This IP address has been reported a total of
19
times from
15 distinct
sources.
209.50.187.55 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 6
reports;
Czechia
with 2
reports;
Spain
with 1
report.
The most common categories in these recent reports were:
Web App Attack
9
times;
Hacking
4
times;
Brute-Force
2
times;
Bad Web Bot
2
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Requested known WordPress backdoor/scanner-only paths (config backups, .env, .git/config). No legiti ...
show moreRequested known WordPress backdoor/scanner-only paths (config backups, .env, .git/config). No legitimate use.
show less
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET DROP Spamhaus D ...
show moreThis IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET DROP Spamhaus DROP Listed Traffic Inbound group 66).
show less
Requested known WordPress backdoor/scanner-only paths (config backups, .env, .git/config). No legiti ...
show moreRequested known WordPress backdoor/scanner-only paths (config backups, .env, .git/config). No legitimate use.
show less
Unauthorized VPN login attempts: 1 attempts were recorded from 209.50.187.55
2026-09-21T18:01:11+02: ...
show moreUnauthorized VPN login attempts: 1 attempts were recorded from 209.50.187.55
2026-09-21T18:01:11+02:00 vpn Access-Reject 'despachos' station: 209.50.187.55 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Honeypot detection: Cisco ASA exploit attempt. 2 events observed. Reported automatically from a hone ...
show moreHoneypot detection: Cisco ASA exploit attempt. 2 events observed. Reported automatically from a honeypot sensor.
show less
[04:26] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gatew ...
show more[04:26] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gateway fingerprinting/recon)
show less
DDoS Attack
FTP Brute-Force
Ping of Death
Port Scan
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
IoT Targeted
Automated report: This IP address has been identified as an active public open proxy.
Classification ...
show moreAutomated report: This IP address has been identified as an active public open proxy.
Classification: Open Proxy | Spoofing | VPN/Anonymizer | Bad Web Bot.
Country: Canada
Threat level: High. This host is listed across multiple public proxy databases and poses a risk of abuse, credential stuffing, scraping, and spoofed traffic.
Reported by automated threat intelligence pipeline. Do not whitelist without manual verification.
show less