AbuseIPDB » 13.125.213.55
13.125.213.55 was found in our database!
This IP was reported 8 times. Confidence of
Abuse
is 37% : ?
ISP
AWS Asia Pacific (Seoul) Region
Usage Type
Data Center/Web Hosting/Transit
ASN
AS16509
Hostname(s)
ec2-13-125-213-55.ap-northeast-2.compute.amazonaws.com
Domain Name
amazon.com
Country
๐ฐ๐ท
Korea (the Republic of)
City
Incheon, Incheon
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 13.125.213.55 :
This IP address has been reported a total of
8
times from
8 distinct
sources.
13.125.213.55 was first reported on
August 4th 2026 , and the most recent report was
2 weeks ago .
Old Reports:
The most recent abuse report for this IP address is from
2 weeks ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ณ๐ฑ
e.fierstra
2026-08-05 08:36:19
(2 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-08-05 06:05:28
(2 weeks ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐ฎ๐น
VHosting
2026-08-05 03:50:03
(2 weeks ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-05 03:47:29
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 13.125.213.55 (ec2-13-125-213-55.ap-northeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 13.125.213.55 (ec2-13-125-213-55.ap-northeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 23:47:23.528399 2026] [security2:error] [pid 815436:tid 815436] [client 13.125.213.55:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.assistguide.net"] [uri "/.env.local"] [unique_id "anKyS4X9r9Wub1UTFWgvoQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-08-05 01:32:35
(2 weeks ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
KR/South Korea/ec2-13-125-213-55.ap-northeast-2.co ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
KR/South Korea/ec2-13-125-213-55.ap-northeast-2.compute.amazonaws.com
show less
Web App Attack
๐ต๐ฑ
srebrakowski.com
2026-08-04 16:02:46
(2 weeks ago)
crowdsec/crowdsecurity/appsec-vpatch
Brute-Force
๐ซ๐ฎ
Kimmo Rieskaniemi
2026-08-04 14:51:54
(2 weeks ago)
CrowdSec triggered crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ซ๐ท
Hippoline
2026-08-04 13:21:24
(2 weeks ago)
[Tue Aug 04 15:20:53.046554 2026] [authz_core:error] [pid 6625] [client 13.125.213.55:58144] AH01630 ...
show more
[Tue Aug 04 15:20:53.046554 2026] [authz_core:error] [pid 6625] [client 13.125.213.55:58144] AH01630: client denied by server configuration: /var/www/hippoline.lu/web/cakephp
[Tue Aug 04 15:21:22.863482 2026] [access_compat:error] [pid 10699] [client 13.125.213.55:35294] AH01797: client denied by server configuration: /var/www/hippoline.lu/web/phpinfo.php
[Tue Aug 04 15:21:23.083714 2026] [access_compat:error] [pid 10699] [client 13.125.213.55:35294] AH01797: client denied by server configuration: /var/www/hippoline.lu/web/info.php
[Tue Aug 04 15:21:23.305317 2026] [access_compat:error] [pid 10699] [client 13.125.213.55:35294] AH01797: client denied by server configuration: /var/www/hippoline.lu/web/php.php
[Tue Aug 04 15:21:23.529418 2026] [access_compat:error] [pid 10699] [client 13.125.213.55:35294] AH01797: client denied by server configuration: /var/www/hippoline.lu/web/i.php
...
show less
Brute-Force
Web App Attack
Showing 1 to
8
of 8 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: