178.132.198.203

Classification: Malicious

178.132.198.203 is a malicious IP address. Reported by 5 threat sources, last seen 2026-09-03. Network: AS213920 Private Customer.

Current activity

  • Known attacker — Seen launching attacks over the Internet.
  • Known scanner — Seen scanning hosts over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
ET CINS Active Threat Intelligence Poor Reputation IP UDP Emerging Threats 2026-08-27 09:14:50 2026-09-03 09:14:47 malicious-activity
ET CINS Active Threat Intelligence Poor Reputation IP TCP Emerging Threats 2026-08-27 09:14:49 2026-09-03 09:14:45 malicious-activity
HTTP bot Blocklist.de 2026-08-26 08:00:47 2026-09-03 08:00:36 attacker malicious-activity
Malicious Host CIArmy 2026-08-26 20:03:32 2026-09-02 20:03:17 attacker malicious-activity
Malicious Host HoneyDB 2026-08-25 00:00:00 2026-08-25 00:00:00 attacker malicious-activity
SSH Attacker Blocklist.de 2026-08-23 14:00:33 2026-08-23 14:00:33 attacker malicious-activity
SSH Attacker AbuseIPDB 2026-08-22 10:57:55 2026-08-23 13:49:58 attacker malicious-activity
Bruteforce AbuseIPDB 2026-08-22 10:44:27 2026-08-23 13:49:58 attacker malicious-activity
Port Scanner AbuseIPDB 2026-08-22 17:19:42 2026-08-23 12:50:15 anomalous-activity attacker malicious-activity reconnaissance
HTTP Scrapper AbuseIPDB 2026-08-22 10:44:27 2026-08-23 12:06:08 anomalous-activity attacker malicious-activity
HTTP Attacker AbuseIPDB 2026-08-22 10:44:27 2026-08-23 12:06:08 attacker malicious-activity
Hacking AbuseIPDB 2026-08-22 17:19:42 2026-08-23 04:18:09 attacker malicious-activity

Tags

ssh bruteforce bot attacker spam

Whois information

AS name
AS213920 Private Customer
Registrant
Private Customer
City
Sao Paulo
Postal code
1002
Country
BR — Brazil 🇧🇷
First indexed
2026-08-23 14:00:33
Last updated
2026-09-03 09:15:03