Skip to content

SSH and EC2 Instance Connect timing out after abuse case resolved

-1

Our instance i-099725ae5d09cc3c9 in ap-south-1 had an abuse case which we have resolved. The instance is running and healthy per system logs, but SSH (port 22) and EC2 Instance Connect are both timing out. SSM Agent shows i/o timeout to ssm.ap-south-1.amazonaws.com. We believe there is a network-level restriction still applied to this instance from the abuse case. Please remove the restriction. Elastic IP: 13.206.53.160, Account: 635936556228

also go the mail as well

Hello,

We have received an abuse report implicating resources on your account. To

enforce the abuse, we have taken the following steps:

Blocked all ports except for 22 and 3389

AWS Account ID: 635936556228

Implicated Resource(s): i-099725ae5d09cc3c9

Region(s): ap-south-1

Reported Activity: Port Scanning

The reported activity listed below violates the AWS Acceptable Use Policy (

https://aws.amazon.com/aup/ ). In order to resolve this report please

reply to this email with the corrective action taken to cease the activity.

Required Actions: Investigate root cause

If you require further assistance with resolving this abuse

report/complaint please see:

https://aws.amazon.com/premiumsupport/knowledge-center/aws-abuse-report/

If you do not consider the activity abusive, please reply to this email

detailing the reasons why.

Regards,

AWS Trust & Safety

-----------REPORT-------

Case number: P01KSNRK3Q82ADGYY2XVG5PY355

Logs:

Timestamp SrcIP SrcPort DstIP DstPort

2026-05-27T19:45:56.637Z 13.206.53.160 58962 82x24x200x217 80

2026-05-27T19:45:56.657Z 13.206.53.160 40424 82x24x200x217 9200

2026-05-27T19:45:56.66Z 13.206.53.160 55870 82x24x200x217 443

2026-05-27T22:19:18.998Z 13.206.53.160 47922 144x79x59x68 9200

  • How do you think the public internet is going to fix this? This is a a community forum not a support queue.

asked 6 days ago42 views
1 Answer
0

I thought your instance is still under a network-level restriction imposed by AWS Trust & Safety due to the abuse case. Even though the abuse activity has been resolved, AWS does not automatically lift restrictions until you formally respond to the abuse case email and confirm corrective actions.

https://repost.aws/knowledge-center/report-aws-abuse

EXPERT
answered 6 days ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.