This IP address has been reported a total of
11
times from
9 distinct
sources.
166.88.89.30 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
L7 DDoS: distributed flood on a shop's faceted search โ automated requests to search/sort URLs, one ...
show moreL7 DDoS: distributed flood on a shop's faceted search โ automated requests to search/sort URLs, one or two per address from thousands of addresses, no page assets loaded | path: /18-velo-route | query: q=Stock+magasin-Cycling+H%C3%A9nin%5C-Beaumont-Cycling+Montpellier/Taille-XS-XL/Famille-Metrix-Pulsium-Xelius-Addict+RC&order=pr
show less
Blocked abusive HTTP application-layer DoS / botnet traffic from 166.88.89.30: traffic from this add ...
show moreBlocked abusive HTTP application-layer DoS / botnet traffic from 166.88.89.30: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
Blocked abusive HTTP application-layer DoS / botnet traffic from 166.88.89.30: traffic from this add ...
show moreBlocked abusive HTTP application-layer DoS / botnet traffic from 166.88.89.30: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
Coordinated application-layer DDoS against git.mills.io (self-hosted Gitea), 2026-06-12 ~20:30-21:10 ...
show moreCoordinated application-layer DDoS against git.mills.io (self-hosted Gitea), 2026-06-12 ~20:30-21:10 UTC. Deliberately expensive multi-label Gitea issue-search queries (/issues?type=all&state=closed&sort=...&labels=<multiple IDs>, ~60-113s CPU each) flooded the backend via proxy/hosting networks. ~36,700 source IPs, ~1 request per IP, identical TLS fingerprint (TLS1.3 0x1301) and one spoofed Chrome UA = single automated tool.
show less
Triggered Cloudflare WAF (firewallCustom) from PL.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/2 ...
show moreTriggered Cloudflare WAF (firewallCustom) from PL.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/2 (GET method)
Endpoint: /documentation
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.3
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Showing 1 to
11
of 11 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ