AbuseIPDB » 197.248.126.217

197.248.126.217 was found in our database!

This IP was reported 461 times. Confidence of Abuse is 100%: ?

100%
ISP Safaricom Limited
Usage Type Fixed Line ISP
ASN AS37061
Hostname(s) 197-248-126-217.safaricombusiness.co.ke
Domain Name safaricom.co.ke
Country ๐Ÿ‡ฐ๐Ÿ‡ช Kenya
City Kikuyu, Kiambu County

IP info including ISP, Usage Type, and Location provided by IPInfo. Updated weekly.

IP Abuse Reports for 197.248.126.217:

This IP address has been reported a total of 461 times from 107 distinct sources. 197.248.126.217 was first reported on , and the most recent report was .

Recent Reports: We have received reports of abusive activity from this IP address within the last week. It is potentially still actively engaged in abusive activities.

Reporter IoA Timestamp (UTC) Comment Categories
๐Ÿ‡บ๐Ÿ‡ธ drewf.ink
[15:57] Triggered SMB honeypot on port 445. Type: NetBIOS + SMB1. Dialect(s): NT LM 0.12
Hacking Exploited Host
๐Ÿ‡บ๐Ÿ‡ธ MPL
tcp/445
Port Scan
๐Ÿ‡บ๐Ÿ‡ธ drewf.ink
[01:18] Port scanning. Port(s) scanned: TCP/1433
Port Scan
๐Ÿ‡บ๐Ÿ‡ธ RAP
2026-06-19 23:18:38 UTC Unauthorized activity to TCP port 1433. SQL
Port Scan
๐Ÿ‡บ๐Ÿ‡ธ RAP
2026-06-19 19:54:23 UTC Unauthorized activity to TCP port 1433. SQL
Port Scan
๐Ÿ‡บ๐Ÿ‡ธ RAP
2026-06-19 16:55:13 UTC Unauthorized activity to TCP port 1433. SQL
Port Scan
๐Ÿ‡ซ๐Ÿ‡ท zulzeen
[distribamap-0] Blocked by SysWarden Firewall [BLOCK] (SMB/Possible Ransomware Attack)
Hacking Brute-Force
๐Ÿ‡ฆ๐Ÿ‡น urnilxfgbez
Last 24 Hours suspicious: (DPT=445|DPT=3389|DPT=22|DPT=3306|DPT=8080|DPT=23|DPT=5900|DPT=1433)
Port Scan
๐Ÿ‡บ๐Ÿ‡ธ drewf.ink
[20:04] Port scanning. Port(s) scanned: TCP/1433
Port Scan
๐Ÿ‡บ๐Ÿ‡ธ RAP
2026-06-18 18:43:10 UTC Unauthorized activity to TCP port 445. SMB
Port Scan
๐Ÿ‡ฌ๐Ÿ‡ง knock
Knock-Knock honeypot brute-force: SMB (3 total hits)
Brute-Force
๐Ÿ‡บ๐Ÿ‡ธ RAP
2026-06-18 15:54:13 UTC Unauthorized activity to TCP port 445. SMB
Port Scan
๐Ÿ‡บ๐Ÿ‡ธ RAP
2026-06-18 13:10:10 UTC Unauthorized activity to TCP port 445. SMB
Port Scan
๐Ÿ‡บ๐Ÿ‡ธ RAP
2026-06-18 12:13:45 UTC Unauthorized activity to TCP port 445. SMB
Port Scan
๐Ÿ‡ฆ๐Ÿ‡บ LiftUp Hosting
Honeypot hit: MSSQL traffic (on 1433) with username sa and empty password
Brute-Force

Showing 1 to 15 of 461 reports


Think this IP has been falsely reported? You may request to have the associated reports reviewed and removed. Request Takedown ๐Ÿšฉ

Recently Reported IPs:

๐Ÿ‡บ๐Ÿ‡ธ 147.185.132.16
๐Ÿ‡ฑ๐Ÿ‡น 141.98.11.134
๐Ÿ‡ง๐Ÿ‡ฌ 78.128.114.110
๐Ÿ‡ธ๐Ÿ‡พ 46.53.66.89
๐Ÿ‡ณ๐Ÿ‡ฑ 45.148.10.157
๐Ÿ‡บ๐Ÿ‡ธ 13.89.124.218
๐Ÿ‡ณ๐Ÿ‡ฑ 176.65.148.132
๐Ÿ‡ณ๐Ÿ‡ฑ 72.56.66.71
๐Ÿ‡ท๐Ÿ‡บ 5.3.146.57
๐Ÿ‡บ๐Ÿ‡ธ 4.246.231.57
๐Ÿ‡ฌ๐Ÿ‡ง 195.96.139.136
๐Ÿ‡บ๐Ÿ‡ธ 157.245.1.7
๐Ÿ‡ฉ๐Ÿ‡ช 109.91.4.177
๐Ÿ‡ง๐Ÿ‡ฌ 78.128.112.30
๐Ÿ‡บ๐Ÿ‡ธ 147.185.132.13
๐Ÿ‡ญ๐Ÿ‡ฐ 114.111.53.214
๐Ÿ‡ฎ๐Ÿ‡ถ 62.201.244.179
๐Ÿ‡ณ๐Ÿ‡ฑ 45.156.128.149
๐Ÿ‡บ๐Ÿ‡ธ 167.234.221.222
๐Ÿ‡ฎ๐Ÿ‡ฉ 103.179.216.158