This IP address has been reported a total of
11
times from
8 distinct
sources.
154.208.54.223 was first reported on
March 28th 2026 , and the most recent report was
3 weeks ago .
In the last 60 days, the top reporter locations were:
United States of America
with 4
reports;
Germany
with 2
reports;
France
with 1
report.
The most common categories in these recent reports were:
Web App Attack
4
times;
Bad Web Bot
4
times;
Brute-Force
3
times;
Exploited Host
2
times;
DDoS Attack
2
times;
Other
1
time.
Old Reports
The most recent abuse report for this IP address is from
3 weeks ago . It is possible that this IP is no
longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐บ๐ธ
TPI-Abuse
2026-09-17 09:57:31
(3 weeks ago)
(mod_security) mod_security (id:210350) triggered by 154.208.54.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 154.208.54.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 05:57:27.169444 2026] [security2:error] [pid 2477:tid 2477] [client 154.208.54.223:20360] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||astglobalgroup.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "astglobalgroup.com"] [uri "/"] [unique_id "aqu5h8w9pEHEy0c2v-O8uQAAAAA"], referer: https://backlinkscheckerseo.space/dir/trusted-link-building-14519
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-08-27 06:08:22
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-22 12:11:44
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 154.208.54.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 154.208.54.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 08:11:38.695428 2026] [security2:error] [pid 3324:tid 3324] [client 154.208.54.223:38696] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.208.54.223 (+1 hits since last alert)|mayiasteadman.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mayiasteadman.com"] [uri "/xmlrpc.php"] [unique_id "aomR-qcnvd_EDAD8pxxghAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-08-22 12:09:16
(1 month ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-geofence-sus.
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-08-22 11:39:40
(1 month ago)
(wordpress) Failed wordpress login from 154.208.54.223 (PK/Pakistan/Punjab/Lahore/-)
Brute-Force
๐ซ๐ท
Zkillu
2026-08-20 16:35:28
(1 month ago)
DDoS flood attack against 82.152.54.0 (2026-08-20 16:30:28 -> 2026-08-20 16:45:28 UTC) targeting AS2 ...
show more
DDoS flood attack against 82.152.54.0 (2026-08-20 16:30:28 -> 2026-08-20 16:45:28 UTC) targeting AS215599. This IP (AS150750) sent ~89959 packets (127.83 MB) during the attack window. Likely a compromised device (botnet).
show less
DDoS Attack
Exploited Host
๐ฉ๐ช
Vegascosmetics
2026-08-16 01:36:38
(1 month ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after deep/obfuscated attack (encoding nest ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after deep/obfuscated attack (encoding nesting / CPU-drain risk). Evidence: DEEP ATTACK: Recursive currentUrl nesting detected
show less
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
Zandro
2026-08-09 21:00:14
(2 months ago)
distributed harvester
DDoS Attack
Bad Web Bot
Exploited Host
๐บ๐ธ
kosada.com
2026-08-05 08:23:09
(2 months ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ฉ๐ช
botreporter
2026-07-07 08:56:01
(3 months ago)
botnet ignoring robots.txt
Bad Web Bot
๐บ๐ธ
kosada.com
2026-03-28 06:19:53
(6 months ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
Showing 1 to
11
of 11 reports