Check an IP Address, Domain Name, Subnet, or ASN
18.220.88.128 has a threat confidence score of 92%. This IP address from United States (AS16509, Amazon.com, Inc.) has been observed in 45 honeypot sessions targeting HTTPS, SIP, FTP, HTTP, DOCKER and 5 other protocols. First observed on April 14, 2026, most recently active April 15, 2026.
Identifies an HTTPS request targeting the .git/config file within a web-accessible repository directory. Access attempts to /.git/config indicate automated repository exposure scanning intended to retrieve remote origin URLs, repository structure, and potentially credential-bearing configuration data. This is a common reconnaissance technique used to identify misconfigured web servers exposing version control metadata.
Client repeatedly sends GET requests to the /bad-request Docker API endpoint, indicating malformed or incompatible traffic against the Docker daemon. This pattern is typically associated with generic internet scanning or tools attempting HTTP interaction without speaking the proper Docker API protocol.
Identifies HTTP GET requests directly targeting the /bad-request path, indicating automated or manual probing of application error-handling routes rather than legitimate navigation flow.