AbuseIPDB » 176.96.136.232
176.96.136.232 was found in our database!
This IP was reported 8 times. Confidence of
Abuse
is 53% : ?
ISP
dataforest GmbH
Usage Type
Data Center/Web Hosting/Transit
ASN
AS58212
Domain Name
dataforest.net
Country
๐ฉ๐ช
Germany
City
Frankfurt am Main, Hesse
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 176.96.136.232 :
This IP address has been reported a total of
8
times from
8 distinct
sources.
176.96.136.232 was first reported on
June 14th 2026 , and the most recent report was
2 days ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐บ๐ธ
cwytech
2026-06-18 22:38:46
(2 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/pf-geofence-high.
Hacking
๐ฉ๐ช
ValtonTahiri
2026-06-18 22:23:05
(2 days ago)
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly as ...
show more
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly associated with port scanning, service discovery, or automated internet probing. Technical: source_ip=176.96.136.232; proto=UDP; source_port=41330; target_port=53413
show less
Port Scan
๐ฉ๐ช
KPS
2026-06-18 21:51:48
(2 days ago)
PortscanM
Port Scan
Anonymous
2026-06-18 20:49:29
(2 days ago)
Jun 18 16:18:02 localhost kernel: [110159167.150362] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:9 ...
show more
Jun 18 16:18:02 localhost kernel: [110159167.150362] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=176.96.136.232 DST=[mungedIP2] LEN=28 TOS=0x00 PREC=0x00 TTL=53 ID=38976 DF PROTO=UDP SPT=40223 DPT=53413 LEN=8
Jun 18 16:18:02 localhost kernel: [110159167.150383] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=176.96.136.232 DST=[mungedIP2] LEN=28 TOS=0x00 PREC=0x00 TTL=53 ID=38976 DF PROTO=UDP SPT=40223 DPT=53413 LEN=8
Jun 18 16:49:28 localhost kernel: [110161053.037845] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=176.96.136.232 DST=[mungedIP2] LEN=28 TOS=0x00 PREC=0x00 TTL=53 ID=48341 DF PROTO=UDP SPT=40074 DPT=53413 LEN=8
Jun 18 16:49:28 localhost kernel: [110161053.037863] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=176.96.136.232 DST=[mungedIP2] LEN=28 TOS=0x00 PREC=0x00 TTL=53 ID=48341 DF PROTO=UDP SPT=40074 DPT=53413 LEN=8
show less
Port Scan
๐ง๐ท
chronos
2026-06-18 20:35:17
(2 days ago)
Port scanning detected. Protocol anomaly. | Port: 53413 | Proto: UDP | Location: Germany, Frankfurt ...
show more
Port scanning detected. Protocol anomaly. | Port: 53413 | Proto: UDP | Location: Germany, Frankfurt am Main
show less
Port Scan
๐ฉ๐ช
iNetWorker
2026-06-18 19:51:02
(2 days ago)
firewall-block, port(s): 53413/udp
Port Scan
๐ฉ๐ช
phil2k
2026-06-18 19:40:56
(2 days ago)
fail2ban:firewall:2026-06-18T21:26:23.040881+02:00 <SRV> firewall: filter IN=<ANONYMIZED_INTERFACE> ...
show more
fail2ban:firewall:2026-06-18T21:26:23.040881+02:00 <SRV> firewall: filter IN=<ANONYMIZED_INTERFACE> OUT= MAC=<ANONYMIZED_MAC> SRC=176.96.136.232 DST=<PRIVATE_IPv4> LEN=28 TOS=0x00 PREC=0x00 TTL=52 ID=20537 DF PROTO=UDP SPT=40081 DPT=53413 LEN=8
2026-06-18T21:40:53.199869+02:00 <SRV> firewall: filter IN=<ANONYMIZED_INTERFACE> OUT= MAC=<ANONYMIZED_MAC> SRC=176.96.136.232 DST=<PRIVATE_IPv4> LEN=28 TOS=0x00 PREC=0x00 TTL=52 ID=56838 DF PROTO=UDP SPT=41754 DPT=53413 LEN=8
show less
DDoS Attack
Port Scan
๐ณ๐ฑ
BIV
2026-06-14 21:25:16
(6 days ago)
Honeypot multi-source hit. Sources: tpot:Suricata. Ports: 54934. Automated tiered (T-Pot+DShield).
Port Scan
Hacking
Showing 1 to
8
of 8 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: