This IP address has been reported a total of
38
times from
30 distinct
sources.
34.86.61.216 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
34.86.61.216 - - [12/Jun/2026:01:18:09 +0200] "GET /.aws/credentials HTTP/1.1" 404 152876 "-" "Mozil ...
show more34.86.61.216 - - [12/Jun/2026:01:18:09 +0200] "GET /.aws/credentials HTTP/1.1" 404 152876 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.79 Safari/537.36"
...
show less
156 requests with url.path *credentials.json
156 requests with url.path *config.json
105 requests ...
show more156 requests with url.path *credentials.json
156 requests with url.path *config.json
105 requests with url.path *compose.yml
104 requests with url.path *secrets.json
103 requests with url.path *config.yml
show less
Bot / scanning and/or hacking attempts: GET /.htaccess HTTP/1.1, GET /web.config HTTP/1.1, GET /.bas ...
show moreBot / scanning and/or hacking attempts: GET /.htaccess HTTP/1.1, GET /web.config HTTP/1.1, GET /.bash_history HTTP/1.1, GET /log/error.log HTTP/1.1, GET /.github/workflows/main.yml HTTP/1.1, GET /.github/workflows/production.yml HTTP/1.1, GET /.github/workflows/ci.yml HTTP/1.1, GET /logs/error.log HTTP/1.1, GET /v1/config.json HTTP/1.1, GET /wp-config.php HTTP/1.1, GET /.idea/WebServers.xml HTTP/1.1, GET /.vscode/sftp.json HTTP/1.1, GET /.vscode/settings.json HTTP/1.1, GET /.vscode/launch.json HTTP/1.1, GET /.vscode/tasks.json HTTP/1.1, GET /.gitlab-ci.yml HTTP/1.1, GET /jenkins/Jenkinsfile HTTP/1.1, GET /services/application.yml HTTP/1.1, GET /private/credentials.json HTTP/1.1, GET /logs/debug.log HTTP/1.1, GET /server.key HTTP/1.1, GET /server.pem HTTP/1.1, GET /.travis.yml HTTP/1.1, GET /access.log HTTP/1.1
show less
{"level":"info","ts":1781184193.2535298,"logger":"http.log.access.log1","msg":"handled request","req ...
show more{"level":"info","ts":1781184193.2535298,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.86.61.216","remote_port":"52532","client_ip":"34.86.61.216","proto":"HTTP/1.1","method":"GET","host":"uupdate.mlkjihwww.cbedgc7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io","uri":"/actuator/env","headers":{"User-Agent":["Mozilla/5.0 (MSIE 9.0; Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.79 Safari/537.36 Edge/14.14931"],"Accept-Charset":["utf-8"],"Accept-Encoding":["gzip"],"Connection":["close"]}},"bytes_read":0,"user_id":"","duration":0.000055226,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://uupdate.mlkjihwww.cbedgc7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io/actuator/env"],"Content-Type":[]}}
{"level":"info","ts":1781184193.2581725,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.86.61.216","remote_por
...
show less
*Port Scan* detected from 34.86.61.216 (US/United States/District of Columbia/Washington/216.61.86.3 ...
show more*Port Scan* detected from 34.86.61.216 (US/United States/District of Columbia/Washington/216.61.86.34.bc.googleusercontent.com).
show less
Web application attack / vulnerability scanning against our public nginx web server (TCP 80/443). So ...
show moreWeb application attack / vulnerability scanning against our public nginx web server (TCP 80/443). Source matched a blocked-path security rule (jail nginx-444); server returned HTTP 444 (connection closed without response). TCP three-way handshake completed (full HTTP request received).
show less
Auto-ban: 376 malicious requests on 2026-06-09 (e.g., env/backup probes, brute-force, or error burst ...
show moreAuto-ban: 376 malicious requests on 2026-06-09 (e.g., env/backup probes, brute-force, or error bursts).
show less