This IP address has been reported a total of
9
times from
9 distinct
sources.
34.154.160.52 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
http-crawl-non_statics - IP: 34.154.160.52 - time="2026-06-15T06:12:12+02:00" level=info msg="(555f ...
show morehttp-crawl-non_statics - IP: 34.154.160.52 - time="2026-06-15T06:12:12+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-crawl-non_statics by ip 34.154.160.52 (IT/396982) : 4h ban on Ip 34.154.160.52" module=db
show less
[MonJun1500:40:24.6331512026][security2:error][pid3338868:tid3338888][client34.154.160.52:0]ModSecur ...
show more[MonJun1500:40:24.6331512026][security2:error][pid3338868:tid3338888][client34.154.160.52:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.distributori-automatici-sigarette-ticino.ch.136-243-54-122.cpanel.site\"][uri\"/dump\"][unique_id\"ai8t2J3wLQBVKk8VEJlJHQAAARA\"]
show less
{"level":"info","ts":1781405236.1297607,"logger":"http.log.access.log1","msg":"handled request","req ...
show more{"level":"info","ts":1781405236.1297607,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.154.160.52","remote_port":"42662","client_ip":"34.154.160.52","proto":"HTTP/1.1","method":"GET","host":"status.mnorman.net","uri":"/heapdump","headers":{"User-Agent":["Mozilla/5.0 (iPhone; CPU iPhone OS 10_3_3 like Mac OS X) AppleWebKit/603.3.8 (KHTML, like Gecko) Mobile/14G60 MicroMessenger/7.0.5(0x17000523) NetType/4G Language/zh_CN"],"Accept-Charset":["utf-8"],"Accept-Encoding":["gzip"],"Connection":["close"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"status.mnorman.net","ech":false}},"bytes_read":0,"user_id":"","duration":0.000127475,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1781405236.1758323,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.154.160.52","remote_port":"42664","client_ip":"34.15
...
show less
{"reqId":"eV7rg50RHi8lS7jGTvPF","level":1,"time":"2026-06-13T21:53:24+00:00","remoteAddr":"34.154.16 ...
show more{"reqId":"eV7rg50RHi8lS7jGTvPF","level":1,"time":"2026-06-13T21:53:24+00:00","remoteAddr":"34.154.160.52","user":"--","app":"core","method":"GET","url":"/actuator/heapdump","scriptName":"/index.php","message":"Trusted domain error. \"34.154.160.52\" tried to access using \"mail.novoclon.com\" as host.","userAgent":"Mozilla/5.0 (Windows NT 6.2; WOW64; rv:39.0) Gecko/20100101 Firefox/39.0","version":"32.0.6.1","data":{"app":"core"}}
{"reqId":"pfnKSu6Fucq8Ud2cQLXs","level":1,"time":"2026-06-13T21:53:24+00:00","remoteAddr":"34.154.160.52","user":"--","app":"core","method":"GET","url":"/actuator/configprops","scriptName":"/index.php","message":"Trusted domain error. \"34.154.160.52\" tried to access using \"mail.novoclon.com\" as host.","userAgent":"Mozilla/5.0 (Linux; Android 9; Pixel 3a) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36","version":"32.0.6.1","data":{"app":"core"}}
{"reqId":"ObznPe1WEzEix9IJ726r","level":1,"time":"2026-06-13T21:53:24+00:00","
...
show less
Brute-Force
Web App Attack
Showing 1 to
9
of 9 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ