This IP address has been reported a total of
53
times from
38 distinct
sources.
54.94.85.181 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 10
reports;
Netherlands
with 9
reports;
Poland
with 6
reports.
The most common categories in these recent reports were:
Web App Attack
43
times;
Bad Web Bot
17
times;
Brute-Force
11
times;
Hacking
7
times;
DDoS Attack
4
times;
Other
5
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Oct 5 07:40:47 54.94.85.181 TCP SPT=56590 DPT=443 SYN
Oct 5 07:40:47 54.94.85.181 TCP SPT=56726 DP ...
show moreOct 5 07:40:47 54.94.85.181 TCP SPT=56590 DPT=443 SYN
Oct 5 07:40:47 54.94.85.181 TCP SPT=56726 DPT=443 SYN
Oct 5 07:40:47 54.94.85.181 TCP SPT=56702 DPT=443 SYN
Oct
...
show less
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 54.94.85.181 (BR/Brazil/ec2-54-94-85-181. ...
show more(secretscan) Secret-Scanner (env/git/ssh/credentials) from 54.94.85.181 (BR/Brazil/ec2-54-94-85-181.sa-east-1.compute.amazonaws.com)
show less
(mod_security) mod_security (id:210492) triggered by 54.94.85.181 (ec2-54-94-85-181.sa-east-1.comput ...
show more(mod_security) mod_security (id:210492) triggered by 54.94.85.181 (ec2-54-94-85-181.sa-east-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 03:45:31.442010 2026] [security2:error] [pid 4996:tid 4996] [client 54.94.85.181:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globetechsecurities.com"] [uri "/backend/.env"] [unique_id "asIEGz4aFLa1xXzm2WxO6AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
Bot / seems abusive / Apache connections: 22
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
Anonymous
Bot / scanning and/or hacking attempts: GET /dump.sql HTTP/1.1, GET /server/.env HTTP/1.1, GET /api/ ...
show moreBot / scanning and/or hacking attempts: GET /dump.sql HTTP/1.1, GET /server/.env HTTP/1.1, GET /api/.env.production HTTP/1.1, GET /terraform.tfstate HTTP/1.1, GET /api/env.local.js HTTP/1.1, GET /.env.stage HTTP/1.1, GET /api/config/.env HTTP/1.1, GET /db.sql HTTP/1.1, GET /appsettings.Production.json HTTP/1.1, GET /id_rsa HTTP/1.1, GET /key.pem HTTP/1.1, GET /database.php HTTP/1.1, GET /app/.env.local HTTP/1.1, GET /api/env.labs.js HTTP/1.1, GET /configuration.php HTTP/1.1, GET /.yarnrc.yml HTTP/1.1, GET /.env.save HTTP/1.1, GET /.travis.yml HTTP/1.1, GET /local.settings.json HTTP/1.1, GET /api/env.labs.json HTTP/1.1, GET /service-account.json HTTP/1.1, GET /Jenkinsfile HTTP/1.1, GET /backup.sql HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /htpasswd HTTP/1.1, GET /appsettings.Development.json HTTP/1.1, GET /azure-pipelines.yml HTTP/1.1, GET /.npmrc HTTP/1.1, GET /appsettings.Staging.json HTTP/1.1
show less
Hacking
Web App Attack
Anonymous
(wordpress) Failed login wp-login.php or xmlrpc.php
[ti-26al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more[ti-26al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 54.94.85.181 - - [04/Oct/2026:04:39:50 +0200] "GET /.env.development HTTP/1.1" 404 7808 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.7.21"
...
show less