AbuseIPDB » 2.189.173.85
2.189.173.85 was found in our database!
This IP was reported 19 times. Confidence of Abuse is 77%: ?
| ISP | Nimadd net co. |
|---|---|
| Usage Type | Fixed Line ISP |
| ASN | AS42337 |
| Domain Name | ito.gov.ir |
| Country | ๐ฎ๐ท Iran (Islamic Republic of) |
| City | Tehran, Tehran |
IP info including ISP, Usage Type, and Location provided by IPInfo. Updated weekly.
IP Abuse Reports for 2.189.173.85:
This IP address has been reported a total of 19 times from 15 distinct sources. 2.189.173.85 was first reported on , and the most recent report was .
Recent Reports: We have received reports of abusive activity from this IP address within the last week. It is potentially still actively engaged in abusive activities.
| Reporter | IoA Timestamp (UTC) | Comment | Categories | |
|---|---|---|---|---|
| ๐ง๐พ StatsMe |
2026-06-09T04:26:00.485633+0300
ET SCAN Suspicious inbound to MSSQL port 1433
|
Port Scan | ||
| ๐ง๐ท SOC Blue Team |
IPs get by Hunting on SIEM
|
Phishing Web Spam Port Scan Hacking | ||
| ๐บ๐ธ MPL |
tcp/445 (2 or more attempts)
|
Port Scan | ||
| ๐ณ๐ด tmiland |
|
Port Scan | ||
| ๐ท๐ธ Smel |
SQL/MH Probe, Scan, Hack -
|
Port Scan Hacking SQL Injection | ||
| ๐ฉ๐ช Justin F. | AS204464 |
Honeypot [nx-infrastructure]: SMB traffic on port 445
Reported by: Justin F.
|
Hacking | ||
| ๐บ๐ธ donarev419 |
Connection to port 445 with data transfer.
Data preview:
|
Port Scan Hacking | ||
| ๐บ๐ธ RAP |
2026-06-07 22:09:17 UTC Unauthorized activity to TCP port 445. SMB
|
Port Scan | ||
| ๐ซ๐ท GoodOldTOS |
Connection to MSSQL honeypot
|
Hacking | ||
| ๐บ๐ธ RAP |
2026-06-07 19:49:40 UTC Unauthorized activity to TCP port 445. SMB
|
Port Scan | ||
| ๐ฉ๐ช AS213449.net |
|
SQL Injection | ||
| ๐ฉ๐ช AS213449.net |
|
SQL Injection | ||
| ๐ฉ๐ช AS213449.net |
|
SQL Injection | ||
| ๐ฉ๐ช HoneyPot-FrPri |
1780792465 - 06/07/2026 02:34:25 Host: 2.189.173.85/2.189.173.85 Port: 1088 TCP Blocked
...
|
Port Scan | ||
| Anonymous |
unsolicited connect TCP dport 445 (sport 46236)
|
Hacking |
Showing 1 to 15 of 19 reports
Think this IP has been falsely reported? You may request to have the associated reports reviewed and removed. Request Takedown ๐ฉ