This IP address has been reported a total of
62
times from
53 distinct
sources.
66.132.159.27 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 16
reports;
France
with 12
reports;
United States of America
with 9
reports.
The most common categories in these recent reports were:
Port Scan
42
times;
Hacking
11
times;
Brute-Force
10
times;
Web App Attack
8
times;
Bad Web Bot
5
times;
Other
8
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[SatOct1018:03:13.5633762026][security2:error][pid1260149:tid1260160][client66.132.159.27:0]ModSecur ...
show more[SatOct1018:03:13.5633762026][security2:error][pid1260149:tid1260160][client66.132.159.27:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"www.monteco-suisse.ch\"][uri\"/\"][unique_id\"asphwa9CmStOe12gGvgV_AAAAAA\"]
show less
Blocked by UFW (TCP on port 8443).
Source port: 58004
TTL: 52
Packet length: 60
TOS: 0x00
This repo ...
show moreBlocked by UFW (TCP on port 8443).
Source port: 58004
TTL: 52
Packet length: 60
TOS: 0x00
This report (for 66.132.159.27) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Oct 10 17:02:57 isp postfix/smtps/smtpd[2360146]: lost connection after CONNECT from 27.159.132.66.c ...
show moreOct 10 17:02:57 isp postfix/smtps/smtpd[2360146]: lost connection after CONNECT from 27.159.132.66.censys-scanner.com[66.132.159.27]
Oct 10 17:02:58 isp postfix/smtps/smtpd[2360146]: lost connection after CONNECT from 27.159.132.66.censys-scanner.com[66.132.159.27]
Oct 10 17:02:59 isp postfix/smtps/smtpd[2360146]: lost connection after CONNECT from 27.159.132.66.censys-scanner.com[66.132.159.27]
...
show less
[SatOct1016:20:22.8885482026][security2:error][pid4172836:tid4172958][client66.132.159.27:0]ModSecur ...
show more[SatOct1016:20:22.8885482026][security2:error][pid4172836:tid4172958][client66.132.159.27:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"mail.hostingedominio.ch\"][uri\"/\"][unique_id\"aspJpi3dR9nv8-DcHGsMlgAAAQk\"]
show less
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly as ...
show moreUFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly associated with port scanning, service discovery, or automated internet probing. Technical: source_ip=66.132.159.27; proto=TCP; source_port=51000; target_port=32361
show less