This IP address has been reported a total of
16
times from
15 distinct
sources.
34.19.254.252 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
Multiple web server 400 error codes from same source ip
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: CHALLENGE
Protocol: HTTP/1.1 (GET m ...
show moreTriggered Cloudflare WAF (firewallCustom) from CA.
Action taken: CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /sendgrid/.env.backup
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3866.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bot / scanning and/or hacking attempts: GET /app/.env.dev HTTP/1.1, GET /app/.env.local HTTP/1.1, GE ...
show moreBot / scanning and/or hacking attempts: GET /app/.env.dev HTTP/1.1, GET /app/.env.local HTTP/1.1, GET /app/sendgrid.env HTTP/1.1, GET /.env.sample HTTP/1.1, GET /server/.env HTTP/1.1, GET /.env.txt HTTP/1.1, GET /.env.dev.local HTTP/1.1, GET /.env.testing HTTP/1.1, GET /.env.docker HTTP/1.1, GET /config/sendgrid.env HTTP/1.1, GET /.env.production HTTP/1.1, GET /env HTTP/1.1, GET /backend/.env.prod HTTP/1.1, GET /deploy/.env HTTP/1.1, GET /wp/.env HTTP/1.1, GET /dev/.env HTTP/1.1, GET /app/.env.old HTTP/1.1, GET /.env.development.local HTTP/1.1, GET /services/api/.env HTTP/1.1, GET /development/.env HTTP/1.1, GET /admin/api/.env HTTP/1.1, GET /.env HTTP/1.1, GET /app/.env.backup HTTP/1.1, GET /api/.env.dev HTTP/1.1, GET /sendgrid/.env.production HTTP/1.1, GET /src/.env.production HTTP/1.1
show less
Http Port:80 (http_status:404) - Agent:Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/5 ...
show moreHttp Port:80 (http_status:404) - Agent:Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.75 Safari/537.36
show less
Aggressive web search of vulnerable pages: /test/.env /.env /backend/.env /backend/api/.env /fronten ...
show moreAggressive web search of vulnerable pages: /test/.env /.env /backend/.env /backend/api/.env /frontend/.env ...
show less
{"level":"info","ts":1781413572.7731605,"logger":"http.log.access.log1","msg":"handled request","req ...
show more{"level":"info","ts":1781413572.7731605,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.19.254.252","remote_port":"33454","client_ip":"34.19.254.252","proto":"HTTP/1.1","method":"GET","host":"status.box0.he2.eric.si","uri":"/.env.bak","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 6.1; WOW64; rv:41.0) Gecko/20100101 Firefox/41.0"],"Accept-Charset":["utf-8"],"Accept-Encoding":["gzip"],"Connection":["close"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"status.box0.he2.eric.si","ech":false}},"bytes_read":0,"user_id":"","duration":0.000115811,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1781413572.775529,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.19.254.252","remote_port":"33426","client_ip":"34.19.254.252","proto":"HTTP/1.1","method":"GET","host":"status.box0.he2.eric.si","uri":"/.e
...
show less