This IP address has been reported a total of
150
times from
97 distinct
sources.
34.38.54.199 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.38.54.199, Reason:[ ...
show moreCluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.38.54.199, Reason:[(mod_security) mod_security (id:210730) triggered by 34.38.54.199 (BE/Belgium/199.54.38.34.bc.googleusercontent.com): 3 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
[MonSep1406:28:51.4216162026][security2:error][pid1295982:tid1295998][client34.38.54.199:0]ModSecuri ...
show more[MonSep1406:28:51.4216162026][security2:error][pid1295982:tid1295998][client34.38.54.199:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\b\(\?:\\\\\\\\.\(\?:ht\(\?:access\|passwd\|group\)\|www_\?acl\)\|global\\\\\\\\.asa\|httpd\\\\\\\\.conf\|boot\\\\\\\\.ini\|web.config\)\\\\\\\\b\|\(\|\^\|\\\\\\\\.\\\\\\\\.\)/etc/\|/\\\\\\\\.\(\?:history\|bash_history\|sh_history\|env\)\$\)\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"204\"][id\"390709\"][rev\"30\"][msg\"Atomicorp.comWAFRules:Attempttoaccessprotectedfileremotely\"][data\"/.env\"][severity\"CRITICAL\"][hostname\"eselectronic.ch\"][uri\"/@fs/app/.env\"][unique_id\"aqd4A3QLN9chw5M5EfTzdQAAAUQ\"]
show less
(mod_security) mod_security triggered on hostname [redacted] 34.38.54.199 (BE/Belgium/199.54.38.34.b ...
show more(mod_security) mod_security triggered on hostname [redacted] 34.38.54.199 (BE/Belgium/199.54.38.34.bc.googleusercontent.com)
show less
{"level":"info","ts":1789316373.442616,"logger":"http.log.access.log0","msg":"handled request","requ ...
show more{"level":"info","ts":1789316373.442616,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.38.54.199","remote_port":"57420","client_ip":"34.38.54.199","proto":"HTTP/1.1","method":"GET","host":"mo6m.status.updown.io","uri":"/","headers":{"Accept-Encoding":["gzip"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:127.0) Gecko/20100101 Firefox/127.0"],"Accept":["*/*"]}},"bytes_read":0,"user_id":"","duration":0.000088689,"size":0,"status":308,"resp_headers":{"Connection":["close"],"Location":["https://mo6m.status.updown.io/"],"Content-Type":[],"Server":["Caddy"]}}
{"level":"info","ts":1789316373.7988691,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.38.54.199","remote_port":"31018","client_ip":"34.38.54.199","proto":"HTTP/1.1","method":"GET","host":"mo6m.status.updown.io","uri":"/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw??","headers":{"Accept-Encoding":["gzip"],"User-Agent":["Mozilla/5.0 (Linux
...
show less
DDoS Attack
Web App Attack
Showing 1 to
15
of 150 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ