Log in to view charts and search reports for this IP.
Log In
No reports in the last 60 days
54.226.165.168 has been reported 37
times. The most recent report is from
.
The full history is preserved below and remains searchable. A
0% score reflects the absence of recent activity, but
this is not a guarantee that earlier reports were invalid. Abuse confidence score decays,
naturally, over time, when the abusive activity stops.
IP Abuse Reports for 54.226.165.168:
This IP address has been reported a total of
37
times from
21 distinct
sources.
54.226.165.168 was first reported on
, and the most recent report was
.
COMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" ...
show moreCOMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. (210730-169)
show less
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 54.226.165.168 (US/United States/ec2 ...
show moreLF_MODSEC: (mod_security) mod_security (id:949110) triggered by 54.226.165.168 (US/United States/ec2-54-226-165-168.compute-1.amazonaws.com): 1 in the last 3600 secs
show less
Web App Attack
Anonymous
Bot / scanning and/or hacking attempts: GET /.aws/credentials HTTP/1.1, GET /wp-config.php.bak HTTP/ ...
show moreBot / scanning and/or hacking attempts: GET /.aws/credentials HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /static/js/2.ca066a4b.chunk.js HTTP/1.1, GET /dashboard/phpinfo.php HTTP/1.1, GET /info.php HTTP/1.1, GET /static/js/main.141b0494.js HTTP/1.1
show less
Attempting to probe for sensitive information accidently exposed via git config.
54.226.165.168 - - ...
show moreAttempting to probe for sensitive information accidently exposed via git config.
54.226.165.168 - - [03/Oct/2025:05:51:23 +0000] "GET /.git/config HTTP/1.1" 403 153 "-" "Mozilla/5.0 (Windows NT 10.0; rv:91.0) Gecko/20100101 Firefox/91.0"
show less
70 attacks on env grabbing URLs, config grabbing URLs (type 2), PHP URLs, password grabbing URLs:
GE ...
show more70 attacks on env grabbing URLs, config grabbing URLs (type 2), PHP URLs, password grabbing URLs:
GET /web/.env HTTP/1.1
GET /appsettings.json HTTP/1.1
GET /getcpuutil.php-bakworking HTTP/1.1
GET /.aws/credentials HTTP/1.1
show less
(mod_security) mod_security triggered on hostname [redacted] 54.226.165.168 (US/United States/ec2-54 ...
show more(mod_security) mod_security triggered on hostname [redacted] 54.226.165.168 (US/United States/ec2-54-226-165-168.compute-1.amazonaws.com)
show less
(modsecurity) srv102 ModSecurity 54.226.165.168 (US/United States/ec2-54-226-165-168.compute-1.amazo ...
show more(modsecurity) srv102 ModSecurity 54.226.165.168 (US/United States/ec2-54-226-165-168.compute-1.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less