This IP address has been reported a total of
53
times from
35 distinct
sources.
34.154.130.23 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show moreProbing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-09-14 14:50 UTC
show less
Hacking
Web App Attack
Anonymous
34.154.130.23 - - [14/Sep/2026:16:50:12 +0200] "GET /.git/config HTTP/1.1" 403 614 "-" "Mozilla/5.0 ...
show more34.154.130.23 - - [14/Sep/2026:16:50:12 +0200] "GET /.git/config HTTP/1.1" 403 614 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.154.130.23 - - [14/Sep/2026:16:50:12 +0200] "GET /.env HTTP/1.1" 403 614 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.154.130.23 - - [14/Sep/2026:16:50:12 +0200] "GET /.env.local HTTP/1.1" 403 614 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.154.130.23 - - [14/Sep/2026:16:50:12 +0200] "GET /.env.production HTTP/1.1" 403 614 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.154.130.23 - - [14/Sep/2026:16:50:12 +0200] "GET /.env.staging HTTP/1.1" 403 614 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.154.130.23 - - [14/Sep/2026:16:50:12 +0200] "
...
show less
34.154.130.23 Probing for vulnerable code from 2026-09-14 04:33:50 WIB, evidence: tienabled|0|0|0|az ...
show more34.154.130.23 Probing for vulnerable code from 2026-09-14 04:33:50 WIB, evidence: tienabled|0|0|0|azmi.my.id/includes/phpinfo.php
show less
Web App Attack
Hacking
Anonymous
(mod_security) mod_security triggered on hostname [redacted] 34.154.130.23 (IT/Italy/23.130.154.34.b ...
show more(mod_security) mod_security triggered on hostname [redacted] 34.154.130.23 (IT/Italy/23.130.154.34.bc.googleusercontent.com)
show less
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show moreRemote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less