Log in to view charts and search reports for this IP.
Log In
No reports in the last 60 days
20.205.10.3 has been reported 409
times. The most recent report is from
.
The full history is preserved below and remains searchable. A
0% score reflects the absence of recent activity, but
this is not a guarantee that earlier reports were invalid. Abuse confidence score decays,
naturally, over time, when the abusive activity stops.
IP Abuse Reports for 20.205.10.3:
This IP address has been reported a total of
409
times from
287 distinct
sources.
20.205.10.3 was first reported on
, and the most recent report was
.
GET /.well-known/ HTTP/1.1
GET /.well-known/classwithtostring.php HTTP/1.1
GET /.well-known/gecko-li ...
show moreGET /.well-known/ HTTP/1.1
GET /.well-known/classwithtostring.php HTTP/1.1
GET /.well-known/gecko-litespeed.php HTTP/1.1
show less
4542 attacks on PHP URLs, ACME URLs:
GET /wp-includes/sitemaps/autoload_classmap.php HTTP/1.1
GET /. ...
show more4542 attacks on PHP URLs, ACME URLs:
GET /wp-includes/sitemaps/autoload_classmap.php HTTP/1.1
GET /.well-known/acme-challenge/index.php HTTP/1.1
show less
This IP was observed 136 times via a honeypot and also performed automated reconnaissance and vulner ...
show moreThis IP was observed 136 times via a honeypot and also performed automated reconnaissance and vulnerability scanning against my server between 2026-01-23T09:16:46Z and 2026-01-23T09:17:17Z UTC.
The honeypot folders included examples such as: /private/, /wp-admin/images/, /wp-content/plugins/WordPressCore/ and others.
The honeypot files included examples such as: /about.php, /api.php, /classwithtostring.php and others.
It issued 183 HTTP requests targeting 47 distinct suspicious paths within about 31 seconds.
The targeted paths included examples such as: /2.php, /ALFA_DATA/alfacgiapi/, /a.php and others.
The scan also attempted to access .well-known paths that are often misused in compromised environments.
Multiple requests used filenames that resemble PHP web shells or exploitation payloads.
This behavior is characteristic of an extensive, fully automated web application attack or exploit framework, not legitimate traffic.
show less