This IP address has been reported a total of
61
times from
54 distinct
sources.
100.52.180.20 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10 ...
show more[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10m window.
Origin: US / AS14618 Amazon.com, Inc.
Active: 14:16:51 UTC
Volume: 1 HTTP req
Probed: /
Status mix: 444ร1
Vhost fishing: secondopinion.ztx-lab.com
UA: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Detected by Cloudflare Security Events via WordPress automation. Detection: bad_bot_scanner (Bad bot ...
show moreDetected by Cloudflare Security Events via WordPress automation. Detection: bad_bot_scanner (Bad bot / scanner behavior). Hits from same IP in last 60 minutes: 1. Unique request paths counted internally: 1. Cloudflare action: managed_challenge. Cloudflare source: botFight.
show less
GENERAL: parametres: [url:uploadCustomIcon=] UA:Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) Appl ...
show moreGENERAL: parametres: [url:uploadCustomIcon=] UA:Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 URL:/index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon
show less
Triggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GE ...
show moreTriggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Detected via HAProxyScanner at 2026-09-02 12:36:02 UTC on destination port WEB (80/443). Repeated sc ...
show moreDetected via HAProxyScanner at 2026-09-02 12:36:02 UTC on destination port WEB (80/443). Repeated scan / connection.
show less
IP address 100.52.180.20 was observed conducting automated reconnaissance and exploitation activity ...
show moreIP address 100.52.180.20 was observed conducting automated reconnaissance and exploitation activity against a public-facing web application. The source generated multiple Web Application Firewall (WAF) detections consistent with malicious probing and attack attempts.
Observed attack patterns include:
Multiple SQL Injection (SQLi) attempts, including:
Basic authentication bypass attempts
Common SQL injection testing payloads
MySQL comment and space-obfuscated SQL injection techniques
Character and comment-based injection payloads
Excessive use of special characters designed to bypass input validation controls
Cross-Site Scripting (XSS) probing activity
Attempted exploitation of React2Shell Remote Code Execution (CVE-2025-55182)
PHP Injection attempts using variable function call techniques
WAF anomaly scoring thresholds exceeded due to the volume and severity of malicious requests
The activity appears to be consistent with an automated vulnerability scanning against web apps.
show less
Web App Attack
Web Spam
SQL Injection
Anonymous
Reported from Nginx log analysis 16. Log: 100.52.180.20 - - [02/Sep/2026:xx:xx:xx 0200] "POST / HTT ...
show moreReported from Nginx log analysis 16. Log: 100.52.180.20 - - [02/Sep/2026:xx:xx:xx 0200] "POST / HTTP/1.1" xxx xxx "https://csgameserver16.ooguy.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 newsai/1.0 Safari/537.36" "-" "US United States Ashburn" "AS14618" "Amazon.com, Inc."
show less
Port Scan
Brute-Force
SSH
Showing 1 to
15
of 61 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ