This IP address has been reported a total of
15
times from
13 distinct
sources.
34.141.53.156 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Triggered Cloudflare WAF (firewallManaged) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show moreTriggered Cloudflare WAF (firewallManaged) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-config.php
UA: Mozilla/5.0 (Linux; Android 9; CLT-L29 Build/HUAWEICLT-L29) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Mobile Safari/537.36 OPR/48.1.2331.132804
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
[SatJun1318:49:04.8052582026][security2:error][pid2070704:tid2070971][client34.141.53.156:0]ModSecur ...
show more[SatJun1318:49:04.8052582026][security2:error][pid2070704:tid2070971][client34.141.53.156:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"r102.ch.81-17-25-250.cpanel.site\"][uri\"/actuator/auditevents\"][unique_id\"ai2KACzxQ-SpnD4EUd4bjAAAAMw\"]
show less
{"level":"info","ts":1781356488.8316855,"logger":"http.log.access.log1","msg":"handled request","req ...
show more{"level":"info","ts":1781356488.8316855,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.141.53.156","remote_port":"39460","client_ip":"34.141.53.156","proto":"HTTP/1.1","method":"GET","host":"update.zyupdate.qporqponmlkjihgfehgc7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io","uri":"/actuator/heapdump","headers":{"Accept-Charset":["utf-8"],"Accept-Encoding":["gzip"],"Connection":["close"],"User-Agent":["Mozilla/5.0 (Linux; Android 7.1.1; BBB100-1 Build/NMF26F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.125 Mobile Safari/537.36"]}},"bytes_read":0,"user_id":"","duration":0.000060896,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://update.zyupdate.qporqponmlkjihgfehgc7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io/actuator/heapdump"],"Content-Type":[]}}
{"level":"info","ts":1781356488.838147,"logger":"http.log.access.log1","msg":"handled request","request":{"re
...
show less
[SatJun1311:42:20.0577252026][security2:error][pid927126:tid927245][client34.141.53.156:0]ModSecurit ...
show more[SatJun1311:42:20.0577252026][security2:error][pid927126:tid927245][client34.141.53.156:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"mail.dsfiduciaria.ch\"][uri\"/heapdump\"][unique_id\"ai0l_P43QvvYWeNWq6_KzQAAANA\"]
show less
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.141.53.156 (DE/Germany/156.53.141. ...
show more(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.141.53.156 (DE/Germany/156.53.141.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less