This IP address has been reported a total of
49
times from
31 distinct
sources.
34.143.200.138 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[FriAug2815:42:21.1738522026][security2:error][pid1595308:tid1595467][client34.143.200.138:0]ModSecu ...
show more[FriAug2815:42:21.1738522026][security2:error][pid1595308:tid1595467][client34.143.200.138:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"mondo-it.ch\"][uri\"/@fs/root/.env\"][unique_id\"apGQPWsPRhJoTi54YoTr6wAAAUI\"]
show less
{"level":"info","ts":1787917276.5213656,"logger":"http.log.access.log0","msg":"handled request","req ...
show more{"level":"info","ts":1787917276.5213656,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.143.200.138","remote_port":"26500","client_ip":"34.143.200.138","proto":"HTTP/1.1","method":"GET","host":"617k.status.updown.io","uri":"/","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"],"Accept":["*/*"],"Accept-Encoding":["gzip"]}},"bytes_read":0,"user_id":"","duration":0.000070205,"size":0,"status":308,"resp_headers":{"Connection":["close"],"Location":["https://617k.status.updown.io/"],"Content-Type":[],"Server":["Caddy"]}}
{"level":"info","ts":1787917282.421309,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.143.200.138","remote_port":"64630","client_ip":"34.143.200.138","proto":"HTTP/1.1","method":"GET","host":"617k.status.updown.io","uri":"/@fs/../.env?raw??","headers":{"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,*
...
show less
Scanning for config & TelegramBot User Agent Spoofing [GET /config.json.js] [Mozilla/5.0 (Macintosh; ...
show moreScanning for config & TelegramBot User Agent Spoofing [GET /config.json.js] [Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.2 Safari/605.1.15; compatible; TelegramBot/1.0]
show less
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.143.200.138 (SG/Singapore/138.200. ...
show more(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.143.200.138 (SG/Singapore/138.200.143.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
(mod_security) mod_security triggered on hostname [redacted] 34.143.200.138 (SG/Singapore/138.200.14 ...
show more(mod_security) mod_security triggered on hostname [redacted] 34.143.200.138 (SG/Singapore/138.200.143.34.bc.googleusercontent.com)
show less