AbuseIPDB » 52.154.20.203
52.154.20.203 was found in our database!
This IP was reported 20 times. Confidence of
Abuse
is 70% : ?
ISP
Microsoft Corporation
Usage Type
Data Center/Web Hosting/Transit
ASN
AS8075
Domain Name
microsoft.com
Country
๐บ๐ธ
United States of America
City
Des Moines, Iowa
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 52.154.20.203 :
This IP address has been reported a total of
20
times from
18 distinct
sources.
52.154.20.203 was first reported on
April 7th 2026 , and the most recent report was
15 minutes ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ฌ๐ง
Axel
2026-04-07 17:52:02
(1 month ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.git/config ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.git/config Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
๐ฌ๐ง
pinguin
2026-04-07 17:41:20
(1 month ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (Linux; Android 13; OnePlus 11) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-07 16:54:20
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 52.154.20.203 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 52.154.20.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 12:54:11.986319 2026] [security2:error] [pid 1520942:tid 1520942] [client 52.154.20.203:31694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alosi.us"] [uri "/.git/config"] [unique_id "adU2s82yXb25kbO2xYCeMAAAABo"], referer: https://www.yahoo.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-04-07 16:12:45
(1 month ago)
Multiple WAF Violations
Web App Attack
๐จ๐ฆ
zXero
2026-04-07 14:35:37
(1 month ago)
Fail2Ban automatic report - jail: web-exploit
Brute-Force
SSH
DDoS Attack
Showing 16 to
20
of 20 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: