35.189.254.248

Recent Activity This IP has received recent abuse reports, which causes the score to increase.
Abuse confidence score ?
100% Critical
30 reports
23 reporters ยท latest 2 days ago
ISP Google LLC
Usage Type Data Center/Web Hosting/Transit
ASN AS396982
Hostname(s) 248.254.189.35.bc.googleusercontent.com
Domain Name google.com
Country ๐Ÿ‡ง๐Ÿ‡ช Belgium
City Brussels, Brussels Capital

ISP, Usage Type, and Location provided by IPInfo. Updated weekly.

Log in to view charts and search reports for this IP. Log In

Reports Activity

Example preview

Report Categories (Last 60 Days)

Example preview

Top Reporter Countries (Last 60 Days)

Example preview
Account required for the enhanced features Log in Sign up

IP Abuse Reports for 35.189.254.248

This IP address has been reported a total of 30 times from 23 distinct sources. 35.189.254.248 was first reported on , and the most recent report was . In the last 60 days, the top reporter locations were: France with 9 reports; United States of America with 4 reports; Germany with 3 reports. The most common categories in these recent reports were: Port Scan 22 times; Hacking 10 times; Brute-Force 4 times; SSH 1 time; Web App Attack 1 time; Other 1 time.

Reporter IoA Timestamp (UTC) Comment Categories
๐Ÿ‡ซ๐Ÿ‡ท thecocasio
Port Scan
๐Ÿ‡ซ๐Ÿ‡ท Kejult
Port Scan
๐Ÿ‡บ๐Ÿ‡ธ azminawwar
[35.189.254.248] triggered by honeypot on port [3306], Timestamp [2026-10-08T10:03:57Z](no payload)
Port Scan Hacking
๐Ÿ‡ซ๐Ÿ‡ท Zikmadol
Trapline honeypot: Redis exploitation. Feed: https://github.com/Zikmadol/trapline-ioc
Hacking
๐Ÿ‡ซ๐Ÿ‡ท Kejult
Port Scan
๐Ÿ‡ฌ๐Ÿ‡ง essinghigh
IPS Detection: 35.189.254.248 -> DPT: 3306
Port Scan
๐Ÿ‡ซ๐Ÿ‡ท fzc2000
Repeated TCP connections to unused ports on a honeypot
Port Scan
๐Ÿ‡น๐Ÿ‡ผ kk_it_man
ET SCAN Suspicious inbound to PostgreSQL port 5432 ET SCAN Suspicious inbound to mySQL port 3306
Port Scan
๐Ÿ‡ฉ๐Ÿ‡ช guldkage
Unauthorized connection attempt detected from IP address 35.189.254.248 to port 5432 (ger-03) [J]
Brute-Force Exploited Host
๐Ÿ‡น๐Ÿ‡ท Domainhizmetleri.com
Source: DH Hunter (Honeypot) | Reason: Redis Command (6379/tcp)
Port Scan Hacking
๐Ÿ‡ซ๐Ÿ‡ท lechat
Port Scan
๐Ÿ‡น๐Ÿ‡ท trakyabirlik
Web App Attack
๐Ÿ‡ฉ๐Ÿ‡ช Kejult
Port Scan
๐Ÿ‡ต๐Ÿ‡ฑ bart@
Port Scan
๐Ÿ‡บ๐Ÿ‡ธ kuroneko_omu
[autoreport] mysql root login attempts
Hacking Brute-Force

Showing 1 to 15 of 30 reports

Think this IP has been falsely reported? You may request to have the associated reports reviewed and removed. Request Takedown ๐Ÿšฉ

Recently Reported IPs:

๐Ÿ‡ง๐Ÿ‡ท 186.238.242.194
๐Ÿ‡ป๐Ÿ‡ณ 123.58.198.35
๐Ÿ‡บ๐Ÿ‡ธ 104.238.110.208
๐Ÿ‡ง๐Ÿ‡ฉ 103.239.252.132
๐Ÿ‡ฌ๐Ÿ‡ง 91.237.124.248
๐Ÿ‡ฎ๐Ÿ‡ถ 65.20.230.220
๐Ÿ‡บ๐Ÿ‡ธ 45.131.195.159
๐Ÿ‡ฐ๐Ÿ‡ท 220.123.33.105
๐Ÿ‡ช๐Ÿ‡จ 186.47.77.39
๐Ÿ‡น๐Ÿ‡ท 178.244.206.96
๐Ÿ‡จ๐Ÿ‡ณ 118.196.119.108
๐Ÿ‡ป๐Ÿ‡ณ 103.163.118.115
๐Ÿ‡ซ๐Ÿ‡ท 85.217.140.43
๐Ÿ‡ง๐Ÿ‡ท 45.229.91.2
๐Ÿ‡ฏ๐Ÿ‡ต 35.213.7.234
๐Ÿ‡ฎ๐Ÿ‡ณ 203.192.207.38
๐Ÿ‡น๐Ÿ‡ผ 111.70.23.238
๐Ÿ‡บ๐Ÿ‡ธ 71.6.134.204
๐Ÿ‡ณ๐Ÿ‡ฑ 45.148.10.151
๐Ÿ‡จ๐Ÿ‡ณ 36.137.242.65