This IP address has been reported a total of
64
times from
55 distinct
sources.
54.252.250.213 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 15
reports;
Germany
with 10
reports;
Netherlands
with 10
reports.
The most common categories in these recent reports were:
Web App Attack
52
times;
Brute-Force
19
times;
Bad Web Bot
13
times;
Hacking
8
times;
Port Scan
6
times;
Other
11
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: AU, Attack patterns: Word ...
show moreBlocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: AU, Attack patterns: WordPress scanning, Webshell probing
show less
GET /alfanew.php7 | rule: web-attack-signature | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) Apple ...
show moreGET /alfanew.php7 | rule: web-attack-signature | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | net: Amazon.com, Inc. AS16509
show less
(mod_security) mod_security (id:1000001) triggered by 54.252.250.213 (AU/Australia/New South Wales/S ...
show more(mod_security) mod_security (id:1000001) triggered by 54.252.250.213 (AU/Australia/New South Wales/Sydney/-/[AS16509 Amazon.com, Inc.]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Fri Oct 09 07:19:26.298469 2026] [security2:error] [pid 437484:tid 437504] [remote 54.252.250.213:60790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/about.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "103"] [id "1000001"] [msg "Bad file blocked: /wp-includes/images/about.php"] [severity "CRITICAL"] [tag "security"] [hostname "mail.michalismaniatis.com"] [uri "/wp-includes/images/about.php"] [unique_id "ashrTrqn1FRfEBU5VJvmhwADwg4"]
show less
Port Scan
Anonymous
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: AU, Attack patterns: Word ...
show moreBlocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: AU, Attack patterns: WordPress scanning, Webshell probing
show less
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto ...
show moreAutomated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto-banned by fail2ban.
show less
Repeated probing for credential and configuration files, and for known webshell and remote-code-exec ...
show moreRepeated probing for credential and configuration files, and for known webshell and remote-code-execution endpoints, on our web server. Every request was refused with a 4xx status; none returned content. Paths probed: /.well-known/acme-challenge/wso112233.php, /.well-known/acme-challenge/classwithtostring.php, /.well-known/content.php.
show less