AbuseIPDB » 52.248.42.198
IP info including ISP, Usage Type, and Location provided by IPInfo. Updated weekly.
Top Reporter Countries (Last 60 Days)
Example previewReport Categories (Last 60 Days)
Example previewIP Abuse Reports for 52.248.42.198:
This IP address has been reported a total of 69 times from 42 distinct sources. 52.248.42.198 was first reported on , and the most recent report was . In the last 60 days, the top reporter locations were: United States of America with 27 reports; Germany with 9 reports; France with 8 reports. The most common categories in these recent reports were: Port Scan 59 times; Hacking 11 times; Brute-Force 5 times; Exploited Host 4 times; Web App Attack 4 times; Other 6 times.
| Reporter | IoA Timestamp (UTC) | Comment | Categories | |
|---|---|---|---|---|
| 🇺🇸 MPL |
tcp/8087 (2 or more attempts)
|
Port Scan | ||
| 🇺🇸 xmission.com |
|
Port Scan | ||
| 🇺🇸 MPL |
tcp/5986
|
Port Scan | ||
| 🇧🇷 diego |
|
Hacking | ||
| 🇧🇷 noconex |
|
Port Scan Brute-Force SSH | ||
| 🇺🇸 MPL |
tcp/25565
|
Port Scan | ||
| 🇳🇱 donarev419 |
Connection to port 541 with data transfer.
Data preview:
|
Port Scan Hacking | ||
| 🇫🇷 service Informatique |
GET /actuator
|
Web App Attack | ||
| 🇩🇪 sandra361 |
|
Port Scan | ||
| 🇩🇪 celestialcity |
|
Port Scan | ||
| 🇺🇸 HamSammich |
Automated sensor: 2 RDP connection/probe attempts over the last 24h (latest 2026-08-30T01:23Z).
|
Port Scan Brute-Force | ||
| 🇮🇹 CoreTech srl |
[DC: IP:151.1.252.27] ntopng alert: blacklisted_client_contact
|
Hacking | ||
| 🇺🇸 MPL |
tcp/61616 (2 or more attempts)
|
Port Scan | ||
| 🇺🇸 MPL |
tcp/3389 (2 or more attempts)
|
Port Scan | ||
| 🇫🇷 zulzeen |
[incypit-web] Blocked by SysWarden Firewall [BLOCK] (Web Attack)
|
Hacking Web App Attack |
Think this IP has been falsely reported? You may request to have the associated reports reviewed and removed. Request Takedown 🚩