User whatda joined AbuseIPDB in April 2026 and has reported 20,280 IP addresses.
Standing (weight) is good.
ACTIVE USER
| IP | Date | Comment | Categories |
|---|---|---|---|
| πΊπΈ 40.124.173.94 |
HTTP attack detected: GET /manager/text/list (probe). UA: Mozilla/5.0 zgrab/0.x
|
Port Scan Web App Attack | |
| π·π΄ 80.94.92.179 |
SSH brute-force login detected. Automated IDS report.
|
Brute-Force SSH | |
| πΊπΈ 184.105.139.68 |
SMTP abuse detected: "GET / HTTP/1.1"
|
Email Spam Brute-Force | |
| π©πͺ 64.89.163.140 |
MySQL enumeration query β Rogue INFILE trap: "SHOW DATABASES"
|
Hacking Brute-Force | |
| πΊπΈ 143.198.102.21 |
|
Port Scan Web App Attack | |
| π§π· 45.205.1.70 |
SNMP query: community="public", version=1, OIDs=[1.3.6.1]
|
Port Scan Hacking | |
| π³π± 176.65.148.189 |
RDP connection attempt for user "unknown"
|
Port Scan Hacking | |
| π΅π° 139.135.44.115 |
TELNET unauthorized access: "start"
|
Brute-Force IoT Targeted | |
| π§πͺ 35.205.126.199 |
RDP connection attempt for user "nmap"
|
Port Scan Hacking | |
| π§πͺ 34.78.153.207 |
RDP connection attempt for user "unknown"
|
Port Scan Hacking | |
| πΊπΈ 47.253.5.130 |
TELNET unauthorized access: "echo -e "\x61\x75\x74\x68\x5F\x6F\x6B\x0A""
|
Brute-Force IoT Targeted | |
| π§πͺ 34.77.161.24 |
SMTP abuse detected: "EHLO scan.local"
|
Email Spam Brute-Force | |
| π§πͺ 34.78.79.163 |
SMTP abuse detected: "EHLO example.com"
|
Email Spam Brute-Force | |
| π§πͺ 34.78.174.238 |
FTP unauthorized access: "USER anonymous"
|
FTP Brute-Force Brute-Force | |
| π©πͺ 91.92.43.121 |
HTTP attack detected: GET /login (auth_bruteforce). UA: Go-http-client/1.1
|
Port Scan Web App Attack | |
| πΊπΈ 64.62.197.119 |
SSH brute-force login detected. Automated IDS report.
|
Brute-Force SSH | |
| π©πͺ 64.89.163.166 |
MySQL enumeration query β Rogue INFILE trap: "SHOW DATABASES"
|
Hacking Brute-Force | |
| πΊπΈ 71.6.232.30 |
Redis unauthorized command: "PING"
|
Port Scan Hacking | |
| π³π± 167.99.44.104 |
VNC unauthorized session established.
|
Port Scan Hacking | |
| π³π± 93.123.109.228 |
HTTP attack detected: GET / (probe). UA: l9tcpid/v1.1.0
|
Port Scan Web App Attack | |
| π§πͺ 198.235.24.231 |
SNMP query: community="public", version=1, OIDs=[1.3.6.1.2.1]
|
Port Scan Hacking | |
| π³π± 89.248.173.216 |
|
Port Scan Web App Attack | |
| π§πͺ 35.240.92.12 |
FTP unauthorized access: "USER anonymous"
|
FTP Brute-Force Brute-Force | |
| π³π± 77.239.124.250 |
SSH brute-force login detected. Automated IDS report.
|
Brute-Force SSH | |
| πΊπΈ 72.167.41.202 |
HTTP tarpit triggered at /.env.local. Scanner trapped for ~30s. UA: axios/1.18.0
|
Bad Web Bot Web App Attack |