← Back to observed IPs
EudorIA Threat Observatory

139.99.209.90

Technical source observed on EudorIA perimeter controls. All the events listed were blocked, contained or detected by the defensive systems.

Confidencehigh4 catalogued events
First observation04/09/2026 19:16
Last observation04/09/2026 19:16
Controls areaIPS
Maximum rule level12/20
Network context

Estimated origin

Country
Australia (AU)
City
Sydney
ASN
AS16276
ASN operator / holder
OVH - OVH SAS, FR
Announced prefix
139.99.128.0/17
Reverse DNS
ns564377.ip-139-99-209.net
Last activity

IPS detection

Public destination
eudoria.it
Service
HTTPS
Rule
100902
Technical reason
ET EXPLOIT D-Link Devices Home Network Administration Protocol Command Execution
Outcome
Blocked / detected
Minimised history

Observed evidence

Last 4 publishable events
04/09/2026 19:16
IPS

IPS detection

high

ET WEB_SERVER WGET Command Specifying Output in HTTP Headers

Destination
eudoria.it
Service
HTTPS
Outcome
Detected
04/09/2026 19:16
IPS

IPS detection

high

ET EXPLOIT D-Link HNAP SOAPAction Command Injection (CVE-2015-2051, CVE-2019-10891, CVE-2022,37056, CVE-2024-33112, CVE-2025-11488, CVE-2025-63932)

Destination
eudoria.it
Service
HTTPS
Outcome
Detected
04/09/2026 19:16
IPS

IPS detection

high

ET EXPLOIT D-Link Devices Home Network Administration Protocol Command Execution

Destination
eudoria.it
Service
HTTPS
Outcome
Detected
04/09/2026 19:16
IPS

IPS detection

high

ET WEB_SERVER Possible D-Link Router HNAP Protocol Security Bypass Attempt

Destination
eudoria.it
Service
HTTPS
Outcome
Detected