Abuse handling

AbuseIPDB & honeypot information.

XenonCloud actively works to keep the internet – and our platform – safer by detecting malicious activity and reporting it through AbuseIPDB.

Have you seen your IP address listed on AbuseIPDB?
If you have been detected by our systems, it means that your IP address has attempted to connect to one or more honeypots operated by XenonCloud or our partners and has exhibited behavior consistent with abuse or malicious activity.

What our honeypots do

Honeypots are intentionally exposed systems designed to attract and study malicious traffic.

  • They listen for suspicious connection attempts, brute-force logins, and exploit traffic.
  • They do not host real customer data or production services.
  • They help us identify compromised systems, scanners, and abusive hosts on the internet.

When an IP address repeatedly interacts with our honeypots in a way that matches known abuse patterns, it may be flagged and reported.

How we use AbuseIPDB

XenonCloud regularly reports verified abusive behavior to AbuseIPDB.

  • We submit reports for IPs that trigger our honeypots with high-confidence abuse signatures.
  • Reports typically include timestamps, target ports, and general attack categories (e.g. SSH brute-force, web exploit attempts).
  • We may also leverage AbuseIPDB data to protect our own customers from known abusive hosts.

Our goal is to contribute accurate, high-quality data to the wider security community while maintaining a safe environment for XenonCloud customers.

If your IP was reported

Being listed on AbuseIPDB does not automatically mean you personally did something wrong. It often indicates that:

  • Your server, workstation, or device may be compromised.
  • A misconfigured script, scanner, or security tool is behaving aggressively.
  • You are using a VPN, proxy, or shared hosting provider where another user is responsible.

We strongly recommend investigating and securing any systems associated with the affected IP address.

Steps you can take

  • Run up-to-date antivirus / anti-malware scans.
  • Verify that SSH, RDP, and other remote services are properly secured.
  • Rotate credentials and disable accounts that are no longer needed.
  • Check logs for unusual login attempts or outbound connections.

After you’ve secured your systems, you may use AbuseIPDB’s own dispute process to request a review or removal of reports, if appropriate.

Contacting XenonCloud about an abuse report

If you have questions about a specific report that you believe originated from a XenonCloud IP address, or if you’re a network operator investigating abuse, you can reach our abuse team using the contact form on this site.

Please include:

  • The IP address in question.
  • Relevant timestamps (with timezone).
  • Any log excerpts or reference links from AbuseIPDB.

We will review the request and, where appropriate, take action on customer accounts that violate our Acceptable Use Policy.

Security is a shared responsibility. Our honeypots and AbuseIPDB reporting are part of XenonCloud’s commitment to keeping our platform, our customers, and the wider internet more secure.