This IP address has been reported a total of
29
times from
23 distinct
sources.
34.128.96.44 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Attempting to probe for sensitive information accidently exposed via git config.
34.128.96.44 - - [ ...
show moreAttempting to probe for sensitive information accidently exposed via git config.
34.128.96.44 - - [29/Sep/2026:13:42:57 +0000] "GET /.git/config HTTP/1.1" 403 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
[MonSep2811:55:15.6397972026][security2:error][pid691772:tid691819][client34.128.96.44:0]ModSecurity ...
show more[MonSep2811:55:15.6397972026][security2:error][pid691772:tid691819][client34.128.96.44:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"www.wp.aaaa6877.org\"][uri\"/\"][unique_id\"aro5gwDipxLuV-FRULYtWwAAAEA\"]
show less
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show moreThis address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.env (+4 more) | 2026-09-26 10:15 UTC
show less
250 attacks on VC URLs, env grabbing URLs, PHP URLs:
GET /.git/config HTTP/1.1
GET /config/app/.env ...
show more250 attacks on VC URLs, env grabbing URLs, PHP URLs:
GET /.git/config HTTP/1.1
GET /config/app/.env HTTP/1.1
GET /includes/phpinfo.php HTTP/1.1
show less
(mod_security) mod_security triggered on hostname [redacted] 34.128.96.44 (ID/Indonesia/44.96.128.34 ...
show more(mod_security) mod_security triggered on hostname [redacted] 34.128.96.44 (ID/Indonesia/44.96.128.34.bc.googleusercontent.com)
show less
(mod_security) mod_security triggered on hostname [redacted] 34.128.96.44 (ID/Indonesia/Jakarta/Jaka ...
show more(mod_security) mod_security triggered on hostname [redacted] 34.128.96.44 (ID/Indonesia/Jakarta/Jakarta/44.96.128.34.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
[da.kdns.gr] httpd-config-scan: sites=www.webfly.gr; logs=/var/log/httpd/domains/webfly.gr.log; samp ...
show more[da.kdns.gr] httpd-config-scan: sites=www.webfly.gr; logs=/var/log/httpd/domains/webfly.gr.log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
Showing 1 to
15
of 29 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ