This IP address has been reported a total of
58
times from
25 distinct
sources.
57.131.131.17 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[MonAug1702:00:21.1606752026][security2:error][pid519562:tid519566][client57.131.131.17:0]ModSecurit ...
show more[MonAug1702:00:21.1606752026][security2:error][pid519562:tid519566][client57.131.131.17:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"serversvizzera.ch\"][uri\"/\"][unique_id\"aoJPFVIS9Q6X0LPrqbXBQQAAAIA\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
Reported from Nginx log analysis 19. Log: 57.131.131.17 - - [16/Aug/2026:xx:xx:xx 0200] "GET / HTTP ...
show moreReported from Nginx log analysis 19. Log: 57.131.131.17 - - [16/Aug/2026:xx:xx:xx 0200] "GET / HTTP/1.1" xxx xxx "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 26_5_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/151.0.7922.57 Mobile/15E148 Safari/604.1" "-" "FR France -" "AS16276" "OVH SAS"
show less
{"ClientAddr":"172.71.148.10:11790","ClientHost":"57.131.131.17","ClientPort":"11790","ClientUsernam ...
show more{"ClientAddr":"172.71.148.10:11790","ClientHost":"57.131.131.17","ClientPort":"11790","ClientUsername":"-","DownstreamContentSize":114,"DownstreamStatus":401,"Duration":17709764,"GzipRatio":0,"OriginContentSize":0,"OriginDuration":0,"OriginStatus":0,"Overhead":17709764,"RequestAddr":"phpmyadmin.timvdberg.dev","RequestContentSize":0,"RequestCount":65078,"RequestHost":"phpmyadmin.timvdberg.dev","RequestMethod":"GET","RequestPath":"/","RequestPort":"-","RequestProtocol":"HTTP/2.0","RequestScheme":"https","RetryAttempts":0,"RouterName":"https-0-g781j1l22qyid4grmjq8a0lf-phpmyadmin@docker","StartLocal":"2026-08-14T22:07:40.224082826Z","StartUTC":"2026-08-14T22:07:40.224082826Z","TLSCipher":"TLS_AES_128_GCM_SHA256","TLSVersion":"1.3","entryPointName":"https","level":"info","msg":"","request_Cf-Connecting-Ip":"57.131.131.17","request_X-Forwarded-For":"57.131.131.17","request_X-Real-Ip":"172.71.148.10","time":"2026-08-14T22:07:40Z"}
...
show less
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show moreBlocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /. User-Agent: Mozilla/5.0 (iPhone; CPU iPhone OS 18_7 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.7.5 Mobile/15E148 Safari/604.1
show less
{"ClientAddr":"104.23.239.64:9316","ClientHost":"57.131.131.17","ClientPort":"9316","ClientUsername" ...
show more{"ClientAddr":"104.23.239.64:9316","ClientHost":"57.131.131.17","ClientPort":"9316","ClientUsername":"-","DownstreamContentSize":109,"DownstreamStatus":401,"Duration":18642254,"GzipRatio":0,"OriginContentSize":0,"OriginDuration":0,"OriginStatus":0,"Overhead":18642254,"RequestAddr":"films.timvdberg.dev","RequestContentSize":0,"RequestCount":46008,"RequestHost":"films.timvdberg.dev","RequestMethod":"GET","RequestPath":"/","RequestPort":"-","RequestProtocol":"HTTP/2.0","RequestScheme":"https","RetryAttempts":0,"RouterName":"films@file","StartLocal":"2026-08-12T22:25:08.439624638Z","StartUTC":"2026-08-12T22:25:08.439624638Z","TLSCipher":"TLS_AES_128_GCM_SHA256","TLSVersion":"1.3","entryPointName":"https","level":"info","msg":"","request_Cf-Connecting-Ip":"57.131.131.17","request_X-Forwarded-For":"57.131.131.17","request_X-Real-Ip":"104.23.239.64","time":"2026-08-12T22:25:08Z"}
{"ClientAddr":"172.71.172.235:9641","ClientHost":"57.131.131.17","ClientPort":"9641","ClientUsername":"-","Downstr
...
show less
[WedAug1200:19:00.3006572026][security2:error][pid2460003:tid2460013][client57.131.131.17:0]ModSecur ...
show more[WedAug1200:19:00.3006572026][security2:error][pid2460003:tid2460013][client57.131.131.17:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"robertselitrenny.ch\"][uri\"/\"][unique_id\"anuf1PKR1Kmt159qrxS7PwAAAAY\"]
show less
Port Scan
Brute-Force
Web App Attack
Showing 1 to
15
of 58 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ