This IP address has been reported a total of
69
times from
40 distinct
sources.
5.255.120.22 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-21.
show less
1.103 requests with url.path *credentials.json
320 requests with url.path *config.json
133 reques ...
show more1.103 requests with url.path *credentials.json
320 requests with url.path *config.json
133 requests with url.path *secrets.json
show less
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show moreTriggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env.local.save
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bot / scanning and/or hacking attempts: GET /service-account-credentials.json HTTP/1.1, GET /app/cre ...
show moreBot / scanning and/or hacking attempts: GET /service-account-credentials.json HTTP/1.1, GET /app/credentials.json HTTP/1.1, GET /.env.bak HTTP/1.1, GET /service-account-config.json HTTP/1.1, GET /.openclaw/openclaw.json HTTP/1.1, GET /gcp-key.json HTTP/1.1, GET /.cursor/mcp.json HTTP/1.1, GET /public/.env HTTP/1.1, GET /.env.development HTTP/1.1, GET /web/.env HTTP/1.1, GET /.anthropic/config.json HTTP/1.1
show less