This IP address has been reported a total of
62
times from
37 distinct
sources.
150.109.154.56 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
Large-scale coordinated botnet (5M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/S ...
show moreLarge-scale coordinated botnet (5M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/Shursky [yordim|LIS|MOW]): Retaliation after theft; Attacker: Mikhail Smirnov (mikhail-smirnov-79830323/Aidan [MOW]): Employed by Angara Technologies Group | Magento Session ID Parameter Blocked: /multimedia/display/display/shopby/screensize-42-46-47-90.html?___SID=7bcb7e82d2f317b0ee3729548334056fU | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36 | (Magento Site)
show less
Blocked by UFW (TCP on 443)
Source port: 37054
TTL: 51
Packet length: 60
TOS: 0x00
This report (for ...
show moreBlocked by UFW (TCP on 443)
Source port: 37054
TTL: 51
Packet length: 60
TOS: 0x00
This report (for 150.109.154.56) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Blocked abusive HTTP application-layer DoS / botnet traffic from 150.109.154.56: traffic from this a ...
show moreBlocked abusive HTTP application-layer DoS / botnet traffic from 150.109.154.56: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
HTTP application-layer DoS / botnet traffic from 150.109.154.56: repeated high-cost dynamic page and ...
show moreHTTP application-layer DoS / botnet traffic from 150.109.154.56: repeated high-cost dynamic page and feed requests (profile/tag views, forums, tracker, RSS) at abusive rates via completed TCP/HTTPS. Likely compromised end-user host.
show less
Triggered Cloudflare WAF (firewallCustom) from HK.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (G ...
show moreTriggered Cloudflare WAF (firewallCustom) from HK.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (GET) | Endpoint: /ip | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 β’ Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Enumerating paths that do not exist (scanning) | method: GET | path: /ip | ua: Mozilla/5.0 (Macintos ...
show moreEnumerating paths that do not exist (scanning) | method: GET | path: /ip | ua: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 | 2026-09-08 20:25 UTC
show less
HTTP application-layer DoS / botnet traffic from 150.109.154.56: repeated high-cost dynamic page and ...
show moreHTTP application-layer DoS / botnet traffic from 150.109.154.56: repeated high-cost dynamic page and feed requests (profile/tag views, forums, tracker, RSS) at abusive rates via completed TCP/HTTPS. Likely compromised end-user host.
show less
Suspicious WooCommerce query combination detected. Not default available on websites. Matched combi ...
show moreSuspicious WooCommerce query combination detected. Not default available on websites. Matched combi patterns: filter_, add-to-cart=, orderby=, product_count=. Activity is consistent with high-volume request abuse.
show less