AbuseIPDB » 52.154.140.87
52.154.140.87 was found in our database!
This IP was reported 20 times. Confidence of Abuse is 84%: ?
| ISP | Microsoft Corporation |
|---|---|
| Usage Type | Data Center/Web Hosting/Transit |
| ASN | AS8075 |
| Domain Name | microsoft.com |
| Country | ๐บ๐ธ United States of America |
| City | Des Moines, Iowa |
IP info including ISP, Usage Type, and Location provided by IPInfo. Updated weekly.
IP Abuse Reports for 52.154.140.87:
This IP address has been reported a total of 20 times from 18 distinct sources. 52.154.140.87 was first reported on , and the most recent report was .
Recent Reports: We have received reports of abusive activity from this IP address within the last week. It is potentially still actively engaged in abusive activities.
| Reporter | IoA Timestamp (UTC) | Comment | Categories | |
|---|---|---|---|---|
| ๐บ๐ธ RAP |
2026-09-02 00:12:55 UTC Unauthorized activity to TCP port 23. Telnet
|
Port Scan | ||
| ๐บ๐ธ mutebot.net |
SRC=52.154.140.87, PROTO=TCP, SPT=43048, DPT=23
|
Port Scan | ||
| ๐ณ๐ฑ ByeByte API |
|
Port Scan | ||
| ๐ช๐ช Tsumugi Kotobuki |
|
Port Scan Hacking | ||
| ๐ฆ๐น begou.dev |
[Threat Intelligence] Port Scanning and/or Unauthorized access -> TCP/23
|
Port Scan | ||
| ๐ฉ๐ช Jochen Pretli |
connection to honeypot
|
Email Spam Port Scan | ||
| ๐บ๐ธ NetVexor |
Attack source identified and submitted via NetVexor BGP Blackhole Network
|
Port Scan Hacking Brute-Force | ||
| Anonymous |
denied traffic to a non-approved destination port. destination port 2078.
|
Port Scan | ||
| ๐ณ๐ฑ Savvii |
15 attempts against mh-modsecurity-ban on pf221102
|
Brute-Force Web App Attack | ||
| ๐ท๐ธ Scan |
MultiHost/MultiPort Probe, Scan, Hack -
|
Port Scan Hacking | ||
| ๐ฉ๐ช Admins@FBN |
FW-PortScan: Traffic Blocked srcport=48083 dstport=2096
|
Port Scan | ||
| ๐บ๐ธ MPL |
tcp port scan (10 or more attempts)
|
Port Scan | ||
| Anonymous |
Sensitive Configuration File Disclosure.
|
Hacking | ||
| ๐ง๐พ lns.bz |
Too many 404 requests [BY]
|
Web App Attack | ||
| ๐ง๐ช voormedia |
Accessed trap at '/___proxy_subdomain_whm/login/'
|
Web App Attack |
Showing 1 to 15 of 20 reports
Think this IP has been falsely reported? You may request to have the associated reports reviewed and removed. Request Takedown ๐ฉ