AbuseIPDB » 220.197.85.127
IP info including ISP, Usage Type, and Location provided by IPInfo. Updated weekly.
Top Reporter Countries (Last 60 Days)
Example previewReport Categories (Last 60 Days)
Example previewIP Abuse Reports for 220.197.85.127:
This IP address has been reported a total of 72 times from 34 distinct sources. 220.197.85.127 was first reported on , and the most recent report was . In the last 60 days, the top reporter locations were: United States of America with 21 reports; Germany with 11 reports; Mongolia with 5 reports. The most common categories in these recent reports were: Port Scan 39 times; Hacking 9 times; Brute-Force 5 times; Web App Attack 3 times; SSH 3 times; Other 4 times.
| Reporter | IoA Timestamp (UTC) | Comment | Categories | |
|---|---|---|---|---|
| 🇺🇸 MPL |
tcp/20880
|
Port Scan | ||
| 🇺🇸 MPL |
tcp/51005
|
Port Scan | ||
| 🇩🇪 conseilgouz |
coe- 404 : Too many 404 errors
|
Brute-Force | ||
| Anonymous |
PROTO=TCP DPT=28017
|
Port Scan Hacking | ||
| 🇺🇸 RAP |
2026-08-23 20:23:36 UTC Unauthorized activity to TCP port 3306.
|
Port Scan | ||
| 🇺🇸 MPL |
tcp/46154 (2 or more attempts)
|
Port Scan | ||
| 🇺🇸 MPL |
tcp/10008
|
Port Scan | ||
| 🇺🇸 MPL |
tcp/2370
|
Port Scan | ||
| 🇲🇳 Public CSIRT/CC of Mongolia |
Honeypot hit: Empty payload (likely service probe); 6030 [1] TCP
|
Port Scan | ||
| Anonymous |
denied traffic to a honeypot network. destination port 2112.
|
Port Scan Hacking | ||
| 🇦🇺 LiftUp Hosting |
Honeypot hit: MSSQL traffic (on 1433) without login credentials
|
Port Scan | ||
| 🇺🇸 MPL |
tcp/8649 (2 or more attempts)
|
Port Scan | ||
| 🇲🇳 Public CSIRT/CC of Mongolia |
Honeypot hit: Empty payload (likely service probe); 3689 [1] TCP
|
Port Scan | ||
| 🇫🇷 EvoX |
🛡️ Honeypot [bsts-tpot-sensor]: Unauthorized traffic (16 bytes of payload); 52200 [1] TCP
|
Port Scan | ||
| 🇺🇸 MPL |
tcp/11 (2 or more attempts)
|
Port Scan |
Think this IP has been falsely reported? You may request to have the associated reports reviewed and removed. Request Takedown 🚩