This IP address has been reported a total of
24
times from
13 distinct
sources.
5.252.101.22 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
byebyte.space auth: TCP packet to port 5986 (high-risk service) at 2026-09-01T10:04:42Z. Source port ...
show morebyebyte.space auth: TCP packet to port 5986 (high-risk service) at 2026-09-01T10:04:42Z. Source port 61000. TCP flags: SYN. Packet: 44B, TTL 250, window 1025, IP id 8673. Single packet, dropped at firewall. p0f: OS Linux 2.2.x-3.x (barebone) (generic match), 5 hops, link Ethernet or modem.
show less
[rede-164-29] 09/01/2026-06:51:30.302485, 5.252.101.22, Protocol: 6, ET CINS Active Threat Intellige ...
show more[rede-164-29] 09/01/2026-06:51:30.302485, 5.252.101.22, Protocol: 6, ET CINS Active Threat Intelligence Poor Reputation IP group 7
show less
byebyte.space auth: TCP packet to port 5901 (high-risk service) at 2026-09-01T08:04:16Z. Source port ...
show morebyebyte.space auth: TCP packet to port 5901 (high-risk service) at 2026-09-01T08:04:16Z. Source port 61000. TCP flags: SYN. Packet: 44B, TTL 250, window 1025, IP id 58119. Single packet, dropped at firewall. p0f: OS Linux 2.2.x-3.x (barebone) (generic match), 5 hops, link Ethernet or modem.
show less
byebyte.space auth: TCP packet to port 5985 (high-risk service) at 2026-09-01T07:46:09Z. Source port ...
show morebyebyte.space auth: TCP packet to port 5985 (high-risk service) at 2026-09-01T07:46:09Z. Source port 61000. TCP flags: SYN. Packet: 44B, TTL 250, window 1025, IP id 3422. Single packet, dropped at firewall. p0f: OS Linux 2.2.x-3.x (barebone) (generic match), 5 hops, link Ethernet or modem.
show less
byebyte.space auth: TCP packet to port 5984 (high-risk service) at 2026-09-01T07:25:08Z. Source port ...
show morebyebyte.space auth: TCP packet to port 5984 (high-risk service) at 2026-09-01T07:25:08Z. Source port 61000. TCP flags: SYN. Packet: 44B, TTL 250, window 1025, IP id 40092. Single packet, dropped at firewall. p0f: OS Linux 2.2.x-3.x (barebone) (generic match), 5 hops, link Ethernet or modem.
show less
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly as ...
show moreUFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly associated with port scanning, service discovery, or automated internet probing. Technical: source_ip=5.252.101.22; proto=TCP; source_port=61000; target_port=6009; flags=SYN
show less
*Port Scan* detected from 5.252.101.22 (DE/Germany/Hesse/Frankfurt am Main/hosted-by.chabka-hosting. ...
show more*Port Scan* detected from 5.252.101.22 (DE/Germany/Hesse/Frankfurt am Main/hosted-by.chabka-hosting.com/[AS213250 ITP-Solutions GmbH & Co. KG]). 21 hits in the last 2827 seconds
show less
*Port Scan* detected from 5.252.101.22 (DE/Germany/Hesse/Frankfurt am Main/hosted-by.chabka-hosting. ...
show more*Port Scan* detected from 5.252.101.22 (DE/Germany/Hesse/Frankfurt am Main/hosted-by.chabka-hosting.com/[AS213250 ITP-Solutions GmbH & Co. KG]). 21 hits in the last 2621 seconds
show less
*Port Scan* detected from 5.252.101.22 (DE/Germany/Hesse/Frankfurt am Main/hosted-by.chabka-hosting. ...
show more*Port Scan* detected from 5.252.101.22 (DE/Germany/Hesse/Frankfurt am Main/hosted-by.chabka-hosting.com/[AS213250 ITP-Solutions GmbH & Co. KG]). 21 hits in the last 2442 seconds
show less