AbuseIPDB » 52.173.164.19
52.173.164.19 was found in our database!
This IP was reported 10 times. Confidence of
Abuse
is 47% : ?
ISP
Microsoft Corporation
Usage Type
Data Center/Web Hosting/Transit
ASN
AS8075
Domain Name
microsoft.com
Country
๐บ๐ธ
United States of America
City
Des Moines, Iowa
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 52.173.164.19 :
This IP address has been reported a total of
10
times from
10 distinct
sources.
52.173.164.19 was first reported on
July 15th 2026 , and the most recent report was
14 hours ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐บ๐ธ
mnsf
2026-09-01 15:05:38
(14 hours ago)
Too many Status 50X (13)
Scanning/Probing (13)
Brute-Force
Web App Attack
๐บ๐ธ
gumbysoft
2026-09-01 14:31:46
(14 hours ago)
Invalid Host header in HTTP request
Web App Attack
Anonymous
2026-09-01 14:24:00
(15 hours ago)
ENV File Scanning Attempt
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-01 13:44:48
(15 hours ago)
15 attempts against mh-modsecurity-ban on steel
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-09-01 13:41:22
(15 hours ago)
Multiple WAF Violations
Web App Attack
๐ท๐ธ
Scan
2026-08-10 06:37:39
(3 weeks ago)
MultiHost/MultiPort Probe, Scan, Hack -
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-10 06:33:47
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 52.173.164.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 52.173.164.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 02:33:38.232391 2026] [security2:error] [pid 8918:tid 8918] [client 52.173.164.19:60213] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.107"] [uri "/.git/HEAD"] [unique_id "anlwwh7c1NztmUVvNsTJzwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
wteiken
2026-08-10 06:29:59
(3 weeks ago)
rocinante.teiken.net:80 52.173.164.19:60108 - - [10/Aug/2026:02:29:46 -0400] "GET /.git/HEAD HTTP/1. ...
show more
rocinante.teiken.net:80 52.173.164.19:60108 - - [10/Aug/2026:02:29:46 -0400] "GET /.git/HEAD HTTP/1.1" 301 589 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
rocinante.teiken.net:80 52.173.164.19:60116 - - [10/Aug/2026:02:29:48 -0400] "GET /.git/config HTTP/1.1" 301 593 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36"
rocinante.teiken.net:80 52.173.164.19:60112 - - [10/Aug/2026:02:29:48 -0400] "GET /.git/logs/HEAD HTTP/1.1" 301 599 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 Edg/124.0.0.0"
rocinante.teiken.net:80 52.173.164.19:60128 - - [10/Aug/2026:02:29:50 -0400] "GET /.git/refs/heads/master HTTP/1.1" 301 615 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.4; rv:125.0) Gecko/20100101 Firefox/125.0"
rocinante.teiken.net:80 52.173.164.19:60800 - - [10/Aug/2026:02:29:50 -0400] "GET /.git/
...
show less
Web App Attack
๐ฎ๐น
VHosting
2026-07-31 22:35:09
(1 month ago)
Detected mail brute force attack from 4 different servers
Brute-Force
๐ธ๐ฌ
digitalsekuriti.id
2026-07-15 05:05:36
(1 month ago)
2026-07-15T12:05:31.251778 scm.getih.net sshd[1464530]: Invalid user r00t from 52.173.164.19 port 62 ...
show more
2026-07-15T12:05:31.251778 scm.getih.net sshd[1464530]: Invalid user r00t from 52.173.164.19 port 6298
2026-07-15T12:05:32.944070 scm.getih.net sshd[1464588]: Invalid user r00t from 52.173.164.19 port 6279
2026-07-15T12:05:34.739630 scm.getih.net sshd[1464609]: Invalid user r00t from 52.173.164.19 port 6272
...
show less
Brute-Force
SSH
Showing 1 to
10
of 10 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: