This IP address has been reported a total of
28
times from
18 distinct
sources.
54.167.242.114 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
(mod_security) mod_security (id:210492) triggered by 54.167.242.114 (US/United States/ec2-54-167-242 ...
show more(mod_security) mod_security (id:210492) triggered by 54.167.242.114 (US/United States/ec2-54-167-242-114.compute-1.amazonaws.com): 5 in the last 300 secs (CF_ENABLE)
show less
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 54.167.242.114 (US/United States/ec2- ...
show more(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 54.167.242.114 (US/United States/ec2-54-167-242-114.compute-1.amazonaws.com): 1 in the last 3600 secs (0-195)
show less
(mod_security) mod_security (id:210492) triggered by 54.167.242.114 (ec2-54-167-242-114.compute-1.am ...
show more(mod_security) mod_security (id:210492) triggered by 54.167.242.114 (ec2-54-167-242-114.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 04:48:51.668942 2026] [security2:error] [pid 12748:tid 12748] [client 54.167.242.114:52564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thomasgardner.com"] [uri "/wp-config.php.bak"] [unique_id "arOSc_psaSROpjrTgfD7DQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
Bot / scanning and/or hacking attempts: GET /.env.save HTTP/1.1, GET /.env.bak HTTP/1.1, GET /compos ...
show moreBot / scanning and/or hacking attempts: GET /.env.save HTTP/1.1, GET /.env.bak HTTP/1.1, GET /composer.json HTTP/1.1, GET /.env.swp HTTP/1.1, GET /.hg/store/00manifest.i HTTP/1.1, GET /.env.old HTTP/1.1, GET /.git/HEAD HTTP/1.1, GET /.git/index HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /wp-config.php.txt HTTP/1.1, GET /.git/config HTTP/1.1, GET /composer.lock HTTP/1.1, GET /.env.txt HTTP/1.1, GET /.svn/entries HTTP/1.1
show less
This address requests our sites over plain http, is answered with a redirect to https, and never fol ...
show moreThis address requests our sites over plain http, is answered with a redirect to https, and never follows it โ over and over. A browser follows redirects; a scanner enumerating hosts does not. It reads nothing it asks for and only loads the server; blocked. Please check what runs on this address. | method: GET | path: /api/session/properties | 2026-09-23 07:56 UTC
show less
733 requests with url.path *.php.bak
636 requests with url.path *debug.log
629 requests with url. ...
show more733 requests with url.path *.php.bak
636 requests with url.path *debug.log
629 requests with url.path */debug.log
262 requests with url.path /phpinfo.php
231 requests with url.path */package.json
221 requests with url.path *.svn/*
211 requests with url.path */yarn.lock
200 requests with url.path */package-lock.json
195 requests with url.path */composer.lock
194 requests with url.path */composer.json
190 requests with url.path *.hg/*
188 requests with url.path */error.log
188 requests with url.path *.sql.gz
show less
Brute-Force
Bad Web Bot
Anonymous
[ns3.backorder.gr] httpd-config-scan: sites=www.blazos.com; logs=/var/log/httpd/domains/blazos.com.l ...
show more[ns3.backorder.gr] httpd-config-scan: sites=www.blazos.com; logs=/var/log/httpd/domains/blazos.com.log; samples=/wp-config.php.bak | /wp-config.php~ | /wp-config.php.save
show less