This IP address has been reported a total of
36
times from
30 distinct
sources.
34.32.147.43 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 10
reports;
United States of America
with 10
reports;
Netherlands
with 5
reports.
The most common categories in these recent reports were:
Web App Attack
27
times;
Bad Web Bot
13
times;
Brute-Force
12
times;
Hacking
8
times;
Port Scan
4
times;
Other
6
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-10-01.
show less
{"level":"info","ts":1790866473.5693626,"logger":"http.log.access.log1","msg":"handled request","req ...
show more{"level":"info","ts":1790866473.5693626,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.32.147.43","remote_port":"59418","client_ip":"34.32.147.43","proto":"HTTP/2.0","method":"GET","host":"status.newmedia.com","uri":"/model/info","headers":{"User-Agent":["DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"],"Accept":["*/*"],"Authorization":["REDACTED"],"Accept-Encoding":["gzip"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.newmedia.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000310733,"size":0,"status":429,"resp_headers":{"Retry-After":["1"],"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"]}}
{"level":"info","ts":1790866473.573164,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.32.147.43","remote_port":"59418","client_ip":"34.32.147.43","proto":"HTTP/2.0","method":"GET","host":"status.newmedia.com","uri":"/z9x8c7v6b5-debug-trigger-status.ne
...
show less
(mod_security) mod_security (id:210730) triggered by 34.32.147.43 (43.147.32.34.bc.googleusercontent ...
show more(mod_security) mod_security (id:210730) triggered by 34.32.147.43 (43.147.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:58:43.492565 2026] [security2:error] [pid 15202:tid 15202] [client 34.32.147.43:39060] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||backyardbrickoven.windisfun.com|F|2"] [data ".windisfun.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "backyardbrickoven.windisfun.com"] [uri "/z9x8c7v6b5-debug-trigger-backyardbrickoven.windisfun.com"] [unique_id "ar5K85qENcGws9lNoGNw9AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
Bot / scanning and/or hacking attempts: POST /api/v1/build_public_tmp/00000000-0000-0000-0000-000000 ...
show moreBot / scanning and/or hacking attempts: POST /api/v1/build_public_tmp/00000000-0000-0000-0000-000000000, POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend, POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e, POST /exec-py HTTP/2.0, POST /php-cgi/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_, POST /flowise/api/v1/node-load-method/customMCP HTTP/2.0, POST /api/designer/v1/file-content HTTP/2.0, POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_, POST /api/fs/exec HTTP/2.0, POST /api/v1/node-load-method/customMCP HTTP/2.0
show less
Automated ban via infra-monitor: mgmt-path-probe, suspicious-probe, webshell-high-confidence, +6 mor ...
show moreAutomated ban via infra-monitor: mgmt-path-probe, suspicious-probe, webshell-high-confidence, +6 more
show less