AbuseIPDB » 54.255.221.57
54.255.221.57 was found in our database!
This IP was reported 7 times. Confidence of
Abuse
is 12% : ?
ISP
Amazon Data Services Japan
Usage Type
Data Center/Web Hosting/Transit
ASN
AS16509
Hostname(s)
ec2-54-255-221-57.ap-southeast-1.compute.amazonaws.com
Domain Name
amazon.com
Country
πΈπ¬
Singapore
City
Singapore
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 54.255.221.57 :
This IP address has been reported a total of
7
times from
5 distinct
sources.
54.255.221.57 was first reported on
August 5th 2025 , and the most recent report was
1 hour ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
πΊπΈ
TPI-Abuse
2026-07-24 12:02:06
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 54.255.221.57 (ec2-54-255-221-57.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 54.255.221.57 (ec2-54-255-221-57.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 08:02:02.062492 2026] [security2:error] [pid 3946142:tid 3946142] [client 54.255.221.57:38840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wandering-home.wendeenicole.com"] [uri "/.git/config"] [unique_id "amNUOnV1Ph8wJR_XQdswNwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΏπ¦
conure
2026-07-24 09:36:16
(3 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 06:20:40
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.255.221.57 (ec2-54-255-221-57.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 54.255.221.57 (ec2-54-255-221-57.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:20:35.258257 2026] [security2:error] [pid 9990:tid 9990] [client 54.255.221.57:52526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.walkerweb.walkerweb.com"] [uri "/.git/config"] [unique_id "amMEM7VM3AiVb2anvw3AoAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 05:26:12
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.255.221.57 (ec2-54-255-221-57.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 54.255.221.57 (ec2-54-255-221-57.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 01:26:08.704619 2026] [security2:error] [pid 23811:tid 23811] [client 54.255.221.57:49346] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.waleed.co.waleed-alshalan.com"] [uri "/.git/config"] [unique_id "amL3cAxUlNSsHTKFGzLBaAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
webbfabriken
2025-08-05 12:11:17
(11 months ago)
Invalid WordPress login attempt
Attack reported by Webbfabriken Security API - WFSecAPI
Brute-Force
π§πͺ
cmbplf
2025-08-05 11:26:18
(11 months ago)
817 requests with url.path */wp-includes/wlwmanifest.xml
Brute-Force
Bad Web Bot
Anonymous
2025-08-05 10:49:26
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Showing 1 to
7
of 7 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown π©
Recently Reported IPs: