AbuseIPDB » 52.199.119.42
52.199.119.42 was found in our database!
This IP was reported 6 times. Confidence of
Abuse
is 18% : ?
ISP
Amazon Data Services Japan
Usage Type
Data Center/Web Hosting/Transit
ASN
AS16509
Hostname(s)
ec2-52-199-119-42.ap-northeast-1.compute.amazonaws.com
Domain Name
amazon.com
Country
π―π΅
Japan
City
Tokyo, Tokyo
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 52.199.119.42 :
This IP address has been reported a total of
6
times from
5 distinct
sources.
52.199.119.42 was first reported on
April 27th 2026 , and the most recent report was
1 month ago .
Old Reports:
The most recent abuse report for this IP address is from
1 month ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
π³π±
homeshowdomain.nl
2026-04-29 22:01:19
(1 month ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-04-28.
show less
Web App Attack
SSH
Hacking
π³π±
jjnxpct
2026-04-29 03:47:33
(1 month ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /.env.old (Rule ID: 920440) - URL file extension is restricted by policy
show less
Web App Attack
SQL Injection
Hacking
π³π±
Site.eu
2026-04-28 03:47:55
(1 month ago)
Excessive 404/403 errors
Brute-Force
πΊπΈ
TPI-Abuse
2026-04-28 01:21:51
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 52.199.119.42 (ec2-52-199-119-42.ap-northeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 52.199.119.42 (ec2-52-199-119-42.ap-northeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 21:21:44.542255 2026] [security2:error] [pid 32001:tid 32001] [client 52.199.119.42:60994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jimvassilakos.com"] [uri "/.git/config"] [unique_id "afALqFiYilAn0-w9zEsKXgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-28 00:58:24
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 52.199.119.42 (ec2-52-199-119-42.ap-northeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 52.199.119.42 (ec2-52-199-119-42.ap-northeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 20:58:20.388126 2026] [security2:error] [pid 31885:tid 31885] [client 52.199.119.42:49760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jimpaddywilliams.org"] [uri "/.git/config"] [unique_id "afAGLNxTVCFGio1gCmcqvgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Jimbocous
2026-04-27 23:42:00
(1 month ago)
145 web app attacks within 15 sec. Unauthorised access attempts. Probing for known web app vulnerabi ...
show more
145 web app attacks within 15 sec. Unauthorised access attempts. Probing for known web app vulnerabilities. Brute force attacks.
show less
DDoS Attack
Brute-Force
Web App Attack
Hacking
Showing 1 to
6
of 6 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown π©
Recently Reported IPs: