Log in to view charts and search reports for this IP.
Log In
Top Reporter Countries (Last 60 Days)
Example preview
Report Categories (Last 60 Days)
Example preview
Reports Activity
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 34.45.248.203:
This IP address has been reported a total of
11
times from
11 distinct
sources.
34.45.248.203 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 3
reports;
Netherlands
with 3
reports;
United States of America
with 2
reports.
The most common categories in these recent reports were:
Web App Attack
8
times;
Brute-Force
5
times;
Bad Web Bot
2
times;
Hacking
2
times;
SQL Injection
2
times;
Other
2
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-30.
show less
(mod_security) mod_security triggered on hostname [redacted] 34.45.248.203 (US/United States/203.248 ...
show more(mod_security) mod_security triggered on hostname [redacted] 34.45.248.203 (US/United States/203.248.45.34.bc.googleusercontent.com)
show less
(mod_security) mod_security triggered on hostname [redacted] 34.45.248.203 (US/United States/203.248 ...
show more(mod_security) mod_security triggered on hostname [redacted] 34.45.248.203 (US/United States/203.248.45.34.bc.googleusercontent.com): (CF_ENABLE)
show less
IP address: 34.45.248.203; Blocked requests: 260;
Operating System: Linux (Shodan), Open port: 22 ( ...
show moreIP address: 34.45.248.203; Blocked requests: 260;
Operating System: Linux (Shodan), Open port: 22 (SSH),
Tags: cloud; Date: 2026-08-29; UTC Time: 18:47:44; Description: High-speed automated scanning/fuzzing attack against the web application, generating 260 malicious HTTP GET/POST requests within a span of just 21 seconds; Attack vectors:
* Credential & Cloud Key Harvesting: Active search for GCP service keys and credentials within .json and .env files in development/infrastructure directories.
* Information Disclosure / Diagnostic Probing: Fuzzing of over 20 paths containing diagnostic scripts (/phpinfo.php, /_profiler/phpinfo, /pinfo.php, /debug.php).
* Source Code Exposure (Git Leakage): Attempted arbitrary reading of version control configuration files (/.git/config).
* Path & Subdirectory Fuzzing: Probing of administrative routes, test environments, and microservices (/administrator/, /uat/, /microservice/, /gateway/, /webmail/).
show less
[SatAug2915:58:24.1632162026][security2:error][pid4159543:tid4159651][client34.45.248.203:0]ModSecur ...
show more[SatAug2915:58:24.1632162026][security2:error][pid4159543:tid4159651][client34.45.248.203:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"gmint.ch\"][uri\"/.git/config\"][unique_id\"apLlgL7ORc8vgg0P5B7H4wAAARY\"]
show less
Port Scan
Brute-Force
Web App Attack
Showing 1 to
11
of 11 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown 🚩