This IP address has been reported a total of
13
times from
11 distinct
sources.
196.188.228.0 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 3
reports;
Czechia
with 1
report;
France
with 1
report.
The most common categories in these recent reports were:
DDoS Attack
5
times;
Web App Attack
4
times;
Hacking
2
times;
Bad Web Bot
1
time;
Exploited Host
1
time;
Other
1
time.
Old Reports
The most recent abuse report for this IP address is from
. It is possible that this IP is no
longer involved in abusive activities.
Unauthorized VPN login attempts: 1 attempts were recorded from 196.188.228.0
2026-09-30T18:56:46+02: ...
show moreUnauthorized VPN login attempts: 1 attempts were recorded from 196.188.228.0
2026-09-30T18:56:46+02:00 vpn Access-Reject 'xvagr01' station: 196.188.228.0 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Repeated requests classified as pathological web bot behavior, for example: /[redacted]/search?f%5B0 ...
show moreRepeated requests classified as pathological web bot behavior, for example: /[redacted]/search?f%5B0%5D=digest_edition%3A504&f%5B1%5D=digest_key_terms%3A327&f%5B2%5D=digest_key_terms%3A517&field_article_edition%5B504%5D=504&field_key_terms%5B324%5D=324 (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36")
show less
DDoS flood attack against 31.56.58.23 (2026-08-15 17:54:21 -> 2026-08-15 18:09:21 UTC) targeting AS2 ...
show moreDDoS flood attack against 31.56.58.23 (2026-08-15 17:54:21 -> 2026-08-15 18:09:21 UTC) targeting AS215599. This IP (AS24757) sent ~293 packets (0.39 MB) during the attack window. Likely a compromised device (botnet).
show less
Automated Layer 7 DDoS attack on e-commerce platform (mr-hanf.de). IP sent 32 malicious requests in ...
show moreAutomated Layer 7 DDoS attack on e-commerce platform (mr-hanf.de). IP sent 32 malicious requests in 24h (BUYproducts_id + wishlist flooding). Attack pattern: automated cart/wishlist manipulation to exhaust server resources. First seen: 12/Aug/2026:10:00:38 +0200, Last seen: 12/Aug/2026:14:04:27 +0200
show less
Automated Layer 7 DDoS attack on e-commerce platform (mr-hanf.de). IP sent 39 malicious requests in ...
show moreAutomated Layer 7 DDoS attack on e-commerce platform (mr-hanf.de). IP sent 39 malicious requests in 24h (BUYproducts_id + wishlist flooding). Attack pattern: automated cart/wishlist manipulation to exhaust server resources. First seen: 12/Aug/2026:10:00:38 +0200, Last seen: 11/Aug/2026:14:30:21 +0200
show less
Distributed L7 HTTP flood (DDoS) - participated in a coordinated flood of a website homepage | req: ...
show moreDistributed L7 HTTP flood (DDoS) - participated in a coordinated flood of a website homepage | req: /?q=i0yQvi&iUPgm5M | 3 distinct paths | UA: Mozilla/5.0 (Android 14; Mobile; rv:145.0) Gecko/145.0 Firefox/145.0
show less
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Mozilla/5.0 (Macintosh; ...
show moreCrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/67.0.0.0 Safari/537.36
show less
Bad web bot: Spoofed/obsolete UA (Opera/9.21.(Windows 98; Win 9x 4.90; oc-FR) Presto/2.9.183 Version ...
show moreBad web bot: Spoofed/obsolete UA (Opera/9.21.(Windows 98; Win 9x 4.90; oc-FR) Presto/2.9.183 Version/10.00). Mass-scanning WordPress plugin. Coordinated large-scale bot attack.
show less