AbuseIPDB » 202.189.23.160
202.189.23.160 was found in our database!
This IP was reported 8 times. Confidence of
Abuse
is 53% : ?
ISP
Shandong eshinton Network Technology Co., Ltd.
Usage Type
Data Center/Web Hosting/Transit
ASN
AS139180
Domain Name
cnnic.cn
Country
๐จ๐ณ
China
City
Beijing, Beijing
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 202.189.23.160 :
This IP address has been reported a total of
8
times from
8 distinct
sources.
202.189.23.160 was first reported on
July 22nd 2026 , and the most recent report was
2 days ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ซ๐ท
โจ
2026-07-24 23:57:15
(2 days ago)
Rule : Security
Rule: Security
Event: Security
4208 \device\harddiskvolume4\windows\syswow64\vmnat ...
show more
Rule : Security
Rule: Security
Event: Security
4208 \device\harddiskvolume4\windows\syswow64\vmnat.exe %592 202.189.23.160 0 77.90.37.147 0 1 {79AECEE0-C998-4773-96FA-2B5E4C0A8344} 140269 %610 44
show less
Port Scan
Hacking
Brute-Force
Anonymous
2026-07-24 21:05:14
(2 days ago)
Jul 24 17:05:14 localhost kernel: [113272326.472825] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:9 ...
show more
Jul 24 17:05:14 localhost kernel: [113272326.472825] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=202.189.23.160 DST=[mungedIP2] LEN=814 TOS=0x00 PREC=0x00 TTL=43 ID=16761 PROTO=ICMP TYPE=0 CODE=0 ID=4346 SEQ=14989
Jul 24 17:05:14 localhost kernel: [113272326.472842] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=202.189.23.160 DST=[mungedIP2] LEN=814 TOS=0x00 PREC=0x00 TTL=43 ID=16761 PROTO=ICMP TYPE=0 CODE=0 ID=4346 SEQ=14989
Jul 24 17:05:14 localhost kernel: [113272326.479185] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=202.189.23.160 DST=[mungedIP2] LEN=1201 TOS=0x00 PREC=0x00 TTL=43 ID=16762 PROTO=ICMP TYPE=0 CODE=0 ID=4515 SEQ=43118
Jul 24 17:05:14 localhost kernel: [113272326.479189] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=202.189.23.160 DST=[mungedIP2] LEN=1201 TOS=0x00 PREC=0x00 TTL=43 ID=16762 PROTO=ICMP TYPE=0 CODE=0 ID=4515 SEQ=4
show less
Port Scan
๐ฉ๐ช
Richie
2026-07-24 20:46:55
(2 days ago)
[HOST1] Port Scan detected
Port Scan
๐บ๐ธ
arc21
2026-07-24 20:27:21
(2 days ago)
2026-07-24T20:27:13.407665+00:00 ENGL-NYC-5 kernel: [1908209.237886] [UFW BLOCK] IN=br0 OUT= PHYSIN= ...
show more
2026-07-24T20:27:13.407665+00:00 ENGL-NYC-5 kernel: [1908209.237886] [UFW BLOCK] IN=br0 OUT= PHYSIN=enp5s0 MAC=c6:28:62:bb:6a:37:44:4c:a8:96:44:e3:08:00 SRC=202.189.23.160 DST=130.12.156.66 LEN=146 TOS=0x02 PREC=0xE0 TTL=40 ID=17139 PROTO=ICMP TYPE=0 CODE=0 ID=4905 SEQ=29223
2026-07-24T20:27:20.234655+00:00 ENGL-NYC-5 kernel: [1908216.064847] [UFW BLOCK] IN=br0 OUT= PHYSIN=enp5s0 MAC=c6:28:62:bb:6a:37:44:4c:a8:96:44:e3:08:00 SRC=202.189.23.160 DST=130.12.156.66 LEN=1310 TOS=0x02 PREC=0xE0 TTL=40 ID=18175 PROTO=ICMP TYPE=0 CODE=0 ID=5127 SEQ=45117
2026-07-24T20:27:20.234750+00:00 ENGL-NYC-5 kernel: [1908216.064873] [UFW BLOCK] IN=br0 OUT= PHYSIN=enp5s0 MAC=c6:28:62:bb:6a:37:44:4c:a8:96:44:e3:08:00 SRC=202.189.23.160 DST=130.12.156.66 LEN=45 TOS=0x02 PREC=0xE0 TTL=40 ID=18176 PROTO=ICMP TYPE=0 CODE=0 ID=25761 SEQ=1152
...
show less
Port Scan
๐บ๐ธ
MPL
2026-07-22 22:28:39
(4 days ago)
tcp/12328 (2 or more attempts)
Port Scan
๐บ๐ธ
thororen
2026-07-22 17:45:10
(4 days ago)
Blocked by UFW [7658/tcp]
Source port: 6180
TTL: 111
Packet length: 48
TOS: 0x00
This report was ge ...
show more
Blocked by UFW [7658/tcp]
Source port: 6180
TTL: 111
Packet length: 48
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Anonymous
2026-07-22 16:16:58
(5 days ago)
denied traffic to a honeypot network. destination port 37811.
Port Scan
Hacking
๐บ๐ธ
sumnone
2026-07-22 10:07:54
(5 days ago)
Port probing on unauthorized port 16818
Port Scan
Hacking
Exploited Host
Showing 1 to
8
of 8 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: