AbuseIPDB » 65.49.1.98

65.49.1.98 was found in our database!

This IP was reported 17,639 times. Confidence of Abuse is 100%: ?

100%
ISP Hurricane Electric LLC
Usage Type Fixed Line ISP
ASN AS6939
Hostname(s) 98.0-24.1.49.65.in-addr.arpa
scan-58e.shadowserver.org
Domain Name he.net
Country United States of America
City San Francisco, California

IP info including ISP, Usage Type, and Location provided by IPInfo. Updated biweekly.

IP Abuse Reports for 65.49.1.98:

This IP address has been reported a total of 17,639 times from 529 distinct sources. 65.49.1.98 was first reported on , and the most recent report was .

Recent Reports: We have received reports of abusive activity from this IP address within the last week. It is potentially still actively engaged in abusive activities.

Reporter IoA Timestamp in UTC Comment Categories
rtbh.com.tr
list.rtbh.com.tr report: tcp/5900, tcp/7777, tcp/8873
Brute-Force
infraestrutura
2025-04-17T14:43:11.328378 erp sshd[1871675]: Invalid user from 65.49.1.98 port 45277
...
Brute-Force SSH
MPL
tcp/5094 (2 or more attempts)
Port Scan
oonux.net
RouterOS: Scanning detected TCP 65.49.1.98:47557 > x.x.x.x:8873
Port Scan
MPL
tcp ports: 5900,20547 (4 or more attempts)
Port Scan
Study Bitcoin 🤗
Port probe to tcp/2101 (microsoft message queuing)
[srv128]
Port Scan
diego
Events: TCP SYN Discovery or Flooding, Seen 20 times in the last 10800 seconds
DDoS Attack
Josh S.
Port Scan
MPL
tcp/8060 (3 or more attempts)
Port Scan
ozisp.com.au
Hacking
spyra.rocks
Plesk Panel
Web App Attack
MPL
tcp/9990 (2 or more attempts)
Port Scan
rtbh.com.tr
list.rtbh.com.tr report: tcp/5988, udp/7
Brute-Force
diego
Events: TCP SYN Discovery or Flooding, Seen 25 times in the last 10800 seconds
DDoS Attack
djboddington
This IP was detected by CrowdSec triggering crowdsecurity/postscreen-rbl
Email Spam

Showing 1 to 15 of 17639 reports


Is this your IP? You may request to takedown any associated reports. We will attempt to verify your ownership. Request Takedown 🚩

Recently Reported IPs: