AbuseIPDB » 167.94.138.203
167.94.138.203 was found in our database!
This IP was reported 4,549 times. Confidence of Abuse is 0%: ?
ISP | Censys, Inc. |
---|---|
Usage Type | Commercial |
ASN | AS398324 |
Domain Name | censys.com |
Country |
![]() |
City | Chicago, Illinois |
IP info including ISP, Usage Type, and Location provided by IPInfo. Updated biweekly.
Important Note: 167.94.138.203 is an IP address from within our whitelist belonging to the subnet 167.94.138.0/24, which we identify as: "Censys (https://about.censys.io/)".
Whitelisted netblocks are typically owned by trusted entities, such as Google or Microsoft who may use them for search engine spiders. However, these same entities sometimes also provide cloud servers and mail services which are easily abused. Pay special attention when trusting or distrusting these IPs.
IP Abuse Reports for 167.94.138.203:
This IP address has been reported a total of 4,549 times from 474 distinct sources. 167.94.138.203 was first reported on , and the most recent report was .
Recent Reports: We have received reports of abusive activity from this IP address within the last week. It is potentially still actively engaged in abusive activities.
Reporter | IoA Timestamp in UTC | Comment | Categories | |
---|---|---|---|---|
![]() |
|
Port Scan | ||
![]() |
2025-07-19T16:09:17.213838+0300
ET DROP Dshield Block Listed Source group 1 |
Port Scan Hacking Spoofing Brute-Force | ||
![]() |
[MK-Root1] Blocked by UFW
|
Port Scan Brute-Force | ||
![]() |
Port probe to tcp/3128 (squid http proxy)
[srv125] |
Port Scan | ||
![]() |
|
Port Scan | ||
![]() |
5 port probes: tcp/993 (imap4over tls), 4x tcp/21 (ftp control)
[gda,srv128] |
FTP Brute-Force Port Scan Brute-Force | ||
![]() |
Port probe to tcp/8501
[srv124] |
Port Scan | ||
![]() |
2 port probes: tcp/9121, tcp/18086
[srv136,srv135] |
Port Scan | ||
Anonymous |
Triggered: repeated knocking on closed ports.
|
Port Scan | ||
![]() |
ID: 3297726118 | PORT: 62700 | https://167-94-138-203.scanthe.net
|
Port Scan | ||
![]() |
|
Web App Attack | ||
![]() |
tcp ports: 139,54441 (40 or more attempts)
|
Port Scan | ||
![]() |
|
Brute-Force SSH | ||
![]() |
Honeypot hit: Empty payload (likely service probe); 60257 [1] TCP
|
Port Scan | ||
![]() |
Censys.io.Scanner
|
Port Scan |
Showing 1 to 15 of 4549 reports
Is this your IP? You may request to takedown any associated reports. We will attempt to verify your ownership. Request Takedown 🚩