This IP address has been reported a total of
31
times from
26 distinct
sources.
54.206.229.85 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 7
reports;
United States of America
with 6
reports;
Netherlands
with 4
reports.
The most common categories in these recent reports were:
Web App Attack
22
times;
Brute-Force
11
times;
Bad Web Bot
8
times;
Hacking
6
times;
DDoS Attack
1
time;
Other
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[ssd5.kdns.gr] httpd-shell-path-probe: sites=www.cancelletto.gr; logs=/var/log/httpd/domains/cancell ...
show more[ssd5.kdns.gr] httpd-shell-path-probe: sites=www.cancelletto.gr; logs=/var/log/httpd/domains/cancelletto.gr.log; samples=/wp-includes/IXR/shell.php
show less
(mod_security) mod_security (id:240000) triggered by 54.206.229.85 (ec2-54-206-229-85.ap-southeast-2 ...
show more(mod_security) mod_security (id:240000) triggered by 54.206.229.85 (ec2-54-206-229-85.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 21:13:18.943226 2026] [security2:error] [pid 24261:tid 24261] [client 54.206.229.85:55470] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||tdsdemo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "tdsdemo.com"] [uri "/images/stories/admin-post.php"] [unique_id "asmRLuY5M3gAnS32QEurGAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
Bot / scanning and/or hacking attempts: GET /cgi-bin HTTP/2.0, GET /admin.php HTTP/2.0, GET /alfanew ...
show moreBot / scanning and/or hacking attempts: GET /cgi-bin HTTP/2.0, GET /admin.php HTTP/2.0, GET /alfanew2.php7 HTTP/2.0, GET /lite.php HTTP/2.0, GET /wp-admin/css/colors/blue/lock.php HTTP/2.0, GET /wp-consar.php HTTP/2.0
show less
17 exploit-probe requests, each answered 403 between 2026-10-10T01:01:24Z and 2026-10-10T01:01:29Z.
...
show more17 exploit-probe requests, each answered 403 between 2026-10-10T01:01:24Z and 2026-10-10T01:01:29Z.
Signatures: wordpress x10, server-script x7
Paths: /edit.php /yanz.php /berlin.php /alfanew.php7 /wp-includes/ /wp-links.php /images/lmfi2.php /cgi-bin/upfile.php
User agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
Query strings omitted. Timestamp is the last hit observed.
show less