AbuseIPDB » 65.49.1.152

65.49.1.152 was found in our database!

This IP was reported 1,559 times. Confidence of Abuse is 100%: ?

100%
ISP Hurricane Electric LLC
Usage Type Fixed Line ISP
ASN AS6939
Hostname(s) 152.0-24.1.49.65.in-addr.arpa
scan-71-00.shadowserver.org
Domain Name he.net
Country United States of America
City San Francisco, California

IP info including ISP, Usage Type, and Location provided by IPInfo. Updated biweekly.

IP Abuse Reports for 65.49.1.152:

This IP address has been reported a total of 1,559 times from 183 distinct sources. 65.49.1.152 was first reported on , and the most recent report was .

Recent Reports: We have received reports of abusive activity from this IP address within the last week. It is potentially still actively engaged in abusive activities.

Reporter IoA Timestamp in UTC Comment Categories
drewf.ink
[16:32] Port scanning. Port(s) scanned: TCP/873
Port Scan
Largnet SOC
65.49.1.152 triggered Icarus honeypot on port 143. Check us out on github.
Port Scan Hacking
Study Bitcoin 🤗
Port probe to tcp/636 (ldapover tls)
[srv128]
Port Scan
mkaraki
1745681102 # Service_probe # SIGNATURE_SEND # source_ip:65.49.1.152 # dst_port:873
...
Port Scan
Anonymous
Tried our host z.
Port Scan Hacking Exploited Host
MPL
tcp/20256
Port Scan
MPL
tcp port scan (3 or more attempts)
Port Scan
RAP
2025-04-26 14:56:11 UTC Unauthorized activity to TCP port 135.
Port Scan
diego
Events: TCP SYN Discovery or Flooding, Seen 5 times in the last 10800 seconds
DDoS Attack
RogueAutomata
Web App Attack
MPL
tcp/9642
Port Scan
MPL
tcp ports: 80,9642 (4 or more attempts)
Port Scan
Study Bitcoin 🤗
Port probe to tcp/22 (ssh)
[srv124]
Port Scan Brute-Force SSH
diego
Events: TCP SYN Discovery or Flooding, Seen 6 times in the last 10800 seconds
DDoS Attack
Study Bitcoin 🤗
Port probe to tcp/16993
[srv124]
Port Scan

Showing 1 to 15 of 1559 reports


Is this your IP? You may request to takedown any associated reports. We will attempt to verify your ownership. Request Takedown 🚩

Recently Reported IPs: