AbuseIPDB » 18.205.159.111
18.205.159.111 was found in our database!
This IP was reported 5 times. Confidence of
Abuse
is 24% : ?
ISP
Amazon Technologies Inc.
Usage Type
Data Center/Web Hosting/Transit
ASN
AS14618
Hostname(s)
ec2-18-205-159-111.compute-1.amazonaws.com
Domain Name
amazon.com
Country
πΊπΈ
United States of America
City
Ashburn, Virginia
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 18.205.159.111 :
This IP address has been reported a total of
5
times from
4 distinct
sources.
18.205.159.111 was first reported on
June 6th 2026 , and the most recent report was
1 week ago .
Old Reports:
The most recent abuse report for this IP address is from
1 week ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
π³π±
Savvii
2026-06-06 11:16:54
(1 week ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Octopuce
2026-06-06 11:00:10
(1 week ago)
Aggressive web search of vulnerable pages: /phpinfo.php /info.php /php.php /i.php /pi.php /pinfo.php ...
show more
Aggressive web search of vulnerable pages: /phpinfo.php /info.php /php.php /i.php /pi.php /pinfo.php /test.php /p.php /debug.php /admin/phpinfo ...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-06 10:37:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 18.205.159.111 (ec2-18-205-159-111.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 18.205.159.111 (ec2-18-205-159-111.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 06:37:18.838685 2026] [security2:error] [pid 27141:tid 27141] [client 18.205.159.111:35010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ancientleather.com"] [uri "/.git/config"] [unique_id "aiP4XsDkElM6zIYbOzSHcgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-06 09:32:27
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 18.205.159.111 (ec2-18-205-159-111.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 18.205.159.111 (ec2-18-205-159-111.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 05:32:20.499459 2026] [security2:error] [pid 16930:tid 16930] [client 18.205.159.111:56636] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anchor07.com"] [uri "/.git/config"] [unique_id "aiPpJMRVyeJI2anmRM4o6wAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π±π»
garmtech.com
2026-06-06 09:31:34
(1 week ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack
Showing 1 to
5
of 5 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown π©
Recently Reported IPs: