This IP address has been reported a total of
18
times from
15 distinct
sources.
34.89.43.138 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
ModSecurity OWASP CRS (Anomaly Score: 50): JavaScript Prototype Pollution;JSON-Based SQL Injection;N ...
show moreModSecurity OWASP CRS (Anomaly Score: 50): JavaScript Prototype Pollution;JSON-Based SQL Injection;Node.js Injection Attack 1/2;PHP Injection Attack: Variable Access Found;Remote Command Execution: Direct Unix Command Execution;Remote Command Execution: Unix Shell Expression Found;Restricted File Access Attempt;SQL Injection Attack: SQL function name detected;URL file extension is restricted by policy;
show less
Web App Attack
Anonymous
{"reqId":"DDWhwblAlnqniLFO7T4M","level":1,"time":"2026-09-17T06:01:13+02:00","remoteAddr":"34.89.43. ...
show more{"reqId":"DDWhwblAlnqniLFO7T4M","level":1,"time":"2026-09-17T06:01:13+02:00","remoteAddr":"34.89.43.138","user":"--","app":"core","method":"GET","url":"/","scriptName":"/index.php","message":"Trusted domain error. \"34.89.43.138\" tried to access using \"vega.khomri.com\" as host.","userAgent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36","version":"34.0.4.1","data":{"app":"core"}}
{"reqId":"MNM9I7XPp40jVOCQ1946","level":1,"time":"2026-09-17T06:01:13+02:00","remoteAddr":"34.89.43.138","user":"--","app":"core","method":"POST","url":"/","scriptName":"/index.php","message":"Trusted domain error. \"34.89.43.138\" tried to access using \"vega.khomri.com\" as host.","userAgent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36","version":"34.0.4.1","data":{"app":"core"}}
{"reqId":"1gTQvqgg72bPu5rZWhTT","level":1,"time":"2026-09-17T06:01:13+02:00","rem
...
show less
malicious bot detected: violations="hit-honeypot"; user_agent="Mozilla/5.0 (X11; Linux x86_64) Apple ...
show moremalicious bot detected: violations="hit-honeypot"; user_agent="Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
(modsecurity) srv103 ModSecurity 34.89.43.138 (138.43.89.34.bc.googleusercontent.com): 30 in the las ...
show more(modsecurity) srv103 ModSecurity 34.89.43.138 (138.43.89.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show moreProbing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-09-17 02:24 UTC
show less
[live3bd] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more[live3bd] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.89.43.138 - - [17/Sep/2026:04:20:30 +0200] "GET /.git/config HTTP/1.1" 404 2105 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less