AbuseIPDB » 13.208.151.36
13.208.151.36 was found in our database!
This IP was reported 5 times. Confidence of
Abuse
is 14% : ?
ISP
Amazon Data Services Osaka
Usage Type
Data Center/Web Hosting/Transit
ASN
AS16509
Hostname(s)
ec2-13-208-151-36.ap-northeast-3.compute.amazonaws.com
Domain Name
amazon.com
Country
π―π΅
Japan
City
Osaka, Osaka
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 13.208.151.36 :
This IP address has been reported a total of
5
times from
4 distinct
sources.
13.208.151.36 was first reported on
July 27th 2026 , and the most recent report was
1 month ago .
Old Reports:
The most recent abuse report for this IP address is from
1 month ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
2026-07-29 07:00:00
(1 month ago)
Apache probe; attempts=194; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.en ...
show more
Apache probe; attempts=194; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.json | /.env.live | /.env.local | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.remote | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.swp | /.env.test | /.env.txt | /.env.uat | /.env.yaml | /.env.yml | /.env~ | /.git/.env | /.git/config | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/.env | /api/dev/.env | /api/staging/.env | /api/v1/.env | /api/v2/.env | /api/v3/.env | /app/.env | /application/.env | /apps/.env | /assets/.env | /aws/.env | /azure/.env | /backend/.env | /backup/.env | /backups/.env | /bin/.env | /bootstrap/.env | /brevo/.env | /build/.env | /buildkite/.env | /bulk/.env | /cache/.env | /cakephp/ | ... [194 exact paths total]
show less
Web App Attack
π³π±
homeshowdomain.nl
2026-07-28 22:01:53
(1 month ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-27.
show less
Web App Attack
SSH
Hacking
ππΊ
wickedip
2026-07-27 06:31:00
(1 month ago)
Multiple WAF violations. (Scanning for credential files, nonexistent PHP files, other hacker files, ...
show more
Multiple WAF violations. (Scanning for credential files, nonexistent PHP files, other hacker files, using fake and/or empty UserAgent values.)
show less
Brute-Force
Exploited Host
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-07-27 05:08:26
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 13.208.151.36 (ec2-13-208-151-36.ap-northeast-3 ...
show more
(mod_security) mod_security (id:210492) triggered by 13.208.151.36 (ec2-13-208-151-36.ap-northeast-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 01:08:19.294645 2026] [security2:error] [pid 8581:tid 8581] [client 13.208.151.36:48122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.emilycolvin.michaelward.com"] [uri "/.git/config"] [unique_id "ambnw7CNPHbuNAzZupUBUwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 01:35:45
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 13.208.151.36 (ec2-13-208-151-36.ap-northeast-3 ...
show more
(mod_security) mod_security (id:210492) triggered by 13.208.151.36 (ec2-13-208-151-36.ap-northeast-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 21:35:40.157163 2026] [security2:error] [pid 2975273:tid 2975273] [client 13.208.151.36:41772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.emails.pawzy.app"] [uri "/.git/config"] [unique_id "ama17C6F8nBUwP0DOGl8MwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Showing 1 to
5
of 5 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown π©
Recently Reported IPs: