This IP address has been reported a total of
9
times from
8 distinct
sources.
31.134.13.198 was first reported on
December 23rd 2025 , and the most recent report was
3 hours ago .
In the last 60 days, the only reporter location was:
United States of America
with 3
reports.
Over the same time period, 31.134.13.198 has changed
country of origin 3 times.
The most common categories in these recent reports were:
Brute-Force
3
times;
Web App Attack
1
time;
Bad Web Bot
1
time;
SSH
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
2026-10-05 17:22:16
(3 hours ago)
SSH tarpit (endlessh) connection from 31.134.13.198
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-01 02:04:32
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 31.134.13.198 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 31.134.13.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:04:26.962929 2026] [security2:error] [pid 30507:tid 30507] [client 31.134.13.198:52115] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.marshdcs.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.marshdcs.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "apYyqn-DCy-88OyyaSSqawAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-20 19:37:47
(1 month ago)
VPN portal credential brute-force / password spray against a SAML-only GlobalProtect portal (2 attem ...
show more
VPN portal credential brute-force / password spray against a SAML-only GlobalProtect portal (2 attempt(s) observed, 2 username(s) tried). Source blocked on our perimeter.
show less
Brute-Force
๐ฉ๐ช
big-cloud.nl
2026-07-31 21:27:41
(2 months ago)
Try to access /xmlrpc.php
Web App Attack
Anonymous
2026-05-18 04:59:33
(4 months ago)
Rate limit bad session: 3 in 2s (Magento Site) (Botnet activity attributed to: Angara Technologies G ...
show more
Rate limit bad session: 3 in 2s (Magento Site) (Botnet activity attributed to: Angara Technologies Group / mikhail-smirnov-79830322)
show less
Hacking
๐ง๐ท
SOC PR
2026-05-11 05:20:37
(4 months ago)
IPS: WordPress HTTP Brute Force Login Attempt.
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-03-14 11:46:17
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 31.134.13.198 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 31.134.13.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 07:46:11.135130 2026] [security2:error] [pid 28809:tid 28809] [client 31.134.13.198:43411] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Himolla-ZeroStress-Recliner/Images/Sinatra/Thumbs.db"] [unique_id "abVKg3rJpz6nJBxuym24eQAAAAY"], referer: https://vitalitywebb.com/backstore/Himolla-ZeroStress-Recliner/Images/Sinatra/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-03-14 07:18:52
(6 months ago)
Bad Web Bot
๐น๐ท
pamircil
2025-12-23 12:11:05
(9 months ago)
๐ฏ WinnieThePooh Honeypot : GET request to '/wp-config.php.old' on (http/80)๐
Hacking
Brute-Force
SSH
Showing 1 to
9
of 9 reports