This IP address has been reported a total of
25
times from
23 distinct
sources.
90.66.30.137 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 5
reports;
Hong Kong
with 4
reports;
United States of America
with 3
reports.
The most common categories in these recent reports were:
Brute-Force
19
times;
SSH
12
times;
Web App Attack
6
times;
Hacking
5
times;
Bad Web Bot
1
time;
Other
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Synology DSM web login brute-force: 9 failed sign-in attempt(s) between 09:48:49 and 18:41:57 CEST o ...
show moreSynology DSM web login brute-force: 9 failed sign-in attempt(s) between 09:48:49 and 18:41:57 CEST on 2026-10-06; part of distributed low-and-slow campaign (1000+ IPs).
show less
Brute-force login attempts, auto-blocked by Synology DSM
Brute-Force
Anonymous
Web directory scan: 10 requests in 9h 40m (Last path: '/webapi/auth.cgi?account=administrator&api=SY ...
show moreWeb directory scan: 10 requests in 9h 40m (Last path: '/webapi/auth.cgi?account=administrator&api=SYNO.API.Auth&format=sid&method=login&passwd=Pass123word&session=FileStation&version=6').
show less
SSH Brute force: 6 attempts were recorded from 90.66.30.137
2026-10-04T23:55:21+02:00 Connection clo ...
show moreSSH Brute force: 6 attempts were recorded from 90.66.30.137
2026-10-04T23:55:21+02:00 Connection closed by authenticating user root 90.66.30.137 port 53090 [preauth]
2026-10-04T23:50:39+02:00 Connection closed by authenticating user root 90.66.30.137 port 37684 [preauth]
2026-10-04T23:53:07+02:00 Connection closed by authenticating user root 90.66.30.137 port 56096 [preauth]
2026-10-04T23:54:06+02:00 Connection closed by authenticating user root 90.66.30.137 port 35620 [preauth]
2026-10-04T23:47:09+02:00 Connection closed by authenticating user root 90.66.30.137 port 44586 [preauth]
2026-10-04T23:55:10+02:00 Connection closed by authenticating user root 90.66.30.137 port 40398 [preauth]
show less
Brute-Force
SSH
Anonymous
2026-10-04T21:57:50.676948+00:00 xmr sshd[2808]: pam_unix(sshd:auth): authentication failure; lognam ...
show more2026-10-04T21:57:50.676948+00:00 xmr sshd[2808]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=90.66.30.137 user=root
2026-10-04T21:57:52.365219+00:00 xmr sshd[2808]: Failed password for root from 90.66.30.137 port 59854 ssh2
...
show less
SSH brute-force: 3 failed login attempts in 42s (last 2026-10-04T21:40:52+00:00); usernames tried: r ...
show moreSSH brute-force: 3 failed login attempts in 42s (last 2026-10-04T21:40:52+00:00); usernames tried: root
show less
Cowrie Honeypot: 2 unauthorised SSH/Telnet login attempts between 2026-10-04T21:39:51Z and 2026-10-0 ...
show moreCowrie Honeypot: 2 unauthorised SSH/Telnet login attempts between 2026-10-04T21:39:51Z and 2026-10-04T21:39:53Z
show less
Oct 4 23:08:17 h3buntu sshd[4125614]: Failed password for root from 90.66.30.137 port 43142 ssh2
Oc ...
show moreOct 4 23:08:17 h3buntu sshd[4125614]: Failed password for root from 90.66.30.137 port 43142 ssh2
Oct 4 23:26:59 h3buntu sshd[4133482]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=90.66.30.137 user=root
Oct 4 23:27:01 h3buntu sshd[4133482]: Failed password for root from 90.66.30.137 port 39166 ssh2
...
show less
SFTP Brute-Force login attempts or hacking probe detected against Pelican control panel. Evidence: 2 ...
show moreSFTP Brute-Force login attempts or hacking probe detected against Pelican control panel. Evidence: 2026-10-04T21:07:06.675226+00:00 pl-waw-01 wings[761033]: ERROR: [Oct 4 21:07:06.675] sftp: failed to accept inbound connection error=[ssh: no auth passed yet, the credentials provided were invalid] ip=90.66.30.137:51660 2026-10-04T21:07:07.535052+00:00 pl-waw-01 wings[761033]: ERROR: [Oct 4 21:07:07.534] sftp: failed to accept inbound connection error=[ssh: no auth passed yet, the credentials provided were invalid] ip=90.66.30.137:52930 2026-10-04T21:07:07.557656+00:00 pl-waw-01 wings[761033]: ERROR: [Oct 4 21:07:07.557] sftp: failed to accept inbound connection error=[ssh: no auth passed yet, the credentials provided were invalid] ip=90.66.30.137:52940 ...
show less
Hacking
Brute-Force
SSH
Anonymous
Suspicious brute-force activity was detected by MikroTik and the source IP was observed in the Brut_ ...
show moreSuspicious brute-force activity was detected by MikroTik and the source IP was observed in the Brut_knock stage tracking list.
show less