This IP address has been reported a total of
342
times from
70 distinct
sources.
118.196.87.226 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
2026-06-14T03:44:48.408539+01:00 vps kernel: [43145245.530814] [PORTSCAN DETECTED] IN=ens3 OUT= MAC= ...
show more2026-06-14T03:44:48.408539+01:00 vps kernel: [43145245.530814] [PORTSCAN DETECTED] IN=ens3 OUT= MAC=fa:16:3e:66:f6:24:02:37:19:0d:c2:f3:08:00 SRC=118.196.87.226 DST=54.37.14.118 LEN=60 TOS=0x00 PREC=0x20 TTL=42 ID=30291 DF PROTO=TCP SPT=55100 DPT=6379 WINDOW=29200 RES=0x00 SYN URGP=0
...
show less
byebyte.space auth: TCP packet to port 6379 (Redis) at 2026-06-13T22:44:27Z. Source port 37052. TCP ...
show morebyebyte.space auth: TCP packet to port 6379 (Redis) at 2026-06-13T22:44:27Z. Source port 37052. TCP flags: SYN. Packet: 60B, TTL 43, window 29200, IP id 5348. Single packet, dropped at firewall. p0f: OS Linux 3.11 and newer (exact match), 21 hops, link Ethernet or modem.
show less
Port scan from this IP. Firewall dropped every packet. Targeted TCP ports: 6379. Activity window: 20 ...
show morePort scan from this IP. Firewall dropped every packet. Targeted TCP ports: 6379. Activity window: 2026-06-07 13:06 UTC to 2026-06-13 22:44 UTC.
show less
Unauthorized connection attempt detected from IP address 118.196.87.226 to port 6379 (ger-02) [REDIS ...
show moreUnauthorized connection attempt detected from IP address 118.196.87.226 to port 6379 (ger-02) [REDIS]
show less
OpenCanary honeypot hit on port 6379 (no legitimate service runs there); logtype 17001. Automated re ...
show moreOpenCanary honeypot hit on port 6379 (no legitimate service runs there); logtype 17001. Automated report.
show less
byebyte.space auth: TCP packet to port 6379 (Redis) at 2026-06-12T11:58:35Z. Source port 55824. TCP ...
show morebyebyte.space auth: TCP packet to port 6379 (Redis) at 2026-06-12T11:58:35Z. Source port 55824. TCP flags: SYN. Packet: 60B, TTL 43, window 29200, IP id 833. Single packet, dropped at firewall. p0f: OS Linux 3.11 and newer (exact match), 21 hops, link Ethernet or modem.
show less
[rede-164-29] 06/12/2026-08:36:25.298289, 118.196.87.226, Protocol: 6, ET CINS Active Threat Intelli ...
show more[rede-164-29] 06/12/2026-08:36:25.298289, 118.196.87.226, Protocol: 6, ET CINS Active Threat Intelligence Poor Reputation IP group 163
show less
Hacking
Anonymous
2026-06-12T03:33:49.279432+01:00 vps kernel: [42971788.330030] [PORTSCAN DETECTED] IN=ens3 OUT= MAC= ...
show more2026-06-12T03:33:49.279432+01:00 vps kernel: [42971788.330030] [PORTSCAN DETECTED] IN=ens3 OUT= MAC=fa:16:3e:66:f6:24:02:37:19:0d:c2:f3:08:00 SRC=118.196.87.226 DST=54.37.14.118 LEN=60 TOS=0x00 PREC=0x20 TTL=42 ID=6518 DF PROTO=TCP SPT=40318 DPT=6379 WINDOW=29200 RES=0x00 SYN URGP=0
...
show less
Blocked by UFW on ampereone [6379/tcp]
Source port: 44970
TTL: 44
Packet length: 60
TOS: 0x00
This ...
show moreBlocked by UFW on ampereone [6379/tcp]
Source port: 44970
TTL: 44
Packet length: 60
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Showing 1 to
15
of 342 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ