This IP address has been reported a total of
22
times from
19 distinct
sources.
160.30.181.252 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
Blocked by firewall on hugin [22/tcp] | Rule: UFW | SPT: 49052 | TTL: 52 | LEN: 60 | TOS: 0x00 โข Rep ...
show moreBlocked by firewall on hugin [22/tcp] | Rule: UFW | SPT: 49052 | TTL: 52 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
UDP flood (DDoS) vs AS215599: 624 pkts / 0.89 MB to UDP 80/8443 across 221 dst IP(s), 2026-08-19 21: ...
show moreUDP flood (DDoS) vs AS215599: 624 pkts / 0.89 MB to UDP 80/8443 across 221 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
UDP flood (DDoS) vs AS215599: 624 pkts / 0.89 MB to UDP 80/8443 across 221 dst IP(s), 2026-08-19 21: ...
show moreUDP flood (DDoS) vs AS215599: 624 pkts / 0.89 MB to UDP 80/8443 across 221 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
Verified scan activity detected by local IDS/firewall correlation. SCAN: HIGHRISK_SINGLEPORT | PORTS ...
show moreVerified scan activity detected by local IDS/firewall correlation. SCAN: HIGHRISK_SINGLEPORT | PORTS=22 | HITS=2 | IPSET=ADD | FIRST=2026-08-17 04:08:04 | LAST=2026-08-17 04:08:05. Last seen 2026-08-17 04:08:05.
show less
Blocked by UFW (TCP on 22)
Source port: 35828
TTL: 49
Packet length: 60
TOS: 0x08
This report (for ...
show moreBlocked by UFW (TCP on 22)
Source port: 35828
TTL: 49
Packet length: 60
TOS: 0x08
This report (for 160.30.181.252) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
2026-08-14T10:52:00.966974 rhel-20gb-ash-1 sshd[2002292]: error: kex_exchange_identification: Connec ...
show more2026-08-14T10:52:00.966974 rhel-20gb-ash-1 sshd[2002292]: error: kex_exchange_identification: Connection closed by remote host
2026-08-14T10:52:00.967005 rhel-20gb-ash-1 sshd[2002292]: Connection closed by 160.30.181.252 port 42024
...
show less
Brute-Force
SSH
Anonymous
denied traffic to a honeypot network. destination port 22.
Auto-blocked by Seczar SecureOps โ High-Risk Port Probe (admin-managed entries) โ SSH (5 events in 5 ...
show moreAuto-blocked by Seczar SecureOps โ High-Risk Port Probe (admin-managed entries) โ SSH (5 events in 5min) at 2026-08-12 08:59
show less
DDOS from known botnet. Scraping ai1ec data from wordpress website. Using randomly generated user ag ...
show moreDDOS from known botnet. Scraping ai1ec data from wordpress website. Using randomly generated user agents.
show less
[Askari] | Behavior: HTTP/1.1 over TLS, Outdated browser, Concurrent page load during attack, Slow-r ...
show more[Askari] | Behavior: HTTP/1.1 over TLS, Outdated browser, Concurrent page load during attack, Slow-read attack, Targeting specific pages
show less
Bad Web Bot
DDoS Attack
Showing 1 to
15
of 22 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ