This IP address has been reported a total of
28
times from
24 distinct
sources.
54.255.219.221 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
(mod_security) mod_security (id:210730) triggered by 54.255.219.221 (ec2-54-255-219-221.ap-southeast ...
show more(mod_security) mod_security (id:210730) triggered by 54.255.219.221 (ec2-54-255-219-221.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 17:22:42.780997 2026] [security2:error] [pid 30444:tid 30444] [client 54.255.219.221:60202] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||learningbyshipping.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "learningbyshipping.com"] [uri "/z9x8c7v6b5-debug-trigger-learningbyshipping.com"] [unique_id "apCqojpax0WsCMAt3EKUkwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
Multiple web server 400 error codes from same source ip
Web App Attack
Anonymous
Bot / scanning and/or hacking attempts: [20/19] done: stream 39, GET /serverless.yml, GET /.env HTTP ...
show moreBot / scanning and/or hacking attempts: [20/19] done: stream 39, GET /serverless.yml, GET /.env HTTP/2.0, [28/27] done: stream 185, GET /api/settings, GET /.env.example HTTP/2.0, [0/0] init
show less