This IP address has been reported a total of
4
times from
3 distinct
sources.
201.20.124.27 was first reported on
September 12th 2022 , and the most recent report was
12 hours ago .
In the last 60 days, the only reporter location was:
United States of America
with 2
reports.
The most common categories in these recent reports were:
Bad Web Bot
2
times;
Web App Attack
2
times;
Brute-Force
2
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
πΊπΈ
TPI-Abuse
2026-10-03 09:02:25
(12 hours ago)
(mod_security) mod_security (id:210350) triggered by 201.20.124.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 201.20.124.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 05:02:19.837758 2026] [security2:error] [pid 16303:tid 16303] [client 201.20.124.27:24420] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||limeroc.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "limeroc.com"] [uri "/"] [unique_id "asDEm1icdNabOobcqA7UCAAAAAQ"], referer: https://backlinkaudit.store/dir/trusted-domain-backlinks-122371
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 02:47:16
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 201.20.124.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 201.20.124.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 22:47:11.367208 2026] [security2:error] [pid 10225:tid 10237] [client 201.20.124.27:24174] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||windstream-sales.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "windstream-sales.com"] [uri "/"] [unique_id "ar8bL24Cohv5HftXiVOd9AAAAIo"], referer: https://seolinkbuilding.website/dir/organic-visibility-backlinks-232777
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
Global Cyber Police
2025-07-27 17:28:09
(1 year ago)
Malicious bot activity detected: Hitting honeypot page (200 OK with 258/259 bytes sent).
Port Scan
Brute-Force
Web App Attack
Anonymous
2022-09-12 21:19:00
(4 years ago)
Sep 13 03:18:56 ns3104219 postfix/smtpd[21096]: warning: unknown[201.20.124.27]: SASL PLAIN authenti ...
show more
Sep 13 03:18:56 ns3104219 postfix/smtpd[21096]: warning: unknown[201.20.124.27]: SASL PLAIN authentication failed: authentication failure
...
show less
Brute-Force
Web App Attack
Showing 1 to
4
of 4 reports