AbuseIPDB » 47.254.238.61
IP info including ISP, Usage Type, and Location provided by IPInfo. Updated weekly.
Top Reporter Countries (Last 60 Days)
Example previewReport Categories (Last 60 Days)
Example previewIP Abuse Reports for 47.254.238.61:
This IP address has been reported a total of 1,620 times from 170 distinct sources. 47.254.238.61 was first reported on , and the most recent report was . In the last 60 days, the top reporter locations were: United States of America with 245 reports; Germany with 43 reports; France with 23 reports. The most common categories in these recent reports were: Port Scan 365 times; Hacking 41 times; Brute-Force 33 times; Web App Attack 9 times; Exploited Host 6 times; Other 9 times.
| Reporter | IoA Timestamp (UTC) | Comment | Categories | |
|---|---|---|---|---|
| 🇺🇸 etu brutus |
47.254.238.61 Blocked by [Attack Vector List]
...
|
Hacking Brute-Force Exploited Host | ||
| 🇹🇭 Sawasdee |
Port Scan
...
|
Port Scan | ||
| 🇯🇵 S.O.B.A. Dev. |
Persistent port scanning or vulnerability scanning
|
Port Scan | ||
| 🇺🇸 sandra361 |
|
Port Scan | ||
| 🇺🇸 MPL |
tcp/9993
|
Port Scan | ||
| 🇺🇸 Starburst SysOp Team |
Host header is a numeric IP address. Pattern match "(?:^( (920350-mnz6-1)
|
Hacking Bad Web Bot | ||
| 🇺🇸 RAP |
2026-09-10 08:47:55 UTC Unauthorized activity to TCP port 8080. Web App
|
Port Scan Web App Attack | ||
| 🇺🇸 MPL |
tcp/5595 (2 or more attempts)
|
Port Scan | ||
| 🇪🇸 raiolanetworks.com |
|
Port Scan | ||
| 🇺🇸 MPL |
tcp/12262 (2 or more attempts)
|
Port Scan | ||
| 🇩🇪 Jochen Pretli |
connection to honeypot
|
Email Spam Port Scan | ||
| 🇬🇧 Andrew |
|
Port Scan | ||
| 🇺🇸 MPL |
tcp/12222
|
Port Scan | ||
| 🇺🇸 MPL |
tcp ports: 7890,12222 (2 or more attempts)
|
Port Scan | ||
| 🇨🇭 pingusurmars |
|
Port Scan |
Think this IP has been falsely reported? You may request to have the associated reports reviewed and removed. Request Takedown 🚩