This IP address has been reported a total of
34
times from
20 distinct
sources.
182.48.89.9 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 8
reports;
Germany
with 2
reports;
Switzerland
with 1
report.
The most common categories in these recent reports were:
Bad Web Bot
10
times;
DDoS Attack
5
times;
Web App Attack
4
times;
Brute-Force
2
times;
Hacking
2
times;
Other
3
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0. ...
show moreMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
show less
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0. ...
show moreMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
show less
L7 DDoS: distributed flood on a shop's faceted search โ automated requests to search/sort URLs, one ...
show moreL7 DDoS: distributed flood on a shop's faceted search โ automated requests to search/sort URLs, one or two per address from thousands of addresses, no page assets loaded | path: /marque/8-orbea | query: q=Mat%C3%A9riau-Carbone/Famille-Oiz-Terra+Race-Wild | 2026-09-17 03:12 UTC
show less
Botnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordu ...
show moreBotnet UDP flood (DDoS) against a hosted game server at 185.143.177.x:5555/udp in AS203136 (LLC Ordunet), Georgia, on 2026-09-15 from 14:17 local time (+04:00). This source sustained more than 800 packets/sec toward a single UDP port, against about 200 packets/sec for a legitimate player of that server. It was one of 8847 sources in 2396 networks and 160 countries recorded inside a single 25-minute window - the server's entire real audience is about a hundred players. Detected on a MikroTik RouterOS router in the raw/prerouting chain (dst-limit 800,200,src-address/10s); the timestamp is when this source crossed the threshold. Not a scan and not brute force - a packet flood, so the host is most likely compromised. Evidence: [email protected].
show less
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0. ...
show moreMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36
show less
Bad Web Bot
Anonymous
Large-scale coordinated botnet (3M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/S ...
show moreLarge-scale coordinated botnet (3M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/Shursky [yordim|LIS|MOW]); Attacker: Mikhail Smirnov (mikhail-smirnov-79830323/Aidan [MOW]) employed by Angara Technologies Group | Attack Signature Blocked: /catalog/product_compare/add/product/10853/uenc/aHR0cHM6Ly93d3cuZDJvZmZpY2UucnUvY2F0YWxvZ3NlYXJjaC9yZXN1bHQvP2NhdD00OCZhbXA7aXB0ZWxfdHlwZT0xNzAmYW1wO21vZGU9Z3JpZCZhbXA7cT1leCs5MA,,/form_key/s4XajXoAVjiGPIAv/ | UA: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_7_7) AppleWebKit/531.1 (KHTML, like Gecko) Chrome/46.0.853.0 Safari/531.1 | (Magento Site)
show less
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0. ...
show moreMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
show less
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa ...
show moreMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
DDoS flood attack against 82.152.54.0 (2026-08-20 16:18:25 -> 2026-08-20 16:33:25 UTC) targeting AS2 ...
show moreDDoS flood attack against 82.152.54.0 (2026-08-20 16:18:25 -> 2026-08-20 16:33:25 UTC) targeting AS215599. This IP (AS63969) sent ~5997 packets (8.52 MB) during the attack window. Likely a compromised device (botnet).
show less