AbuseIPDB » 57.154.3.243
57.154.3.243 was found in our database!
This IP was reported 10 times. Confidence of
Abuse
is 53% : ?
ISP
Microsoft Limited
Usage Type
Data Center/Web Hosting/Transit
ASN
AS8075
Domain Name
microsoft.com
Country
๐บ๐ธ
United States of America
City
Phoenix, Arizona
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 57.154.3.243 :
This IP address has been reported a total of
10
times from
10 distinct
sources.
57.154.3.243 was first reported on
August 4th 2026 , and the most recent report was
11 hours ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
2026-09-01 10:57:34
(11 hours ago)
57.154.3.243 - - [01/Sep/2026:12:57:15 +0200] "GET /.git/config HTTP/1.1" 403 7187 "-" "Mozilla/5.0 ...
show more
57.154.3.243 - - [01/Sep/2026:12:57:15 +0200] "GET /.git/config HTTP/1.1" 403 7187 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
57.154.3.243 - - [01/Sep/2026:12:57:15 +0200] "GET /admin/login HTTP/1.1" 404 5535 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
57.154.3.243 - - [01/Sep/2026:12:57:15 +0200] "GET /app HTTP/1.1" 404 5535 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
57.154.3.243 - - [01/Sep/2026:12:57:16 +0200] "GET /wp-content/plugins/post-smtp/readme.txt HTTP/1.1" 403 7187 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
57.154.3.243 - - [01/Sep/2026:12:57:16 +0200] "GET /.git/config HTTP/1.1" 403 7194 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:139.0) Gecko/20100101 Firefox/139.0"
57.154.3.243 - - [01/Sep/2026:12:57:16 +0200] "GET /.git/config HTTP/1.1" 403
...
show less
DDoS Attack
๐ฉ๐ช
FeG Deutschland
2026-09-01 08:45:08
(13 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-09-01 08:04:02
(14 hours ago)
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-09-01 07:23:28
(15 hours ago)
20 attempts against mh-misbehave-ban on ficus
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:23:24
(15 hours ago)
(mod_security) mod_security (id:218420) triggered by 57.154.3.243 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:218420) triggered by 57.154.3.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:23:20.373814 2026] [security2:error] [pid 3673:tid 3673] [client 57.154.3.243:29724] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||justinrudd.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "justinrudd.com"] [uri "/php-cgi/php-cgi.exe"] [unique_id "apZ9aL2WxUJ61ywbw-BJAgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
www.fransveldman.world
2026-08-17 10:32:34
(2 weeks ago)
Fetched browser challenge page 10 times in <2h without solving. Likely bad bot.
Bad Web Bot
๐ฎ๐น
VHosting
2026-08-04 20:50:03
(4 weeks ago)
Detected mail brute force attack from 4 different servers
Brute-Force
Anonymous
2026-08-04 05:34:14
(4 weeks ago)
denied traffic to a honeypot network. destination port 2096.
Port Scan
Hacking
Anonymous
2026-08-04 05:21:51
(4 weeks ago)
57.154.3.243 detected on srv02
Port Scan
๐น๐ผ
kk_it_man
2026-08-04 03:50:12
(4 weeks ago)
Port Scan
Showing 1 to
10
of 10 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: