This IP address has been reported a total of
21
times from
20 distinct
sources.
34.166.190.61 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-29.
show less
34.166.190.61 - - [30/Aug/2026:13:35:51 +0300] "GET /settings.py HTTP/1.1" 404 511 "-" "Mozilla/5.0 ...
show more34.166.190.61 - - [30/Aug/2026:13:35:51 +0300] "GET /settings.py HTTP/1.1" 404 511 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.166.190.61 - - [30/Aug/2026:13:35:51 +0300] "GET /settings.json HTTP/1.1" 404 511 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Hacking
Anonymous
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: SA, Attack patterns: Word ...
show moreBlocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: SA, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
251 attacks on config grabbing URLs (type 2), VC URLs, env grabbing URLs, PHP URLs:
GET /application ...
show more251 attacks on config grabbing URLs (type 2), VC URLs, env grabbing URLs, PHP URLs:
GET /application_default_credentials.json HTTP/1.1
GET /.git/config HTTP/1.1
GET /config/app/.env HTTP/1.1
GET /includes/phpinfo.php HTTP/1.1
show less
2026-08-30 01:17:14,381 fail2ban.actions [695583]: NOTICE [apache-noscript] Ban 34.166.190.6 ...
show more2026-08-30 01:17:14,381 fail2ban.actions [695583]: NOTICE [apache-noscript] Ban 34.166.190.61
2026-08-30 01:17:15,055 fail2ban.actions [695583]: NOTICE [nginx-404] Ban 34.166.190.61
...
show less
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: SA, Attack patterns: Word ...
show moreBlocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: SA, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Attacked NCSR.CN production server: SSH brute-force / web scanning / honeypot trips. fail2ban banned ...
show moreAttacked NCSR.CN production server: SSH brute-force / web scanning / honeypot trips. fail2ban banned. Evidence in server logs.
show less