This IP address has been reported a total of
15
times from
13 distinct
sources.
196.191.221.134 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 2
reports;
Czechia
with 1
report;
United Kingdom of Great Britain and Northern Ireland
with 1
report.
The most common categories in these recent reports were:
Bad Web Bot
2
times;
Port Scan
1
time;
Brute-Force
1
time.
Old Reports
The most recent abuse report for this IP address is from
. It is possible that this IP is no
longer involved in abusive activities.
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36 Edg/144.0.0.0
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0
show less
Email account brute force: 1 attempts were recorded from 196.191.221.134
2026-08-21T11:18:46+02:00 w ...
show moreEmail account brute force: 1 attempts were recorded from 196.191.221.134
2026-08-21T11:18:46+02:00 warning: unknown[196.191.221.134]: SASL PLAIN authentication failed: authentication failure, [email protected]show less
Brute-Force
Anonymous
Blocked by ModSec and CSF
Port Scan
Anonymous
SMTP brute force - auth failed
Brute-Force
Exploited Host
Anonymous
Large-scale coordinated botnet (777+k IPs). Attacker: mikhail-smirnov-79830323 (LinkedIn/profile ID) ...
show moreLarge-scale coordinated botnet (777+k IPs). Attacker: mikhail-smirnov-79830323 (LinkedIn/profile ID) employed by Angara Technologies Group (Explicitly identified himself as enemy a week before attack began) | Attack Signature Blocked: /wishlist/index/add/product/9801/form_key/byEbSMse6JIDnqAC/ | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5 rv:6.0; my-MM) AppleWebKit/533.47.6 (KHTML, like Gecko) Version/4.0 Safari/533.47.6 | (Magento Site)
show less
Bad web bot: Spoofed/obsolete UA (Mozilla/5.0 (compatible; MSIE 8.0; Windows NT 11.0; Trident/5.1)). ...
show moreBad web bot: Spoofed/obsolete UA (Mozilla/5.0 (compatible; MSIE 8.0; Windows NT 11.0; Trident/5.1)). Mass-scanning WordPress plugin. Coordinated large-scale bot attack.
show less
Confirmed malicious activity observed via T-Pot honeypot Observed 18 events on port 443 (unknown) fr ...
show moreConfirmed malicious activity observed via T-Pot honeypot Observed 18 events on port 443 (unknown) from 2025-12-31T14:13:48+00:00 to 2025-12-31T18:40:46.204000+00:00. Sample: {"src_ip": "196.191.221.134", "event_type": "flow", "dest_port": 443, "src_port": 4833}
show less
Confirmed malicious activity observed via T-Pot honeypot Observed 8 events on port 443 (unknown) fro ...
show moreConfirmed malicious activity observed via T-Pot honeypot Observed 8 events on port 443 (unknown) from 2025-12-30T12:12:10+00:00 to 2025-12-30T12:14:35.521000+00:00. Sample: {"dest_port": 443, "src_port": 43461, "src_ip": "196.191.221.134"}
show less