Log in to view charts and search reports for this IP.
Log In
Top Reporter Countries (Last 60 Days)
Example preview
Report Categories (Last 60 Days)
Example preview
Reports Activity
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 42.1.117.94:
This IP address has been reported a total of
89
times from
46 distinct
sources.
42.1.117.94 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 41
reports;
France
with 18
reports;
Germany
with 15
reports.
The most common categories in these recent reports were:
Port Scan
73
times;
Hacking
25
times;
Brute-Force
24
times;
DDoS Attack
7
times;
Exploited Host
6
times;
Other
13
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
PortSentry honeypot: unsolicited TCP connection to closed decoy port 445 (SMB) on a host running no ...
show morePortSentry honeypot: unsolicited TCP connection to closed decoy port 445 (SMB) on a host running no such service. Automated port-scan detection at 2026-08-27T10:27:47Z.
show less
Unsolicited TCP connection from 42.1.117.94 to port 0 at 2026-08-25T07:34:55Z. Source IP completed t ...
show moreUnsolicited TCP connection from 42.1.117.94 to port 0 at 2026-08-25T07:34:55Z. Source IP completed three-way handshake to non-public service on this host. Detected by automated intrusion monitoring.
show less
Volumetric UDP flood (DDoS) against a hosted game server at 185.143.177.x:27004/udp in AS203136 (LLC ...
show moreVolumetric UDP flood (DDoS) against a hosted game server at 185.143.177.x:27004/udp in AS203136 (LLC Ordunet), Georgia. This source sustained more than 150 packets/sec toward a single destination UDP port and was one of ~250 sources in a distributed flood that peaked at 410,000 pps / 1.7 Gbit/s. Detected on a MikroTik RouterOS border router by per-source rate accounting (raw prerouting chain, dst-limit 150,50,src-address/10s); the timestamp is the moment this source crossed the threshold, timezone +04:00. This is not a port scan and not a brute-force attempt - it is a pure packet flood, so the host is most likely compromised and part of a botnet. Full packet-level evidence available on request to [email protected].
show less