This IP address has been reported a total of
48
times from
43 distinct
sources.
104.46.220.20 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: JP, Attack patterns: Word ...
show moreBlocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: JP, Attack patterns: WordPress scanning
show less
| [Normal/Japan] Aggressive IP 104.46.220.20 (~350 hits). Type: DoS Defender- Web server 400 error c ...
show more| [Normal/Japan] Aggressive IP 104.46.220.20 (~350 hits). Type: DoS Defender- Web server 400 error code
show less
๐ฅ VERY AGGRESSIVE SCANNER probed over 100 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack
Anonymous
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: JP, Attack patterns: Word ...
show moreBlocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: JP, Attack patterns: WordPress scanning
show less
WebApp brute force attack detected. Multiple file scanning attempts from 104.46.220.20. Detected by ...
show moreWebApp brute force attack detected. Multiple file scanning attempts from 104.46.220.20. Detected by fail2ban.
show less
(aggressive_scanner) REGOLA 8 - Aggressive Web Scanner 104.46.220.20 (JP/Japan/-): 1 in the last 360 ...
show more(aggressive_scanner) REGOLA 8 - Aggressive Web Scanner 104.46.220.20 (JP/Japan/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 104.46.220.20 - - [18/May/2026:14:36:57 +0200] "GET /404.php HTTP/1.1" 200 4741 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" "-" host=www.fondazioneilcireneo.it
show less
(upload_shell) srv201 Shell upload 104.46.220.20 (JP/Japan/-): 1 in the last 3600 secs; Ports: *; Di ...
show more(upload_shell) srv201 Shell upload 104.46.220.20 (JP/Japan/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
[MonMay1814:03:08.1883772026][security2:error][pid4176767:tid4176773][client104.46.220.20:0]ModSecur ...
show more[MonMay1814:03:08.1883772026][security2:error][pid4176767:tid4176773][client104.46.220.20:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"wp-content/uploads/.\*\\\\\\\\.ph\(\?:p\|tml\|t\)\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/99_asl_jitp.conf\"][line\"5100\"][id\"382238\"][rev\"2\"][msg\"Atomicorp.comWAFRules-VirtualJustInTimePatch:PHPfileexecutioninuploadsdirectorydenied\"][data\"wp-content/uploads/index.php\"][severity\"CRITICAL\"][hostname\"behindthemoon.ch\"][uri\"/wp-content/uploads/index.php\"][unique_id\"agr__L2HqGzuahNs18OjlgAAAMQ\"]
show less