66.132.172.99

Classification: Whitelisted

66.132.172.99 is a whitelisted (trusted) IP address. Reported by 6 threat sources, last seen 2026-09-13. Network: AS398324 Censys, Inc..

Current activity

  • Known attacker — Seen launching attacks over the Internet.
  • Known scanner — Seen scanning hosts over the Internet.
  • IoT threat — Seen attacking IoT devices.
  • Open proxy — Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Unauthorized scanning of hosts Blocklist.net.ua 2026-09-10 16:07:40 2026-09-13 16:22:57 attacker malicious-activity
Empty reason Blocklist.net.ua 2026-09-11 16:25:36 2026-09-11 16:25:36 attacker malicious-activity
Mail Spammer Blocklist.de 2026-04-30 08:04:08 2026-09-11 12:01:50 attacker malicious-activity
IMAP Attacker Blocklist.de 2026-04-30 07:02:58 2026-09-11 11:01:38 attacker malicious-activity
SSH Attacker Blocklist.de 2026-03-28 10:03:41 2026-09-09 14:00:50 attacker malicious-activity
Unknown malware ThreatFox Abuse.ch 2026-09-04 23:12:01 2026-09-05 00:25:08 malicious-activity
HTTP bot Blocklist.de 2026-08-20 08:01:26 2026-08-20 08:01:26 attacker malicious-activity
Matched whitelist source: Censys_registrant Maltiverse 2026-06-15 14:03:52 2026-08-19 20:04:50 benign
Hacking AbuseIPDB 2026-03-20 01:25:53 2026-06-15 13:05:21 malicious-activity
Port Scanner AbuseIPDB 2026-03-19 20:27:06 2026-06-15 12:44:28 anomalous-activity
Bruteforce AbuseIPDB 2026-03-19 22:28:56 2026-06-15 09:31:58 malicious-activity
SSH Attacker AbuseIPDB 2026-03-19 22:28:56 2026-06-15 09:31:58 malicious-activity
HTTP Scrapper AbuseIPDB 2026-03-21 18:26:36 2026-06-15 09:31:43 anomalous-activity
HTTP Attacker AbuseIPDB 2026-03-19 20:46:15 2026-06-15 09:31:43 malicious-activity
DDoS Attacker AbuseIPDB 2026-03-21 08:20:09 2026-06-14 16:44:18 malicious-activity
Malicious Host AbuseIPDB 2026-03-20 17:13:49 2026-06-14 16:44:18 compromised malicious-activity
SQL Injection AbuseIPDB 2026-03-24 10:52:18 2026-06-12 15:05:34 malicious-activity
Mail Spammer AbuseIPDB 2026-03-25 05:16:44 2026-06-11 07:29:27 malicious-activity
IMAP Attacker AbuseIPDB 2026-04-01 15:40:41 2026-06-10 23:05:19 malicious-activity
IoT Attacker AbuseIPDB 2026-03-26 22:28:14 2026-06-09 13:06:10 malicious-activity
DNS Compromise AbuseIPDB 2026-04-11 06:47:03 2026-06-05 21:24:09 compromised
FTP Attacker AbuseIPDB 2026-05-06 16:19:45 2026-06-03 01:36:19 malicious-activity
Matched whitelist entry Maltiverse 2026-05-31 14:06:13 2026-05-31 14:06:13 benign
Known Attacker AbuseIPDB 2026-05-26 00:11:01 2026-05-26 00:11:01 malicious-activity
Phishing AbuseIPDB 2026-03-20 01:25:53 2026-05-18 03:51:27 malicious-activity
SIP Attacker AbuseIPDB 2026-03-26 13:18:50 2026-05-14 04:38:43 malicious-activity
Proxy AbuseIPDB 2026-04-03 09:54:43 2026-04-29 20:08:14 anonymization
DNS Poisoning AbuseIPDB 2026-03-27 07:20:02 2026-04-14 01:36:03 compromised
Bruteforce login attacker Blocklist.de 2026-03-29 05:01:30 2026-03-30 05:01:18 malicious-activity
HTTP Attacker Blocklist.de 2026-03-29 03:01:42 2026-03-30 03:01:18 malicious-activity
Malicious Host CIArmy 2026-03-21 15:04:47 2026-03-23 15:04:43 malicious-activity
Suspicious Host AbuseIPDB 2026-03-20 00:14:42 2026-03-20 00:14:42 anomalous-activity

Tags

ssh bruteforce bot apache ddos rfi attacker login joomla wordpress imap pop3 sasl mail spam port:26936 suricata t-pot port:11262 abuse

Whois information

AS name
AS398324 Censys, Inc.
Registrant
Censys, Inc.
City
Ann Arbor
State
MI
Postal code
48109
Country
US — United States 🇺🇸
First indexed
2026-03-20 01:18:10
Last updated
2026-09-13 16:22:57