AbuseIPDB » 138.91.109.125

138.91.109.125
Activity Trending Down This IP hasn't received reports recently, which causes the score to decay.
8,180 reports found in our database
100% Critical
Abuse confidence score ?
ISP
Microsoft Corp
Usage Type
Data Center/Web Hosting/Transit
ASN
Domain Name
microsoft.com
Country
🇺🇸 United States of America
City
Dulles Town Center, Virginia

IP info including ISP, Usage Type, and Location provided by IPInfo. Updated weekly.

Log in to view charts and search reports for this IP. Log In

Top Reporter Countries (Last 60 Days)

Example preview

Report Categories (Last 60 Days)

Example preview

Reports Activity

Example preview
Account required for the enhanced features Log in Sign up

IP Abuse Reports for 138.91.109.125:

This IP address has been reported a total of 8,180 times from 580 distinct sources. 138.91.109.125 was first reported on , and the most recent report was . In the last 60 days, the top reporter locations were: United States of America with 425 reports; Germany with 106 reports; France with 47 reports. The most common categories in these recent reports were: Port Scan 655 times; Brute-Force 121 times; Hacking 115 times; Web App Attack 62 times; Bad Web Bot 23 times; Other 70 times.

Reporter IoA Timestamp (UTC) Comment Categories
🇺🇸 MPL
tcp/2096 (2 or more attempts)
Port Scan
🇺🇸 MPL
tcp ports: 4040,443 (4 or more attempts)
Port Scan
🇫🇷 thecocasio
Port Scan
🇳🇱 VMHeaven.io
Blocked by UFW [7077/tcp] Source port: 49367 TTL: 44 Packet length: 52
Port Scan
🇺🇸 MPL
tcp/9042 (2 or more attempts)
Port Scan
🇺🇸 gu-alvareza
ZGrab.Scanner
Port Scan
🇬🇧 OptimusGO
Port Scan Brute-Force
🇺🇸 Cyber Crusader
Hundreds of Attempts (at least) to Connect to and Access Firewall Ports
Port Scan Hacking Brute-Force
🇺🇸 MPL
tcp/27017 (2 or more attempts)
Port Scan
🇺🇸 MPL
tcp/194 (2 or more attempts)
Port Scan
🇧🇷 noconex
Port Scan Brute-Force SSH
🇺🇸 OceanTreasure
tcp/5900; Scan for open VNC remote desktop port (R18) @ 2026-08-23T18:20:43Z
Brute-Force
🇦🇱 router.al
08/23/2026-17:58:58.809797 138.91.109.125 Protocol: 6 ET SCAN Zmap User-Agent (Inbound)
Hacking
🇺🇸 MPL
tcp/8443
Port Scan
🇵🇱 sefinek.net
Port Scan

Showing 1 to 15 of 8180 reports


Think this IP has been falsely reported? You may request to have the associated reports reviewed and removed. Request Takedown 🚩

Recently Reported IPs:

🇩🇪 195.182.16.23
🇨🇳 123.138.203.163
🇨🇳 119.6.235.41
🇨🇳 116.179.32.168
🇳🇱 45.148.10.141
🇧🇷 16.5.0.244
🇮🇩 210.87.125.27
🇦🇷 201.231.46.99
🇷🇴 185.19.40.62
🇦🇿 158.181.40.117
🇮🇳 151.158.2.135
🇨🇳 119.96.158.238
🇨🇳 111.170.27.100
🇨🇳 106.125.210.171
🇩🇪 93.231.182.156
🇳🇱 91.92.42.183
🇫🇷 77.239.124.207
🇺🇸 64.62.156.212
🇺🇸 43.162.107.52
🇷🇺 158.46.253.46