This IP address has been reported a total of
36
times from
27 distinct
sources.
20.55.214.69 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
(mod_security) mod_security (id:210492) triggered by 20.55.214.69 (-): 1 in the last 300 secs; Ports ...
show more(mod_security) mod_security (id:210492) triggered by 20.55.214.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 14:02:17.147852 2026] [security2:error] [pid 327946:tid 327946] [client 20.55.214.69:43935] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.177"] [uri "/.git/HEAD"] [unique_id "amT6KSl9Fyd7k7X0WfrB0gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-25 13:16:12 20.55.214.69:42885 WARNING: Bad encapsulated packet length from peer (5635), whi ...
show more2026-07-25 13:16:12 20.55.214.69:42885 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1768 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]
2026-07-25 13:16:17 20.55.214.69:42911 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1768 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]
2026-07-25 13:16:18 20.55.214.69:43080 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1768 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]
...
show less
Port Scan
Hacking
Anonymous
20.55.214.69 - - [25/Jul/2026:16:39:38 +0000] "GET /.git/HEAD HTTP/1.1" 404 134 "-" "Mozilla/5.0 (Ma ...
show more20.55.214.69 - - [25/Jul/2026:16:39:38 +0000] "GET /.git/HEAD HTTP/1.1" 404 134 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.4; rv:125.0) Gecko/20100101 Firefox/125.0"
20.55.214.69 - - [25/Jul/2026:16:39:39 +0000] "GET /.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
Anonymous
[web.zebs.ch] httpd-config-scan: sites=www.example.com; logs=/var/log/httpd/access_log; samples=/.gi ...
show more[web.zebs.ch] httpd-config-scan: sites=www.example.com; logs=/var/log/httpd/access_log; samples=/.git/HEAD | /.git/config | /.git/logs/HEAD
show less
Hacking
Web App Attack
Anonymous
denied traffic to a honeypot network. destination port 2096.
20.55.214.69 (US/United States/-), 5 distributed cpanel attacks on account [root] in the last 900 se ...
show more20.55.214.69 (US/United States/-), 5 distributed cpanel attacks on account [root] in the last 900 secs
show less
CrowdSec: Symphony auto-ban: /___proxy_subdomain_whm/login/?login_only=1 (100.0% confidence) (720h b ...
show moreCrowdSec: Symphony auto-ban: /___proxy_subdomain_whm/login/?login_only=1 (100.0% confidence) (720h ban)
show less