AbuseIPDB » 189.123.96.1

189.123.96.1 was found in our database!

This IP was reported 16 times. Confidence of Abuse is 32%: ?

32%
ISP Claro NXT Telecomunicacoes Ltda
Usage Type Fixed Line ISP
ASN AS28573
Hostname(s) bd7b6001.virtua.com.br
Domain Name claro.com.br
Country ๐Ÿ‡ง๐Ÿ‡ท Brazil
City Ribeirao Preto, Sao Paulo

IP info including ISP, Usage Type, and Location provided by IPInfo. Updated weekly.

IP Abuse Reports for 189.123.96.1:

This IP address has been reported a total of 16 times from 12 distinct sources. 189.123.96.1 was first reported on , and the most recent report was .

Recent Reports: We have received reports of abusive activity from this IP address within the last week. It is potentially still actively engaged in abusive activities.

Reporter IoA Timestamp (UTC) Comment Categories
๐Ÿ‡ธ๐Ÿ‡ช NordhTech
More than 3 malicious connection attempts, trying port(s) 7338/tcp, then blocked from services ...
Port Scan Hacking
Anonymous
Port Scan
๐Ÿ‡ซ๐Ÿ‡ท Duggy_Tuxy๐Ÿงฑ
[DS-BLKS-PROD01] Blocked by SysWarden Firewall (Traffic from Blocked Country (GeoIP))
Port Scan
๐Ÿ‡บ๐Ÿ‡ธ Cyber Crusader
Hundreds of Attempts (at least) to Connect to and Access Firewall Ports
Port Scan Hacking Brute-Force
Anonymous
unsolicited UDP packet to port 33695 (1380 bytes)
Hacking
Anonymous
unsolicited UDP packet to port 65133 (26 bytes)
Hacking
๐Ÿ‡ฉ๐Ÿ‡ช AS213449.net
04/25/2026-23:37:59.027342 189.123.96.1 ET SCAN Suspicious inbound to mySQL port 3306
SQL Injection
๐Ÿ‡บ๐Ÿ‡ธ Cyber Crusader
Hundreds of Attempts (at least) to Connect to and Access Firewall Ports
Port Scan Hacking Brute-Force
Anonymous
Unauthorized connection attempt
Port Scan Hacking Exploited Host
Anonymous
Unauthorized connection attempt
Port Scan Hacking Exploited Host
๐Ÿ‡บ๐Ÿ‡ธ quilla
Botnet infected device observed in honeypot (Vector: TCP HANDSHAKE ATTACK)
DDoS Attack
๐Ÿ‡จ๐Ÿ‡ฆ polycoda
๐Ÿฅถ Part of massive botnet scraping campaign that nearly turned into a DDoS on 2025-11-27
DDoS Attack
๐Ÿ‡ฉ๐Ÿ‡ช SMARTNET
Aisuru(Mirai variant) DDoS
DDoS Attack
Anonymous
scanning http requests from known botnet
Web App Attack
Anonymous
scanning http requests from known botnet
Web App Attack

Showing 1 to 15 of 16 reports


Think this IP has been falsely reported? You may request to have the associated reports reviewed and removed. Request Takedown ๐Ÿšฉ

Recently Reported IPs:

๐Ÿ‡ฉ๐Ÿ‡ช 212.227.203.59
๐Ÿ‡ณ๐Ÿ‡ฑ 204.76.203.79
๐Ÿ‡ฉ๐Ÿ‡ช 193.124.20.229
๐Ÿ‡ธ๐Ÿ‡ช 185.189.46.67
๐Ÿ‡ฎ๐Ÿ‡ณ 152.57.126.230
๐Ÿ‡ธ๐Ÿ‡ฌ 84.247.151.140
๐Ÿ‡บ๐Ÿ‡ธ 71.6.134.230
๐Ÿ‡บ๐Ÿ‡ธ 23.95.191.250
๐Ÿ‡ฌ๐Ÿ‡ง 5.226.140.117
๐Ÿ‡จ๐Ÿ‡ณ 223.144.195.128
๐Ÿ‡ต๐Ÿ‡ฐ 182.188.123.65
๐Ÿ‡ญ๐Ÿ‡ฐ 152.32.128.204
๐Ÿ‡น๐Ÿ‡ท 104.28.154.251
๐Ÿ‡ท๐Ÿ‡ด 81.180.93.2
๐Ÿ‡ง๐Ÿ‡ฌ 79.124.62.126
๐Ÿ‡ฏ๐Ÿ‡ต 72.63.16.216
๐Ÿ‡ฑ๐Ÿ‡น 45.227.254.170
๐Ÿ‡บ๐Ÿ‡ธ 24.5.244.85
๐Ÿ‡ฎ๐Ÿ‡ช 20.13.164.162