This IP address has been reported a total of
34
times from
26 distinct
sources.
66.245.220.118 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: JP, Attack patterns: Word ...
show moreBlocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: JP, Attack patterns: WordPress scanning, Webshell probing
show less
(aggressive_scanner) REGOLA 9 - Aggressive Web Scanner 66.245.220.118 (JP/Japan/-): 1 in the last 36 ...
show more(aggressive_scanner) REGOLA 9 - Aggressive Web Scanner 66.245.220.118 (JP/Japan/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 66.245.220.118 - - [21/Jun/2026:03:33:12 +0200] "GET /breads1.php HTTP/1.1" 404 4758 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" "-" host=lucadipa.com
show less
Attempted access to sensitive endpoint (/wp-content/155.php) detected. Automated scan or unauthorize ...
show moreAttempted access to sensitive endpoint (/wp-content/155.php) detected. Automated scan or unauthorized probing.
show less
Web App Attack
Anonymous
(PERMBLOCK) 66.245.220.118 (JP/Japan/-) has had more than 4 temp blocks in the last 86400 secs; Port ...
show more(PERMBLOCK) 66.245.220.118 (JP/Japan/-) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
(aggressive_scanner) REGOLA 9 - Aggressive Web Scanner 66.245.220.118 (JP/Japan/-): 1 in the last 36 ...
show more(aggressive_scanner) REGOLA 9 - Aggressive Web Scanner 66.245.220.118 (JP/Japan/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 66.245.220.118 - - [20/Jun/2026:23:58:36 +0200] "GET /test1.php HTTP/1.1" 404 4758 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" "-" host=lucadipa.com
show less
Attempted access to sensitive endpoint (/wp-admin/maint/index.php) detected. Automated scan or unaut ...
show moreAttempted access to sensitive endpoint (/wp-admin/maint/index.php) detected. Automated scan or unauthorized probing.
show less
[SatJun2022:58:59.9782372026][security2:error][pid3870580:tid3870606][client66.245.220.118:0]ModSecu ...
show more[SatJun2022:58:59.9782372026][security2:error][pid3870580:tid3870606][client66.245.220.118:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"safeoncloud.ch\"][uri\"/xmlrpc.php\"][unique_id\"ajb_E-otac1IFpUeNNtccwAAABc\"]
show less
[SatJun2021:38:34.4737222026][security2:error][pid1413620:tid1413738][client66.245.220.118:0]ModSecu ...
show more[SatJun2021:38:34.4737222026][security2:error][pid1413620:tid1413738][client66.245.220.118:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"wp-content/uploads/.\*\\\\\\\\.ph\(\?:p\|tml\|t\)\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/99_asl_jitp.conf\"][line\"5100\"][id\"382238\"][rev\"2\"][msg\"Atomicorp.comWAFRules-VirtualJustInTimePatch:PHPfileexecutioninuploadsdirectorydenied\"][data\"wp-content/uploads/index.php\"][severity\"CRITICAL\"][hostname\"hosting-dominio.com\"][uri\"/wp-content/uploads/index.php\"][unique_id\"ajbsOnJEs5erXVLP9IGPDAAAARI\"]
show less
Blocked by CrowdSec - crowdsecurity/http-probing (US)
Port Scan
Brute-Force
Web App Attack
SSH
Anonymous
Aggressive Robot or Attack DDOS
DDoS Attack
Anonymous
Bot / scanning and/or hacking attempts: GET /goods.php HTTP/1.1, GET /inputs.php HTTP/1.1, GET /file ...
show moreBot / scanning and/or hacking attempts: GET /goods.php HTTP/1.1, GET /inputs.php HTTP/1.1, GET /file.php HTTP/1.1, GET /admin.php HTTP/1.1, GET /adminfuns.php HTTP/1.1, GET /404.php HTTP/1.1
show less
Hacking
Web App Attack
Showing 1 to
15
of 34 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ