This IP address has been reported a total of
11
times from
8 distinct
sources.
3.106.56.78 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-27.
show less
threat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity ...
show morethreat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity/appsec-vpatch,crowdsecurity/vpatch-CVE-2025-55182,crowdsecurity/vpatch-env-access,crowdsecurity/vpatch-git-config targets=cloud hit_count=6 first_seen=2026-07-27T14:31:08Z last_seen=2026-07-27T14:31:09Z
show less
(ScanningForFiles) Scanning for files triggerd 3.106.56.78 (AU/Australia/ec2-3-106-56-78.ap-southeas ...
show more(ScanningForFiles) Scanning for files triggerd 3.106.56.78 (AU/Australia/ec2-3-106-56-78.ap-southeast-2.compute.amazonaws.com): 10 in the last 600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
Anonymous
Multiple web server 400 error codes from same source ip
(mod_security) mod_security triggered on hostname [redacted] 3.106.56.78 (AU/Australia/New South Wal ...
show more(mod_security) mod_security triggered on hostname [redacted] 3.106.56.78 (AU/Australia/New South Wales/Sydney/ec2-3-106-56-78.ap-southeast-2.compute.amazonaws.com)
show less
SQL Injection
Showing 1 to
11
of 11 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ