This IP address has been reported a total of
17
times from
14 distinct
sources.
54.196.134.220 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-26.
show less
(modsecurity) srv102 ModSecurity 54.196.134.220 (US/United States/ec2-54-196-134-220.compute-1.amazo ...
show more(modsecurity) srv102 ModSecurity 54.196.134.220 (US/United States/ec2-54-196-134-220.compute-1.amazonaws.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
{"level":"info","ts":1784956051.3168986,"logger":"http.log.access.log1","msg":"handled request","req ...
show more{"level":"info","ts":1784956051.3168986,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"54.196.134.220","remote_port":"57136","client_ip":"54.196.134.220","proto":"HTTP/1.1","method":"GET","host":"availability.applixure.com","uri":"/www/.env","headers":{"Connection":["keep-alive"],"Next-Action":["x"],"X-Nextjs-Request-Id":["c1f1314d"],"User-Agent":["Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"],"Accept-Encoding":["gzip, deflate"],"Accept":["*/*"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"http/1.1","server_name":"availability.applixure.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000847168,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1784956051.4556127,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"54.196.134.220","remote_port":"35640"
...
show less
IM360 WAF: Direct access to sensitive file or dotfile MV:/site/.env
Web App Attack
Anonymous
Bot / scanning and/or hacking attempts: GET /.env.txt HTTP/1.1, GET /.env HTTP/1.1, GET /.env.bak HT ...
show moreBot / scanning and/or hacking attempts: GET /.env.txt HTTP/1.1, GET /.env HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env2 HTTP/1.1, GET /.env.yml HTTP/1.1, GET /.env.ci HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.env.json HTTP/1.1, GET /.env.uat HTTP/1.1, GET /.env~ HTTP/1.1, GET /.env.yaml HTTP/1.1, GET /.env1 HTTP/1.1, GET /.env.live HTTP/1.1, GET /.env.swp HTTP/1.1, GET /.env.dist HTTP/1.1, GET /.env_copy HTTP/1.1, GET /.env.docker HTTP/1.1, GET /.env.preprod HTTP/1.1
show less