This IP address has been reported a total of
105
times from
80 distinct
sources.
196.11.179.18 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
5 incidents: port scanning. First: 2026-06-04 06:41, Last: 2026-06-04 07:30 UTC. Triggers: port-trap ...
show more5 incidents: port scanning. First: 2026-06-04 06:41, Last: 2026-06-04 07:30 UTC. Triggers: port-trap,non-public-port,firewall-tcp,ufw-repeater,recidive.
show less
Blocked by UFW [23/tcp]
Source port: 25405
TTL: 44
Packet length: 44
TOS: 0x00
This report was gene ...
show moreBlocked by UFW [23/tcp]
Source port: 25405
TTL: 44
Packet length: 44
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
[Tue May 26 11:51:57.526380 2026] [security2:error] [pid 765164:tid 140291022501568] [client 196.11. ...
show more[Tue May 26 11:51:57.526380 2026] [security2:error] [pid 765164:tid 140291022501568] [client 196.11.179.18:59626] ModSecurity: Access denied with code 403 (phase 1). Match of "eq 0" against "&REQUEST_HEADERS:Transfer-Encoding" required. [file "/etc/modsecurity/coreruleset-4.26.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "857"] [id "920171"] [msg "GET or HEAD Request with Transfer-Encoding"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: GET found within REQUEST_HEADERS: 1 request_line = GET /index.php/informasi-iklim/infografis-iklim/infografis-tahunan HTTP/2.0 Request URI RAW = /index.php/informasi-iklim/infografis-iklim/infografis-tahunan Request Basename = infografis-tahunan"] [severity "CRITICAL"] [ver "OWASP_CRS/4.26.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "cape
...
show less
Generic malicious activity detected: Tentativa de varredura de porta TCP... | Proto: TCP | Port: 596 ...
show moreGeneric malicious activity detected: Tentativa de varredura de porta TCP... | Proto: TCP | Port: 59601 | Location: South Africa, Johannesburg
show less
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
Reported from Nginx log analysis 18. Log: 196.11.179.18 - - [10/Feb/2026:xx:xx:xx 0100] "GET /tag/c ...
show moreReported from Nginx log analysis 18. Log: 196.11.179.18 - - [10/Feb/2026:xx:xx:xx 0100] "GET /tag/chase HTTP/1.1" xxx xxx "https://siyge.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36" "-" "ZA South Africa Springs" "AS327996" "ACCELERIT"
show less
Port Scan
Brute-Force
SSH
Anonymous
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show moreDistributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in thread-skip.asp
show less