This IP address has been reported a total of
23
times from
21 distinct
sources.
197.211.52.4 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
1 attack(s) detected, such as these: {"event":"spam_block","ip":"197.211.52.4","host":"receiver mail ...
show more1 attack(s) detected, such as these: {"event":"spam_block","ip":"197.211.52.4","host":"receiver mail server","request":"unsolicited bulk mail via SMTP port 25","reason":"Proxmox Mail Gateway (PMG) triggered a block. Source exhibits persistent spam behavior, violating RFC mail standards."} * Report Details *: https://p4u.xyz/FDD755HSBXW/1* IP Details *: https://p4u.xyz/FDD755HSBXW/2
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36 Edg/144.0.0.0
show less
UDP flood (DDoS) vs AS215599: 347 pkts / 0.5 MB to UDP 8443 across 211 dst IP(s), 2026-08-19 21:46 t ...
show moreUDP flood (DDoS) vs AS215599: 347 pkts / 0.5 MB to UDP 8443 across 211 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
UDP flood (DDoS) vs AS215599: 347 pkts / 0.5 MB to UDP 8443 across 211 dst IP(s), 2026-08-19 21:46 t ...
show moreUDP flood (DDoS) vs AS215599: 347 pkts / 0.5 MB to UDP 8443 across 211 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
PortSentry honeypot: unsolicited TCP connection to closed decoy port 445 (SMB) on a host running no ...
show morePortSentry honeypot: unsolicited TCP connection to closed decoy port 445 (SMB) on a host running no such service. Automated port-scan detection at 2026-08-17T10:57:13Z.
show less
Received: from 50.6.200.195 (EHLO server-630313.itechinnovate.com) by 10.196.216.84 with SMTPs (vers ...
show moreReceived: from 50.6.200.195 (EHLO server-630313.itechinnovate.com) by 10.196.216.84 with SMTPs (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256); Sun, 09 Aug 2026 09:20:25 +0000 Received: from [197.211.52.4] (port=15662 helo=[192.168.8.101]) by server-630313.itechinnovate.com with esmtpa (Exim 4.99.5) (envelope-from <[email protected]>) id 1wszhY-00000009P6O-1AVK; Subject: Re:Hello To: Recipients <[email protected]> From: "Gina Rinehart" <[email protected]> Reply-To: [email protected] Return-Path: <[email protected]> X-Originating-Ip: [50.6.200.195] Received-SPF: fail (domain of teamnogueiradubai.com does not designate 50.6.200.195 as permitted sender) Authentication-Results: mta.yahoo.com; dkim=unknown; spf=fail smtp.mailfrom=teamnogueiradubai.com arc_overridden_status=NOT_OVERRIDDEN;
show less
Fraud Orders
DDoS Attack
Web Spam
Email Spam
Port Scan
Spoofing
Brute-Force
Exploited Host
FTP Brute-Force
Phishing
Hacking
CrowdSec: Distributed L7 HTTP flood on WordPress 'The Events Calendar' AJAX endpoints (request_forma ...
show moreCrowdSec: Distributed L7 HTTP flood on WordPress 'The Events Calendar' AJAX endpoints (request_format~json) - DDoS | req: /calendrier-2/action~agenda/cat_ids~297,360/tag_ids~385,578,611,590,747,573,451,448,581/request_format~json/ | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
show less
DDoS Attack
Web App Attack
Showing 1 to
15
of 23 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ