This IP address has been reported a total of
68
times from
58 distinct
sources.
134.199.218.54 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
ModSecurity detection - Rules: 920450(HTTP header is restricted by policy (/content-encoding/)), 200 ...
show moreModSecurity detection - Rules: 920450(HTTP header is restricted by policy (/content-encoding/)), 200002(Failed to parse request body.)
show less
HTTP header is restricted by policy (/content-encoding/). String match within "/content-encoding/ /p ...
show moreHTTP header is restricted by policy (/content-encoding/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_content-encoding. (920450-mnz6-7)
show less
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10 ...
show more[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10m window.
Origin: US / AS14061 DigitalOcean, LLC
Active: 15:07:29 UTC
Volume: 1 HTTP req
Probed: /
Status mix: 444ร1
Vhost fishing: secondopinion.ztx-lab.com
UA: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
CSF/lfd permanent block on srv1.woytas.ovh. Trigger=LF_MODSEC; ports=*; (mod_security) mod_security ...
show moreCSF/lfd permanent block on srv1.woytas.ovh. Trigger=LF_MODSEC; ports=*; (mod_security) mod_security (id:949110) triggered by 134.199.218.54 (US/United States/-): 5 in the last 3600 secs
show less
Triggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (PO ...
show moreTriggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (POST method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
[Wed Sep 02 16:19:03.817913 2026] [authz_core:error] [pid 1698237] [client 134.199.218.54:19890] AH0 ...
show more[Wed Sep 02 16:19:03.817913 2026] [authz_core:error] [pid 1698237] [client 134.199.218.54:19890] AH01630: client denied by server configuration: /var/www/html/default/, referer: https://narrowblast-usercontent.amo.rocks/
[Wed Sep 02 16:19:03.992926 2026] [authz_core:error] [pid 1698237] [client 134.199.218.54:19890] AH01630: client denied by server configuration: /var/www/html/default/, referer: https://narrowblast-usercontent.amo.rocks/
[Wed Sep 02 16:19:04.211154 2026] [authz_core:error] [pid 1698237] [client 134.199.218.54:19890] AH01630: client denied by server configuration: /var/www/html/default/, referer: https://narrowblast-usercontent.amo.rocks/
[Wed Sep 02 16:19:04.425199 2026] [authz_core:error] [pid 1698237] [client 134.199.218.54:19890] AH01630: client denied by server configuration: /var/www/html/default/, referer: https://narrowblast-usercontent.amo.rocks/
[Wed Sep 02 16:19:04.677754 2026] [authz_core:error] [pid 1698237] [client 134.199.218.54:19890] AH01630: client den
...
show less