Jan 4 18:19:44 65.60.2.164 TCP SPT=911 DPT=39589 SYN
Jan 4 18:19:47 65.60.2.164 TCP SPT=911 DPT=39 ...
show moreJan 4 18:19:44 65.60.2.164 TCP SPT=911 DPT=39589 SYN
Jan 4 18:19:47 65.60.2.164 TCP SPT=911 DPT=39589 SYN
Jan 4 18:19:53 65.60.2.164 TCP SPT=911 DPT=39589
...
show less
Jan 4 08:08:04 65.60.2.164 TCP SPT=911 DPT=14985 SYN
Jan 4 08:08:06 65.60.2.164 TCP SPT=911 DPT=14 ...
show moreJan 4 08:08:04 65.60.2.164 TCP SPT=911 DPT=14985 SYN
Jan 4 08:08:06 65.60.2.164 TCP SPT=911 DPT=14985 SYN
Jan 4 08:08:12 65.60.2.164 TCP SPT=911 DPT=14985
...
show less
Jan 3 05:11:25 65.60.2.164 TCP SPT=911 DPT=49417 SYN
Jan 3 05:11:28 65.60.2.164 TCP SPT=911 DPT=49 ...
show moreJan 3 05:11:25 65.60.2.164 TCP SPT=911 DPT=49417 SYN
Jan 3 05:11:28 65.60.2.164 TCP SPT=911 DPT=49417 SYN
Jan 3 05:11:34 65.60.2.164 TCP SPT=911 DPT=49417
...
show less
Blocked by UFW (TCP on port 21391).
Source port: 911
TTL: 112
Packet length: 48
TOS: 0x00
This repo ...
show moreBlocked by UFW (TCP on port 21391).
Source port: 911
TTL: 112
Packet length: 48
TOS: 0x00
This report (for 65.60.2.164) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Confirmed malicious activity observed via T-Pot honeypot Observed 1 events on port 5838 (flow) from ...
show moreConfirmed malicious activity observed via T-Pot honeypot Observed 1 events on port 5838 (flow) from 2025-12-29T16:40:27.026000+00:00 to 2025-12-29T16:40:27.026000+00:00. Sample: {"src_ip": "65.60.2.164", "event_type": "flow", "dest_port": 5838, "src_port": 911}
show less
Dec 29 06:06:13 65.60.2.164 TCP SPT=911 DPT=16700 SYN
Dec 29 06:06:16 65.60.2.164 TCP SPT=911 DPT=16 ...
show moreDec 29 06:06:13 65.60.2.164 TCP SPT=911 DPT=16700 SYN
Dec 29 06:06:16 65.60.2.164 TCP SPT=911 DPT=16700 SYN
Dec 29 06:06:22 65.60.2.164 TCP SPT=911 DPT=16700
...
show less
Dec 28 13:19:16 65.60.2.164 TCP SPT=911 DPT=40892 SYN
Dec 28 13:19:19 65.60.2.164 TCP SPT=911 DPT=40 ...
show moreDec 28 13:19:16 65.60.2.164 TCP SPT=911 DPT=40892 SYN
Dec 28 13:19:19 65.60.2.164 TCP SPT=911 DPT=40892 SYN
Dec 28 13:19:25 65.60.2.164 TCP SPT=911 DPT=40892
...
show less
Dec 27 07:50:47 65.60.2.164 TCP SPT=911 DPT=23893 SYN
Dec 27 07:50:50 65.60.2.164 TCP SPT=911 DPT=23 ...
show moreDec 27 07:50:47 65.60.2.164 TCP SPT=911 DPT=23893 SYN
Dec 27 07:50:50 65.60.2.164 TCP SPT=911 DPT=23893 SYN
Dec 27 07:50:56 65.60.2.164 TCP SPT=911 DPT=23893
...
show less
Dec 26 20:49:26 65.60.2.164 TCP SPT=911 DPT=49762 SYN
Dec 26 20:49:29 65.60.2.164 TCP SPT=911 DPT=49 ...
show moreDec 26 20:49:26 65.60.2.164 TCP SPT=911 DPT=49762 SYN
Dec 26 20:49:29 65.60.2.164 TCP SPT=911 DPT=49762 SYN
Dec 26 20:49:35 65.60.2.164 TCP SPT=911 DPT=49762
...
show less
Dec 26 22:47:24 65.60.2.164 TCP SPT=911 DPT=63555 SYN
Dec 26 22:47:26 65.60.2.164 TCP SPT=911 DPT=63 ...
show moreDec 26 22:47:24 65.60.2.164 TCP SPT=911 DPT=63555 SYN
Dec 26 22:47:26 65.60.2.164 TCP SPT=911 DPT=63555 SYN
Dec 26 22:47:32 65.60.2.164 TCP SPT=911 DPT=63555
...
show less
Port Scan
Anonymous
persistent multiport/host [DoS Attack: SYN/ACK Scan, RST Scan] port 911 4 probe(s) in 24 hrs