AbuseIPDB » 13.50.225.28
13.50.225.28 was found in our database!
This IP was reported 12 times. Confidence of
Abuse
is 0% : ?
ISP
Amazon Data Services Sweden
Usage Type
Data Center/Web Hosting/Transit
ASN
AS16509
Hostname(s)
ec2-13-50-225-28.eu-north-1.compute.amazonaws.com
Domain Name
amazon.com
Country
πΈπͺ
Sweden
City
Stockholm, Stockholm
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 13.50.225.28 :
This IP address has been reported a total of
12
times from
10 distinct
sources.
13.50.225.28 was first reported on
February 19th 2025 , and the most recent report was
1 year ago .
Old Reports:
The most recent abuse report for this IP address is from
1 year ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
π§πͺ
cmbplf
2025-03-10 06:20:12
(1 year ago)
3.011 POST requests to */wp-login.php
Brute-Force
Bad Web Bot
πΊπΈ
Duologic
2025-03-06 20:25:02
(1 year ago)
THREAT vulnerability phpunit Remote Code Execution Vulnerability(55852)
Hacking
Web App Attack
π©πͺ
Ba-Yu
2025-03-06 15:43:25
(1 year ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
π¬π§
wojtek
2025-03-05 20:56:28
(1 year ago)
Mar 5 20:56:02 bee postfix/smtpd[137000]: warning: ec2-13-50-225-28.eu-north-1.compute.amazonaws.co ...
show more
Mar 5 20:56:02 bee postfix/smtpd[137000]: warning: ec2-13-50-225-28.eu-north-1.compute.amazonaws.com[13.50.225.28]: SASL PLAIN authentication failed: authentication failure
Mar 5 20:56:04 bee postfix/smtpd[137000]: warning: ec2-13-50-225-28.eu-north-1.compute.amazonaws.com[13.50.225.28]: SASL LOGIN authentication failed: authentication failure
Mar 5 20:56:17 bee postfix/smtpd[137000]: warning: ec2-13-50-225-28.eu-north-1.compute.amazonaws.com[13.50.225.28]: SASL PLAIN authentication failed: authentication failure
Mar 5 20:56:19 bee postfix/smtpd[137000]: warning: ec2-13-50-225-28.eu-north-1.compute.amazonaws.com[13.50.225.28]: SASL LOGIN authentication failed: authentication failure
Mar 5 20:56:27 bee postfix/smtpd[137000]: warning: ec2-13-50-225-28.eu-north-1.compute.amazonaws.com[13.50.225.28]: SASL PLAIN authentication failed: authentication failure
...
show less
Brute-Force
πΊπΈ
snappic
2025-03-05 17:10:05
(1 year ago)
Malicious URI path & Amazon AWS User Agent Spoofing [GET /.env] [Mozilla/5.0 (X11; Linux x86_64) App ...
show more
Malicious URI path & Amazon AWS User Agent Spoofing [GET /.env] [Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36]
show less
Bad Web Bot
Web App Attack
π¨π
teamsecure
2025-03-05 06:42:15
(1 year ago)
Banned for trying to access env
Web App Attack
πΊπΈ
Major Hostility
2025-03-05 01:57:14
(1 year ago)
"GET /.env HTTP/1.1" 404
"GET /.env HTTP/1.1" 404
Web App Attack
πΊπΈ
MogBox
2025-03-04 17:45:28
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 13.50.225.28 (SE/Sweden/ec2-13-50-225-28.eu-nor ...
show more
(mod_security) mod_security (id:210492) triggered by 13.50.225.28 (SE/Sweden/ec2-13-50-225-28.eu-north-1.compute.amazonaws.com): 1 in the last 3600 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Tue Mar 04 12:45:26.490798 2025] [security2:error] [pid 2034830:tid 2034877] [client 13.50.225.28:0] [client 13.50.225.28] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mogbox.net"] [uri "/.env"] [unique_id "Z8c8Ngt2GH07byHKxvf8kQAAABA"]
show less
Hacking
π«π·
dynamix
2025-03-04 10:35:20
(1 year ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
MPL
2025-02-25 16:07:57
(1 year ago)
tcp/443 (3 or more attempts)
Port Scan
πΊπΈ
MPL
2025-02-19 21:47:41
(1 year ago)
tcp/80
Port Scan
πΊπΈ
MPL
2025-02-19 21:29:15
(1 year ago)
tcp/80 (5 or more attempts)
Port Scan
Showing 1 to
12
of 12 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown π©
Recently Reported IPs: