This IP address has been reported a total of
17
times from
14 distinct
sources.
34.148.187.159 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
34.148.187.159 - - [15/Jun/2026:13:36:00 +0000] "GET /server/actuator/heapdump HTTP/1.1" 301 3709 "- ...
show more34.148.187.159 - - [15/Jun/2026:13:36:00 +0000] "GET /server/actuator/heapdump HTTP/1.1" 301 3709 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 12_1_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/16D57 MicroMessenger/7.0.5(0x17000523) NetType/WIFI Language/zh_CN"
...
show less
{"level":"info","ts":1781500367.3727477,"logger":"http.log.access.log1","msg":"handled request","req ...
show more{"level":"info","ts":1781500367.3727477,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.148.187.159","remote_port":"51308","client_ip":"34.148.187.159","proto":"HTTP/1.1","method":"GET","host":"status.korni22.org","uri":"/.env.preprod","headers":{"Accept-Charset":["utf-8"],"Accept-Encoding":["gzip"],"Connection":["close"],"User-Agent":["Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.8 (KHTML, like Gecko) Version/10.1 Safari/603.1.30"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"status.korni22.org","ech":false}},"bytes_read":0,"user_id":"","duration":0.000093399,"size":0,"status":429,"resp_headers":{"Retry-After":["1"],"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"]}}
{"level":"info","ts":1781500367.373985,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.148.187.159","remote_port":"51404","client_ip":"34.148.187.159","proto":"HTTP/1.1","method":"GET","
...
show less
Aggressive web search of vulnerable pages: /prod/.env /development/.env /api/v3/.env /app/.env /back ...
show moreAggressive web search of vulnerable pages: /prod/.env /development/.env /api/v3/.env /app/.env /backend/.env.local ...
show less
Bot / scanning and/or hacking attempts: GET /.env.old HTTP/1.1, GET /app/.env.local HTTP/1.1, GET /s ...
show moreBot / scanning and/or hacking attempts: GET /.env.old HTTP/1.1, GET /app/.env.local HTTP/1.1, GET /src/.env HTTP/1.1, GET /config/.env.local HTTP/1.1, GET /frontend/.env.dev HTTP/1.1, GET /test/.env HTTP/1.1, GET /internal/.env.production HTTP/1.1, GET /frontend/.env HTTP/1.1, GET /tmp/.env HTTP/1.1, GET /stage/.env HTTP/1.1, GET /conf/.env HTTP/1.1, GET /config/.env HTTP/1.1, GET /api/backend/.env HTTP/1.1, GET /cms/.env HTTP/1.1, GET /laravel/.env HTTP/1.1, GET /server/.env.backup HTTP/1.1, GET /.env.backup.txt HTTP/1.1, GET /api/.env.local HTTP/1.1, GET /api/.env.old HTTP/1.1, GET /.env.backup HTTP/1.1, GET /backend/.env.production HTTP/1.1, GET /dev/.env HTTP/1.1, GET /sendgrid/.env.prod HTTP/1.1, GET /mailer/sendgrid.env HTTP/1.1, GET /backend/.env.bak HTTP/1.1, GET /service/.env HTTP/1.1
show less
You are now banned for 10 years by Schiffdorf-West Patrol. Trigger: crowdsecurity/http-sensitive-fil ...
show moreYou are now banned for 10 years by Schiffdorf-West Patrol. Trigger: crowdsecurity/http-sensitive-files
show less
Port Scan
Web App Attack
Showing 1 to
15
of 17 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ