Neutral Activity
There is no recent abuse activity, or the IP address is whitelisted.
Whitelisted Subnet
Whitelisted netblocks are typically owned by trusted entities, such as Google or Microsoft who
may use them for search engine spiders. However, these same entities sometimes also provide cloud
servers and mail services which are easily abused. Pay special attention when trusting or
distrusting these IPs.
Log in to view charts and search reports for this IP.
Log In
Reports Activity
Example preview
Report Categories (Last 60 Days)
Example preview
Top Reporter Countries (Last 60 Days)
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 172.68.234.4
This IP address has been reported a total of
45
times from
16 distinct
sources.
172.68.234.4 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Belgium
with 2
reports;
Switzerland
with 1
report.
The most common categories in these recent reports were:
Web App Attack
3
times;
Hacking
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[TueSep2917:02:21.6806602026][security2:error][pid964522:tid964603][client172.68.234.4:0]ModSecurity ...
show more[TueSep2917:02:21.6806602026][security2:error][pid964522:tid964603][client172.68.234.4:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"710\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"swiss-domain-name.ch\"][uri\"/.env.sample\"][unique_id\"arvS_SxP1NqTOAZRA4_IPgAAAUQ\"]
show less
Triggered Cloudflare WAF (firewallManaged) from FR.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show moreTriggered Cloudflare WAF (firewallManaged) from FR.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /aws-config.js
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-04-04T08:58:19.067900+02:00 nimbus sshd[29834]: Invalid user chris from 172.68.234.4 port 30076 ...
show more2026-04-04T08:58:19.067900+02:00 nimbus sshd[29834]: Invalid user chris from 172.68.234.4 port 30076
2026-04-04T08:58:19.234855+02:00 nimbus sshd[29834]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=172.68.234.4
2026-04-04T08:58:21.261745+02:00 nimbus sshd[29834]: Failed password for invalid user chris from 172.68.234.4 port 30076 ssh2
...
show less
Confirmed malicious activity observed via T-Pot honeypot Observed 10 events on port 80 (unknown) fro ...
show moreConfirmed malicious activity observed via T-Pot honeypot Observed 10 events on port 80 (unknown) from 2026-01-01T17:48:15+00:00 to 2026-01-01T17:50:35.781000+00:00. Sample: {"src_port": 13134, "event_type": "http", "dest_port": 80, "src_ip": "172.68.234.4"}
show less