This IP address has been reported a total of
22
times from
19 distinct
sources.
34.59.130.151 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
11.144 requests with url.path //xmlrpc.php
10.830 requests with url.path */xmlrpc.php
7.621 reque ...
show more11.144 requests with url.path //xmlrpc.php
10.830 requests with url.path */xmlrpc.php
7.621 requests with url.path */wp-includes/wlwmanifest.xml
show less
{"ClientAddr":"172.70.100.37:9937","ClientHost":"34.59.130.151","ClientPort":"9937","ClientUsername" ...
show more{"ClientAddr":"172.70.100.37:9937","ClientHost":"34.59.130.151","ClientPort":"9937","ClientUsername":"-","DownstreamContentSize":0,"DownstreamStatus":429,"Duration":411599,"OriginContentSize":0,"OriginDuration":0,"OriginStatus":0,"Overhead":411599,"RequestAddr":"timvdberg.dev","RequestContentSize":0,"RequestCount":186670,"RequestHost":"timvdberg.dev","RequestMethod":"GET","RequestPath":"/blog/wp-includes/wlwmanifest.xml","RequestPort":"-","RequestProtocol":"HTTP/2.0","RequestScheme":"https","RetryAttempts":0,"RouterName":"https-0-omari8kj3ono91z1qv5lbj10-coraza-www@docker","StartLocal":"2026-08-24T11:05:58.229898706Z","StartUTC":"2026-08-24T11:05:58.229898706Z","TLSCipher":"TLS_AES_128_GCM_SHA256","TLSVersion":"1.3","entryPointName":"https","level":"info","msg":"","request_Cf-Connecting-Ip":"34.59.130.151","request_X-Forwarded-For":"34.59.130.151","request_X-Real-Ip":"172.70.100.37","time":"2026-08-24T11:05:58Z"}
{"ClientAddr":"172.70.100.37:9937","ClientHost":"34.59.130.151","ClientPo
...
show less
http-probing - IP: 34.59.130.151 - time="2026-08-24T13:01:03+02:00" level=info msg="(555f66b4f6a745 ...
show morehttp-probing - IP: 34.59.130.151 - time="2026-08-24T13:01:03+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-probing by ip 34.59.130.151 (US/396982) : 4h ban on Ip 34.59.130.151" module=db
show less
Web application attack / vulnerability scanning against our public nginx web server (TCP 80/443). So ...
show moreWeb application attack / vulnerability scanning against our public nginx web server (TCP 80/443). Source matched a blocked-path security rule (jail nginx-444); server returned HTTP 444 (connection closed without response). TCP three-way handshake completed (full HTTP request received).
show less
[24/Aug/2026:13:50:48 +0300] -- 34.59.130.151 Ban reason: Scanner [CMS_GENERIC] | Request: GET //wp- ...
show more[24/Aug/2026:13:50:48 +0300] -- 34.59.130.151 Ban reason: Scanner [CMS_GENERIC] | Request: GET //wp-includes/ID3/license.txt HTTP/1.1
show less