AbuseIPDB » 167.94.138.112

167.94.138.112 was found in our database!

This IP was reported 4,445 times. Confidence of Abuse is 0%: ?

0%
ISP Censys, Inc.
Usage Type Commercial
ASN AS398324
Hostname(s) scanner-27.ch1.censys-scanner.com
Domain Name censys.com
Country United States of America
City Chicago, Illinois

IP info including ISP, Usage Type, and Location provided by IPInfo. Updated biweekly.


Important Note: 167.94.138.112 is an IP address from within our whitelist belonging to the subnet 167.94.138.0/24, which we identify as: "Censys (https://about.censys.io/)".

Whitelisted netblocks are typically owned by trusted entities, such as Google or Microsoft who may use them for search engine spiders. However, these same entities sometimes also provide cloud servers and mail services which are easily abused. Pay special attention when trusting or distrusting these IPs.

IP Abuse Reports for 167.94.138.112:

This IP address has been reported a total of 4,445 times from 530 distinct sources. 167.94.138.112 was first reported on , and the most recent report was .

Recent Reports: We have received reports of abusive activity from this IP address within the last week. It is potentially still actively engaged in abusive activities.

Reporter IoA Timestamp in UTC Comment Categories
YaRi78
Unsolicited postgresql connection attempt from 167.94.138.112 detected
Port Scan
StatsMe
2025-06-09T00:16:37.418099+0300
ET DROP Dshield Block Listed Source group 1
Port Scan Hacking Spoofing Brute-Force
oonux.net
RouterOS: Scanning detected TCP 167.94.138.112:58914 > x.x.x.x:8893
Port Scan
MPL
tcp/9933 (6 or more attempts)
Port Scan
sid3windr
SSH port scan (Tarpitted for 20s, wasted 7B)
Port Scan SSH
drewf.ink
[18:10] Port scanning. Port(s) scanned: TCP/5060
Port Scan
Axel
Brute-Force SSH
diego
Web App Attack
6kilowatti
Port Scan
tedmichalik.com
Web App Attack
sefinek.net
Honeypot hit: Empty payload (likely service probe); 5391 [3] TCP
Port Scan
Brian Minton
Brute-Force
mkaraki
1749450026 # Service_probe # SIGNATURE_SEND # source_ip:167.94.138.112 # dst_port:10001
...
Port Scan
webbfabriken
Web Spam
COMPLEX
Honeypot [1]: Empty payload (likely service probe); 32474 [1] TCP
Port Scan

Showing 106 to 120 of 4445 reports


Is this your IP? You may request to takedown any associated reports. We will attempt to verify your ownership. Request Takedown 🚩

Recently Reported IPs: