AbuseIPDB » 20.127.247.146
20.127.247.146 was found in our database!
This IP was reported 8 times. Confidence of
Abuse
is 48% : ?
ISP
Microsoft Corporation
Usage Type
Data Center/Web Hosting/Transit
ASN
AS8075
Domain Name
microsoft.com
Country
๐บ๐ธ
United States of America
City
Dulles Town Center, Virginia
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 20.127.247.146 :
This IP address has been reported a total of
8
times from
8 distinct
sources.
20.127.247.146 was first reported on
August 22nd 2026 , and the most recent report was
3 days ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ฉ๐ช
netclix.gr
2026-08-22 21:08:47
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 20.127.247.146 (US/United States/-): ( ...
show more
(mod_security) mod_security triggered on hostname [redacted] 20.127.247.146 (US/United States/-): (CF_ENABLE)
show less
SQL Injection
๐ณ๐ฑ
globcom
2026-08-22 20:46:50
(3 days ago)
General hacking/exploits/scanning
Web App Attack
Anonymous
2026-08-22 20:40:17
(3 days ago)
Aug 22 16:40:16 localhost kernel: [115776371.398287] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:9 ...
show more
Aug 22 16:40:16 localhost kernel: [115776371.398287] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=20.127.247.146 DST=[mungedIP2] LEN=60 TOS=0x00 PREC=0x40 TTL=42 ID=57059 DF PROTO=TCP SPT=19337 DPT=2078 WINDOW=64240 RES=0x00 SYN URGP=0
Aug 22 16:40:16 localhost kernel: [115776371.398296] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=20.127.247.146 DST=[mungedIP2] LEN=60 TOS=0x00 PREC=0x40 TTL=42 ID=57059 DF PROTO=TCP SPT=19337 DPT=2078 SEQ=1309482949 ACK=0 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405A00402080AFA4D57C0000000000103030A)
Aug 22 16:40:16 localhost kernel: [115776371.709914] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=20.127.247.146 DST=[mungedIP2] LEN=60 TOS=0x00 PREC=0x40 TTL=42 ID=29557 DF PROTO=TCP SPT=18515 DPT=2082 WINDOW=64240 RES=0x00 SYN URGP=0
Aug 22 16:40:16 localhost kernel: [115776371.709928] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f
show less
Port Scan
๐บ๐ธ
Neosmith20
2026-08-22 18:52:22
(3 days ago)
Knock-Knock honeypot brute-force: proto8 (47 total hits)
Brute-Force
๐ฉ๐ช
ut-addicted.com
2026-08-22 18:29:56
(4 days ago)
\[22/Aug/2026:20:29:52 +0200\] aonqoBYibtE68QjHQaMCAwAAAME 20.127.247.146 19141 78.46.187.162 80
\[2 ...
show more
\[22/Aug/2026:20:29:52 +0200\] aonqoBYibtE68QjHQaMCAwAAAME 20.127.247.146 19141 78.46.187.162 80
\[22/Aug/2026:20:29:53 +0200\] aonqoRYibtE68QjHQaMCBAAAANg 20.127.247.146 18332 78.46.187.162 80
\[22/Aug/2026:20:29:54 +0200\] aonqohYibtE68QjHQaMCBQAAANI 20.127.247.146 18339 78.46.187.162 80
show less
Brute-Force
Web App Attack
๐ฌ๐ง
saxicola
2026-08-22 18:29:25
(4 days ago)
20.127.247.146 - - [22/Aug/2026:19:29:23 +0100] "GET /.git/HEAD HTTP/1.1" 403 499 "-" "Mozilla/5.0 ( ...
show more
20.127.247.146 - - [22/Aug/2026:19:29:23 +0100] "GET /.git/HEAD HTTP/1.1" 403 499 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:125.0) Gecko/20100101 Firefox/125.0"
20.127.247.146 - - [22/Aug/2026:19:29:24 +0100] "GET /.git/config HTTP/1.1" 403 499 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.0"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-22 18:02:23
(4 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 17:11:11
(4 days ago)
(mod_security) mod_security (id:949110) triggered by 20.127.247.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 20.127.247.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 13:11:06.569834 2026] [security2:error] [pid 22114:tid 22114] [client 20.127.247.146:17543] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "192.64.150.239"] [uri "/.git/HEAD"] [unique_id "aonYKuo1FAnYN9tRuB970AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Showing 1 to
8
of 8 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: