This IP address has been reported a total of
30
times from
17 distinct
sources.
45.74.28.247 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
France
with 6
reports;
Netherlands
with 4
reports;
Germany
with 3
reports.
The most common categories in these recent reports were:
Port Scan
17
times;
Hacking
8
times;
Web App Attack
7
times;
Bad Web Bot
5
times;
Brute-Force
2
times;
Other
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Honeypot Finding: repeated TCP service probing on TCP/50443 (service); 2 application-level events ac ...
show moreHoneypot Finding: repeated TCP service probing on TCP/50443 (service); 2 application-level events across 2 source port(s). Sensor(s): Honeytrap.
show less
Honeypot detection: port scan / service probe. 4 events observed. 2 distinct ports targeted. Reporte ...
show moreHoneypot detection: port scan / service probe. 4 events observed. 2 distinct ports targeted. Reported automatically from a honeypot sensor.
show less
Honeypot Finding: repeated TCP service probing on TCP/1443 (service); 4 application-level events acr ...
show moreHoneypot Finding: repeated TCP service probing on TCP/1443 (service); 4 application-level events across 4 source port(s). Sensor(s): Honeytrap.
show less
Honeypot Finding: repeated TCP service probing on TCP/9443 (service); 4 application-level events acr ...
show moreHoneypot Finding: repeated TCP service probing on TCP/9443 (service); 4 application-level events across 4 source port(s). Sensor(s): Honeytrap.
show less
Honeypot Finding: repeated TCP service probing on TCP/4443 (service); 2 application-level events acr ...
show moreHoneypot Finding: repeated TCP service probing on TCP/4443 (service); 2 application-level events across 2 source port(s). Sensor(s): Honeytrap.
show less
Honeypot Finding: active TCP application payload captured by Honeytrap; 4 payload-bearing connection ...
show moreHoneypot Finding: active TCP application payload captured by Honeytrap; 4 payload-bearing connection/event(s), 3562 payload byte(s) total, maximum payload 1483 byte(s). Target port(s): 10443.
show less
This source IP appears to have had partial success against a monitored honeynet, with activity obser ...
show moreThis source IP appears to have had partial success against a monitored honeynet, with activity observed between 2026-10-02 10:42:22 UTC and 2026-10-02 10:42:23 UTC. Automated triage flagged this session for manual review: exploit attempt observed, followed by continued activity from the same source -- worth manual review. Logged: 3 network events and 1 web request. Targeted port 80/tcp. Suricata signatures fired: ET DROP Dshield Block Listed Source group 1, SURICATA TLS invalid record type, and SURICATA Applayer Detect protocol only one direction. Request observed: GET / (HTTP 302). User-Agent string: 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36'. Observed techniques align with MITRE ATT&CK T1595 (Active Scanning), T1046 (Network Service Discovery), T1083 (File and Directory Discovery), and T1190 (Exploit Public-Facing Application). Captured by a private research honeynet.
show less