This IP address has been reported a total of
15
times from
15 distinct
sources.
34.146.20.36 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Aggressive web search of vulnerable pages: /frontend/.env /api/v3/.env /frontend/.env.local /backend ...
show moreAggressive web search of vulnerable pages: /frontend/.env /api/v3/.env /frontend/.env.local /backend/.env.local /backend/.env ...
show less
{"level":"info","ts":1781417593.0016212,"logger":"http.log.access.log1","msg":"handled request","req ...
show more{"level":"info","ts":1781417593.0016212,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.146.20.36","remote_port":"43872","client_ip":"34.146.20.36","proto":"HTTP/1.1","method":"GET","host":"159-89-098-098.cprapid.com","uri":"/dashboard/.env","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36"],"Accept-Charset":["utf-8"],"Accept-Encoding":["gzip"],"Connection":["close"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"159-89-098-098.cprapid.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000151298,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1781417593.0066123,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.146.20.36","remote_port":"43730","client_ip":"34.146.20.36","proto":"HTTP/1.1","method":"G
...
show less
[SunJun1405:22:15.1470532026][security2:error][pid2098555:tid2098669][client34.146.20.36:0]ModSecuri ...
show more[SunJun1405:22:15.1470532026][security2:error][pid2098555:tid2098669][client34.146.20.36:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.cxservices.ch.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"ai4eZ4l3tXZGzXEDQYnSWgAAAJE\"]
show less