This IP address has been reported a total of
13
times from
13 distinct
sources.
34.14.198.13 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
Multiple web server 400 error codes from same source ip
{"level":"info","ts":1781355180.6080618,"logger":"http.log.access.log1","msg":"handled request","req ...
show more{"level":"info","ts":1781355180.6080618,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.14.198.13","remote_port":"35952","client_ip":"34.14.198.13","proto":"HTTP/1.1","method":"GET","host":"md.status.dtcc.taipei","uri":"/v2/actuator/configprops","headers":{"User-Agent":["Mozilla/5.0 (iPad; CPU OS 13_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) GSA/79.0.259819395 Mobile/17A5556d Safari/604.1"],"Accept-Charset":["utf-8"],"Accept-Encoding":["gzip"],"Connection":["close"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"md.status.dtcc.taipei","ech":false}},"bytes_read":0,"user_id":"","duration":0.000111643,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1781355180.6102111,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.14.198.13","remote_port":"35972","client_ip":"34.14.198.13","proto"
...
show less
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.14.198.13 (IN/India/13.198.14.34.b ...
show more(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.14.198.13 (IN/India/13.198.14.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
[SatJun1308:27:21.9262662026][security2:error][pid4071091:tid4071339][client34.14.198.13:0]ModSecuri ...
show more[SatJun1308:27:21.9262662026][security2:error][pid4071091:tid4071339][client34.14.198.13:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"edomustech.ch\"][uri\"/app/heapdump\"][unique_id\"aiz4SaHKoBDuyQ212NgAzgAAAM4\"]
show less
Hacking
Web App Attack
Anonymous
34.14.198.13 - - [13/Jun/2026:08:09:34 +0200] "GET /actuator/heapdump HTTP/1.1" 404 451 "-" "Mozilla ...
show more34.14.198.13 - - [13/Jun/2026:08:09:34 +0200] "GET /actuator/heapdump HTTP/1.1" 404 451 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.170 Safari/537.36"
34.14.198.13 - - [13/Jun/2026:08:09:34 +0200] "GET /actuator/logfile HTTP/1.1" 404 451 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3864.0 Safari/537.36"
34.14.198.13 - - [13/Jun/2026:08:09:34 +0200] "GET /actuator/env HTTP/1.1" 404 451 "-" "Mozilla/5.0 (en-us) AppleWebKit/525.13 (KHTML, like Gecko; Google Web Preview) Version/3.1 Safari/525.13"
34.14.198.13 - - [13/Jun/2026:08:09:34 +0200] "GET /actuator/dump HTTP/1.1" 404 451 "-" "Opera/10.61 (J2ME/MIDP; Opera Mini/5.1.21219/19.999; en-US; rv:1.9.3a5) WebKit/534.5 Presto/2.6.30"
34.14.198.13 - - [13/Jun/2026:08:09:34 +0200] "GET /heapdump HTTP/1.1" 404 451 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/533.17.8 (KHTML, like Gecko) Version/5.0.1 Safari/533.17.8"
...
show less
Aggressive web search of vulnerable pages: /secrets/aws.json /secrets/gcp.json /secrets/credentials. ...
show moreAggressive web search of vulnerable pages: /secrets/aws.json /secrets/gcp.json /secrets/credentials.json /secrets/azure.json /docker-compose.pr ...
show less