This IP address has been reported a total of
12
times from
11 distinct
sources.
66.234.150.9 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show moreAutomated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cache.teddypot.space | URI: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36 OPR/117.0.0. | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
Anonymous
[server.tmg.gr] httpd-config-scan: sites=www.exarjournal.com; logs=/var/log/httpd/domains/exarjourna ...
show more[server.tmg.gr] httpd-config-scan: sites=www.exarjournal.com; logs=/var/log/httpd/domains/exarjournal.com.log; samples=/.env.example | /.env
show less
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensiti ...
show moreDetected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensitive files, source control, config, and backups). Hits from same IP in last 60 minutes: 6. Unique request paths counted internally: 2. Cloudflare action: block. Cloudflare source: firewallCustom.
show less
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 66.234.150.9 - - [30/Sep/2026:00:52:07 +0200] "GET /.env.example HTTP/2.0" 403 69 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36 Trailer/93.3.8652.5"
...
show less
Bad Web Bot
Web App Attack
Anonymous
66.234.150.9 - - [30/Sep/2026:06:48:26 +0800] "GET /.env.example HTTP/1.1" 301 - "-" "Mozilla/5.0 (i ...
show more66.234.150.9 - - [30/Sep/2026:06:48:26 +0800] "GET /.env.example HTTP/1.1" 301 - "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 10_3 like Mac OS X) AppleWebKit/602.1.50 (KHTML, like Gecko) CriOS/56.0.2924.75 Mobile/14E5239e YisouSpider/5.0 Safari/602."
...
show less
[28/Sep/2026:17:36:07 +0300] -- 66.234.150.9 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-lo ...
show more[28/Sep/2026:17:36:07 +0300] -- 66.234.150.9 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-login.php HTTP/1.1
show less
Blocked by UFW (TCP on 51413)
Source port: 14141
TTL: 110
Packet length: 52
TOS: 0x00
This report ( ...
show moreBlocked by UFW (TCP on 51413)
Source port: 14141
TTL: 110
Packet length: 52
TOS: 0x00
This report (for 66.234.150.9) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Blocked by UFW (TCP on 27278)
Source port: 54369
TTL: 44
Packet length: 60
TOS: 0x08
This report (f ...
show moreBlocked by UFW (TCP on 27278)
Source port: 54369
TTL: 44
Packet length: 60
TOS: 0x08
This report (for 66.234.150.9) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Showing 1 to
12
of 12 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ