This IP address has been reported a total of
9
times from
9 distinct
sources.
194.60.254.225 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2026-08-20T12:46:12.018820Z [cowrie.telnet.factory.HoneyPotTelnetFactory] New connection: 194.60.254 ...
show more2026-08-20T12:46:12.018820Z [cowrie.telnet.factory.HoneyPotTelnetFactory] New connection: 194.60.254.225:52674 (158.69.22.11:2223) [session: 72ac1834f191]
2026-08-20T12:49:06.498751Z [cowrie.ssh.factory.CowrieSSHFactory] New connection: 194.60.254.225:34490 (158.69.22.11:2222) [session: 9e930281f6d4]
...
show less
UDP flood (DDoS) vs AS215599: 240 pkts / 0.34 MB to UDP 80 across 105 dst IP(s), 2026-08-19 21:46 to ...
show moreUDP flood (DDoS) vs AS215599: 240 pkts / 0.34 MB to UDP 80 across 105 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
UDP flood (DDoS) vs AS215599: 240 pkts / 0.34 MB to UDP 80 across 105 dst IP(s), 2026-08-19 21:46 to ...
show moreUDP flood (DDoS) vs AS215599: 240 pkts / 0.34 MB to UDP 80 across 105 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
Bad web bot: Spoofed/obsolete UA (Opera/9.45.(Windows NT 5.2; fo-FO) Presto/2.9.162 Version/12.00). ...
show moreBad web bot: Spoofed/obsolete UA (Opera/9.45.(Windows NT 5.2; fo-FO) Presto/2.9.162 Version/12.00). Mass-scanning WordPress plugin. Coordinated large-scale bot attack.
show less