This IP address has been reported a total of
19
times from
18 distinct
sources.
34.139.218.241 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Germany
with 3
reports;
United States of America
with 3
reports;
Italy
with 2
reports.
The most common categories in these recent reports were:
Web App Attack
14
times;
Brute-Force
5
times;
Hacking
4
times;
Port Scan
3
times;
Bad Web Bot
2
times;
Other
3
times.
Old Reports
The most recent abuse report for this IP address is from
. It is possible that this IP is no
longer involved in abusive activities.
ban-reviewer auto report; ip=34.139.218.241; scenario=custom/kgateway-auth-client-error-burst; verdi ...
show moreban-reviewer auto report; ip=34.139.218.241; scenario=custom/kgateway-auth-client-error-burst; verdict=valid_ban; confidence=0.92; categories=15; active_decisions=4; lookback_decisions=4; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=ip_decision_count_high; ip_active_decision_count_high
show less
Web-app scanner probing a public web service with a Next.js middleware authorization-bypass exploit ...
show moreWeb-app scanner probing a public web service with a Next.js middleware authorization-bypass exploit attempt plus credential/file-recon HTTP requests in a tight window; firewall closed the requests (444) and blocked port 8080.
Target: HTTP 80/443/8080 on a public web service, incl. a Next.js middleware auth-bypass probe (GET /) on port 80
Seen: 2026-09-21 07:52 EDT
- 2026-09-21 07:52:40 โ IDS 'ET WEB_SERVER Next.js Middleware Authorization Bypass (CVE-2025-29927)' flagged a TCP probe from this IP to a public web service on port 80
- 2026-09-21 07:52:39 โ HTTP/1.1 GET / requests to public web services on ports 80 and 443 returned 444 (connection closed); a probe to port 8080 was blocked at the firewall
show less