This IP address has been reported a total of
44
times from
31 distinct
sources.
34.41.109.233 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Word ...
show moreBlocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
time="2026-09-18T13:47:46Z" level=info msg="Access to https://portainer.sw0ok.dev/ (method GET) is n ...
show moretime="2026-09-18T13:47:46Z" level=info msg="Access to https://portainer.sw0ok.dev/ (method GET) is not authorized to user <anonymous>, responding with status code 302 with location redirect to https://auth.sw0ok.dev/?rd=https%3A%2F%2Fportainer.sw0ok.dev%2F&rm=GET" method=GET path=/api/authz/forward-auth remote_ip=34.41.109.233
time="2026-09-18T13:47:46Z" level=info msg="Access to https://portainer.sw0ok.dev/ (method POST) is not authorized to user <anonymous>, responding with status code 303 with location redirect to https://auth.sw0ok.dev/?rd=https%3A%2F%2Fportainer.sw0ok.dev%2F&rm=POST" method=GET path=/api/authz/forward-auth remote_ip=34.41.109.233
time="2026-09-18T13:47:46Z" level=info msg="Access to https://portainer.sw0ok.dev/ (method POST) is not authorized to user <anonymous>, responding with status code 303 with location redirect to https://auth.sw0ok.dev/?rd=https%3A%2F%2Fportainer.sw0ok.dev%2F&rm=POST" method=GET path=/api/authz/forward-auth remote_ip=34.41.109.233
time="202
...
show less
Probed planted web canary URI (not a real app path).
HTTP request completed against planted URIs (.e ...
show moreProbed planted web canary URI (not a real app path).
HTTP request completed against planted URIs (.env/wp-login/xmlrpc/phpmyadmin/.git).
jail=nginx-canary proto=tcp port=80,443 failures>=2 class=web-app-probe
these paths are not real apps on this host; hit is hostile recon
when=2026-09-18T13:40:07Z sensor=fail2ban role=web-canary
src=34.41.109.233
show less
time="2026-09-18T12:16:47Z" level=info msg="Access to https://portainer.sw0ok.dev/ (method GET) is n ...
show moretime="2026-09-18T12:16:47Z" level=info msg="Access to https://portainer.sw0ok.dev/ (method GET) is not authorized to user <anonymous>, responding with status code 302 with location redirect to https://auth.sw0ok.dev/?rd=https%3A%2F%2Fportainer.sw0ok.dev%2F&rm=GET" method=GET path=/api/authz/forward-auth remote_ip=34.41.109.233
time="2026-09-18T12:16:47Z" level=info msg="Access to https://portainer.sw0ok.dev/ (method POST) is not authorized to user <anonymous>, responding with status code 303 with location redirect to https://auth.sw0ok.dev/?rd=https%3A%2F%2Fportainer.sw0ok.dev%2F&rm=POST" method=GET path=/api/authz/forward-auth remote_ip=34.41.109.233
time="2026-09-18T12:16:47Z" level=info msg="Access to https://portainer.sw0ok.dev/ (method POST) is not authorized to user <anonymous>, responding with status code 303 with location redirect to https://auth.sw0ok.dev/?rd=https%3A%2F%2Fportainer.sw0ok.dev%2F&rm=POST" method=GET path=/api/authz/forward-auth remote_ip=34.41.109.233
time="202
...
show less
Sensitive file and configuration probing detected against a public web server.
84 suspicious reques ...
show moreSensitive file and configuration probing detected against a public web server.
84 suspicious requests
84 critical requests
Observed requests:
GET /web/.env
GET /site/.env
GET /server/.env
GET /public/.env
Risk level: CRITICAL
Reference: STI-20260918-113910-34-41-109-233
show less