AbuseIPDB » 31.134.4.227
31.134.4.227 was found in our database!
This IP was reported 9 times. Confidence of
Abuse
is 16% : ?
ISP
Trade Commodity Firm Ltd
Usage Type
Data Center/Web Hosting/Transit
ASN
AS43444
Domain Name
traffictransitsolution.us
Country
๐ซ๐ฎ
Finland
City
Helsinki, Uusimaa
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 31.134.4.227 :
This IP address has been reported a total of
9
times from
7 distinct
sources.
31.134.4.227 was first reported on
November 7th 2025 , and the most recent report was
1 month ago .
Old Reports:
The most recent abuse report for this IP address is from
1 month ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐บ๐ธ
TPI-Abuse
2026-04-30 19:31:18
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 31.134.4.227 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.134.4.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 15:31:14.210012 2026] [security2:error] [pid 15897:tid 15897] [client 31.134.4.227:9783] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "satanisdead.com"] [uri "/.env"] [unique_id "afOuAvnHSyv3luIJzG2wTwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-04-29 23:28:10
(1 month ago)
[ThuApr3001:28:08.4880922026][security2:error][pid2445843:tid2445880][client31.134.4.227:0]ModSecuri ...
show more
[ThuApr3001:28:08.4880922026][security2:error][pid2445843:tid2445880][client31.134.4.227:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"spicydesign.ch\"][uri\"/.aws/credentials\"][unique_id\"afKUCAcM7qAydHkIBZ9oyQAAAUE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฆ๐ฑ
router.al
2026-04-28 17:49:17
(1 month ago)
04/28/2026-17:49:16.813578 31.134.4.227 Protocol: 6 GPL WEB_SERVER 403 Forbidden
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-27 23:22:59
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 31.134.4.227 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 31.134.4.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 19:22:52.869112 2026] [security2:error] [pid 9757:tid 9757] [client 31.134.4.227:64199] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.hamiltontruckingcompany.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.hamiltontruckingcompany.com"] [uri "/s3cmd.ini"] [unique_id "ae_vzF6aOc-D9KFCV4Zg1QAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
filstal.org
2026-04-27 12:12:26
(1 month ago)
Security scan or malicious bot activity detected by Fail2Ban
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-26 05:01:20
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 31.134.4.227 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 31.134.4.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 01:01:13.130562 2026] [security2:error] [pid 31442:tid 31442] [client 31.134.4.227:51975] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.haciendaefrain.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.haciendaefrain.com"] [uri "/s3cmd.ini"] [unique_id "ae2cGZ8eDqYzBToAOfudEAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2025-12-23 11:02:13
(5 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 31.134.4.227 (FI/Finland/-): 1 in the last 360 ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 31.134.4.227 (FI/Finland/-): 1 in the last 3600 secs (0-193)
show less
Hacking
๐จ๐ฆ
wil.com
2025-11-15 05:34:49
(6 months ago)
GlobalProtect login attempts with user moesha45.
VPN IP
Brute-Force
๐บ๐ธ
fbarela
2025-11-07 04:00:46
(6 months ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
Showing 1 to
9
of 9 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: