUnwanted traffic detected by honeypot on March 02, 2026: port scans (1 port 22 scan), and brute force and hacking attacks (9 over ssh).
show less
2026-03-02T08:30:37.930255+00:00 ip-172-31-5-127 sshd[1023205]: Connection closed by authenticating ...
show more2026-03-02T08:30:37.930255+00:00 ip-172-31-5-127 sshd[1023205]: Connection closed by authenticating user root 159.89.14.14 port 42810 [preauth]
2026-03-02T08:31:23.681598+00:00 ip-172-31-5-127 sshd[1023226]: Connection closed by authenticating user root 159.89.14.14 port 35384 [preauth]
2026-03-02T08:32:08.804585+00:00 ip-172-31-5-127 sshd[1023240]: Connection closed by authenticating user root 159.89.14.14 port 59332 [preauth]
...
show less
2026-03-02T02:30:45.769163 nas.marchenko.net sshd-session[571091]: Failed password for root from 159 ...
show more2026-03-02T02:30:45.769163 nas.marchenko.net sshd-session[571091]: Failed password for root from 159.89.14.14 port 35440 ssh2
2026-03-02T02:31:31.013575 nas.marchenko.net sshd-session[572203]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=159.89.14.14 user=root
2026-03-02T02:31:33.625477 nas.marchenko.net sshd-session[572203]: Failed password for root from 159.89.14.14 port 59762 ssh2
...
show less