This IP address has been reported a total of
562
times from
443 distinct
sources.
20.114.175.89 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Connection to port 3000 with data transfer.
Data preview: HEAD / HTTP/1.1
Host: 87.229.95.155:3000
...
show moreConnection to port 3000 with data transfer.
Data preview: HEAD / HTTP/1.1
Host: 87.229.95.155:3000
Connection: close
User-Agent: Mozilla/5.0 (Windows NT 10
show less
20.114.175.89 - - [21/Aug/2026:17:15:00 +0300] "GET /.env.bak HTTP/1.1" 403 239 "-" "Mozilla/5.0 (iP ...
show more20.114.175.89 - - [21/Aug/2026:17:15:00 +0300] "GET /.env.bak HTTP/1.1" 403 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_7 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.7 Mobile/15E148 Safari/604.1"
20.114.175.89 - - [21/Aug/2026:17:15:00 +0300] "GET /.env.production HTTP/1.1" 403 239 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_7 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.7 Mobile/15E148 Safari/604.1"
...
show less
Automated web application probing detected against a public web server.
14 suspicious requests
9 cr ...
show moreAutomated web application probing detected against a public web server.
14 suspicious requests
9 critical requests
Observed requests:
GET /v1/models
GET /terraform.tfstate
GET /serviceAccountKey.json
Risk level: CRITICAL
Reference: STI-20260822-100221-20-114-175-89
show less
Level: (LOW): Known Attacker via CitrixHoneypot IOC Country: United States 19x -> Target Country: As ...
show moreLevel: (LOW): Known Attacker via CitrixHoneypot IOC Country: United States 19x -> Target Country: Ashburn, USA HTTPS
show less
[2026-08-22 10:46:48] Probing for dotfiles
"GET /.config/gcloud/application_default_credentials.jso ...
show more[2026-08-22 10:46:48] Probing for dotfiles
"GET /.config/gcloud/application_default_credentials.json HTTP/1.1" 403
show less