This IP address has been reported a total of
39
times from
30 distinct
sources.
34.152.53.215 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 10
reports;
Germany
with 8
reports;
France
with 6
reports.
The most common categories in these recent reports were:
Web App Attack
31
times;
Bad Web Bot
16
times;
Brute-Force
16
times;
Hacking
6
times;
Port Scan
2
times;
Other
2
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
{"ClientAddr":"34.152.53.215:48782","ClientHost":"34.152.53.215","ClientPort":"48782","ClientUsernam ...
show more{"ClientAddr":"34.152.53.215:48782","ClientHost":"34.152.53.215","ClientPort":"48782","ClientUsername":"-","DownstreamContentSize":1488,"DownstreamStatus":404,"Duration":71743601,"OriginContentSize":1488,"OriginDuration":71611692,"OriginStatus":404,"Overhead":131909,"RequestAddr":"vdkln.com","RequestContentSize":0,"RequestCount":2342,"RequestHost":"vdkln.com","RequestMethod":"GET","RequestPath":"/userfiles?path=../../.env","RequestPort":"-","RequestProtocol":"HTTP/2.0","RequestScheme":"https","RetryAttempts":0,"RouterName":"vdkln-shlink-shortlinks@file","ServiceAddr":"shlink:8080","ServiceName":"shlink-svc@file","ServiceURL":"http://shlink:8080","StartLocal":"2026-10-06T21:21:10.627331392Z","StartUTC":"2026-10-06T21:21:10.627331392Z","TLSCipher":"TLS_AES_128_GCM_SHA256","TLSVersion":"1.3","entryPointName":"websecure","level":"info","msg":"","time":"2026-10-06T21:21:10Z"}
{"ClientAddr":"34.152.53.215:48782","ClientHost":"34.152.53.215","ClientPort":"48782","ClientUsername":"-","Downstre
...
show less
path traversal and probing for exposed files and admin pages: 42 attempts within 1 minutes, seen by ...
show morepath traversal and probing for exposed files and admin pages: 42 attempts within 1 minutes, seen by web server log, WAF, fail2ban and CrowdSec (reported by RemotePower)
show less
WordPress attack on tuncayozkan.com (auto-detected): tur=imza ulke=CA puan=100 nginx=14 wf=7 cf=3 hi ...
show moreWordPress attack on tuncayozkan.com (auto-detected): tur=imza ulke=CA puan=100 nginx=14 wf=7 cf=3 hiz=122 404cesit=108. Blocked by adaptive firewall.
show less
Web App Attack
Bad Web Bot
Anonymous
Bot / scanning and/or hacking attempts: POST /functionRouter HTTP/2.0, POST /read-document HTTP/2.0, ...
show moreBot / scanning and/or hacking attempts: POST /functionRouter HTTP/2.0, POST /read-document HTTP/2.0, POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%, POST /api/v1/node-load-method/customMCP HTTP/2.0, POST /api/v1/validate/code HTTP/2.0, POST /php-cgi/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_, [331/331] read: stream 0, , POST /flowise/api/v1/node-load-method/customMCP HTTP/2.0, POST /api/templates/preview HTTP/2.0, POST /exec-py HTTP/2.0, GET /@fs/var/run/secrets/kubernetes.io/serviceaccount/ca.crt?ra, POST /cgi-bin/php?-d+allow_url_include%3don+-d+auto_prepend_fil, POST /api/fs/exec HTTP/2.0, POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_, POST /api/v1/build_public_tmp/00000000-0000-0000-0000-000000000, POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_, POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e
show less
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show moreHTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000 ...
show moreBAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000-196)
show less
(mod_security) mod_security triggered on hostname [redacted] 34.152.53.215 (CA/Canada/215.53.152.34. ...
show more(mod_security) mod_security triggered on hostname [redacted] 34.152.53.215 (CA/Canada/215.53.152.34.bc.googleusercontent.com)
show less