AbuseIPDB » 15.165.34.225
15.165.34.225 was found in our database!
This IP was reported 4 times. Confidence of
Abuse
is 17% : ?
ISP
AWS Asia Pacific (Seoul) Region
Usage Type
Data Center/Web Hosting/Transit
ASN
AS16509
Hostname(s)
ec2-15-165-34-225.ap-northeast-2.compute.amazonaws.com
Domain Name
amazon.com
Country
π°π·
Korea (the Republic of)
City
Incheon, Incheon
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 15.165.34.225 :
This IP address has been reported a total of
4
times from
3 distinct
sources.
15.165.34.225 was first reported on
July 8th 2026 , and the most recent report was
2 weeks ago .
Old Reports:
The most recent abuse report for this IP address is from
2 weeks ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
π¬π·
setupgr
2026-07-08 15:10:02
(2 weeks ago)
(mod_security) mod_security (id:1000001) triggered by 15.165.34.225 (KR/South Korea/Incheon/Incheon/ ...
show more
(mod_security) mod_security (id:1000001) triggered by 15.165.34.225 (KR/South Korea/Incheon/Incheon/-/[AS16509 AMAZON-02]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Wed Jul 08 18:09:58.181681 2026] [security2:error] [pid 1409118:tid 1409161] [client 15.165.34.225:52908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/p.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "103"] [id "1000001"] [msg "Bad file blocked: /p.php"] [severity "CRITICAL"] [tag "security"] [hostname "villa-izabela.com"] [uri "/p.php"] [unique_id "ak5oRhIhbCIkZEt_tZ6j9gAAAFA"]
show less
Port Scan
π¨π
dalslab ltd
2026-07-08 13:53:26
(2 weeks ago)
[08/Jul/2026:15:53:09 +0200] - 404 404 - GET https vikunja.dalslab.com "/api/.env" [Client 15.165.34 ...
show more
[08/Jul/2026:15:53:09 +0200] - 404 404 - GET https vikunja.dalslab.com "/api/.env" [Client 15.165.34.225] [Length 24] [Gzip -] [Sent-to 10.1.1.252] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[08/Jul/2026:15:53:24 +0200] - 404 404 - GET https vikunja.dalslab.com "/api/v1/.env" [Client 15.165.34.225] [Length 24] [Gzip -] [Sent-to 10.1.1.252] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[08/Jul/2026:15:53:24 +0200] - 404 404 - GET https vikunja.dalslab.com "/api/v2/.env" [Client 15.165.34.225] [Length 24] [Gzip -] [Sent-to 10.1.1.252] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[08/Jul/2026:15:53:26 +0200] - 404 404 - GET https vikunja.dalslab.com "/api/v3/.env" [Client 15.165.34.225] [Length 24] [Gzip -] [Sent-to 10.1.1.252] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Ap
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
π±π»
garmtech.com
2026-07-08 12:46:15
(2 weeks ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/api/v3/.env
Web App Attack
π±π»
garmtech.com
2026-07-08 12:45:26
(2 weeks ago)
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js ...
show more
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js < 15.0.5/16.0.7 (CVE-2025-55182, CVE-2025-66478)
show less
Hacking
Showing 1 to
4
of 4 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown π©
Recently Reported IPs: